İçeriğe atla
Noroxi

yiiframework kayıtları

yiiframework üreticisine ait 28 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
1 · %3,6
Silahlaştırılmış
1 · %3,6
Pre-auth RCE
8
Düzeltme kaydı olan
%85,7
Yayından KEV’e ortanca
23 gün

Tüm kayıtlar

28 kayıt
  • Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited i

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %88

    yiiframework · yii9 Nis 2025

  • CVE-2020-15148
    64Bu hafta

    Unsafe deserialization in Yii 2

    KritikCVSS 10,0Kavram kanıtıEPSS %79

    yiiframework · yii15 Eyl 2020

  • CVE-2024-4990
    60Bu hafta

    Unsafe Reflection in base Component class in yiisoft/yii2

    KritikCVSS 9,1İstismar yokEPSS %80

    yiiframework · yii20 Mar 2025

  • CVE-2023-47130
    40Planlayın

    Unsafe deserialization of user data in yiisoft/yii

    KritikCVSS 9,8İstismar yokEPSS %3

    yiiframework · yii14 Kas 2023

  • CVE-2018-7269
    40Planlayın

    The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection atta

    KritikCVSS 9,8İstismar yokEPSS %2

    yiiframework · yii21 Mar 2018

  • CVE-2023-26750
    40Planlayın

    SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code vi

    KritikCVSS 9,8İstismar yokEPSS %2

    yiiframework · yii4 Nis 2023

  • CVE-2018-8073
    39İzleyin

    Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with th

    KritikCVSS 9,8İstismar yokEPSS %2

    yiiframework · yii21 Mar 2018

  • CVE-2022-41922
    39İzleyin

    yiisoft/yii before v1.1.27 vulnerable to Remote Code Execution if the application calls `unserialize()` on arbitrary user input

    KritikCVSS 9,8İstismar yokEPSS %1

    yiiframework · yii23 Kas 2022

  • CVE-2015-5467
    39İzleyin

    web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter

    KritikCVSS 9,8İstismar yokEPSS %1

    yiiframework · yii21 Eyl 2023

  • CVE-2023-50708
    39İzleyin

    yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation

    KritikCVSS 9,8İstismar yokEPSS %1

    yiiframework · yii2-authclient22 Ara 2023

  • CVE-2020-36655
    35İzleyin

    Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field.

    YüksekCVSS 8,8İstismar yokEPSS %1

    yiiframework · gii20 Oca 2023

  • CVE-2018-6009
    35İzleyin

    In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.

    YüksekCVSS 8,8İstismar yokEPSS %1

    yiiframework · yiiframework22 Oca 2018

  • CVE-2023-50714
    35İzleyin

    The Oauth2 PKCE implementation is vulnerable

    YüksekCVSS 8,8İstismar yokEPSS %0

    yiiframework · yii2-authclient22 Ara 2023

  • CVE-2018-8074
    32İzleyin

    Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunctio

    YüksekCVSS 8,1İstismar yokEPSS %1

    yiiframework · yii21 Mar 2018

  • CVE-2018-6010
    31İzleyin

    In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit refl

    YüksekCVSS 7,5İstismar yokEPSS %3

    yiiframework · yiiframework22 Oca 2018

  • CVE-2014-4672
    31İzleyin

    The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value

    YüksekCVSS 7,5İstismar yokEPSS %2

    yiiframework · yiiframework3 Tem 2014

  • CVE-2021-3689
    31İzleyin

    Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2

    YüksekCVSS 7,5İstismar yokEPSS %2

    yiiframework · yii10 Ağu 2021

  • CVE-2017-11516
    24İzleyin

    An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug

    OrtaCVSS 6,1İstismar yokEPSS %1

    yiiframework · yii21 Tem 2017

  • CVE-2022-31454
    24İzleyin

    Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books.

    OrtaCVSS 6,1İstismar yokEPSS %0

    yiiframework · yii27 Tem 2023

  • CVE-2025-32027
    24İzleyin

    Yii does not prevent XSS in scenarios where fallback error renderer is used

    OrtaCVSS 6,1İstismar yokEPSS %0

    yiiframework · yii10 Nis 2025

  • CVE-2018-20745
    23İzleyin

    Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible wi

    OrtaCVSS 5,9İstismar yokEPSS %1

    yiiframework · yii28 Oca 2019

  • CVE-2021-3692
    22İzleyin

    Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2

    OrtaCVSS 5,3İstismar yokEPSS %2

    yiiframework · yii10 Ağu 2021

  • CVE-2025-2690
    21İzleyin

    yiisoft Yii2 MockClass.php generate deserialization

    OrtaCVSS 5,3İstismar yokEPSS %1

    yiiframework · yii24 Mar 2025

  • CVE-2025-2689
    21İzleyin

    yiisoft Yii2 SortableIterator.php getIterator deserialization

    OrtaCVSS 5,3İstismar yokEPSS %1

    yiiframework · yii24 Mar 2025

  • CVE-2022-34297
    21İzleyin

    Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field.

    OrtaCVSS 5,4İstismar yokEPSS %1

    yiiframework · gii9 Ara 2022