yiiframework records
28 published records for vendor yiiframework.
Researcher profile
- Entered KEV
- 1 · 3.6%
- Weaponized
- 1 · 3.6%
- Pre-auth RCE
- 8
- With a fix record
- 85.7%
- Median publish → KEV
- 23 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-502 Deserialization of Untrusted Data3
- CWE-1241 Use of Predictable Algorithm in Random Number Generator2
- CWE-20 Improper Input Validation2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
28 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2024-58136Weaponized | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited iyiiframework · yii · CWE-424 | Critical9.8 | KEV | 87.8% | Apr 9, 2025 |
64This week | CVE-2020-15148Proof of concept | Unsafe deserialization in Yii 2yiiframework · yii · CWE-502 | Critical10.0 | — | 78.8% | Sep 15, 2020 |
60This week | CVE-2024-4990No exploit | Unsafe Reflection in base Component class in yiisoft/yii2yiiframework · yii · CWE-470 | Critical9.1 | — | 80.2% | Mar 20, 2025 |
40Plan | CVE-2023-47130No exploit | Unsafe deserialization of user data in yiisoft/yiiyiiframework · yii · CWE-502 | Critical9.8 | — | 3.1% | Nov 14, 2023 |
40Plan | CVE-2018-7269No exploit | The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attayiiframework · yii · CWE-89 | Critical9.8 | — | 1.9% | Mar 21, 2018 |
40Plan | CVE-2023-26750No exploit | SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code viyiiframework · yii · CWE-89 | Critical9.8 | — | 1.8% | Apr 4, 2023 |
39Monitor | CVE-2018-8073No exploit | Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with thyiiframework · yii · CWE-94 | Critical9.8 | — | 1.6% | Mar 21, 2018 |
39Monitor | CVE-2022-41922No exploit | yiisoft/yii before v1.1.27 vulnerable to Remote Code Execution if the application calls `unserialize()` on arbitrary user inputyiiframework · yii · CWE-502 | Critical9.8 | — | 1.2% | Nov 23, 2022 |
39Monitor | CVE-2015-5467No exploit | web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeteryiiframework · yii · CWE-22 | Critical9.8 | — | 0.9% | Sep 21, 2023 |
39Monitor | CVE-2023-50708No exploit | yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementationyiiframework · yii2-authclient · CWE-203 | Critical9.8 | — | 0.7% | Dec 22, 2023 |
35Monitor | CVE-2020-36655No exploit | Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field.yiiframework · gii · CWE-94 | High8.8 | — | 1.5% | Jan 20, 2023 |
35Monitor | CVE-2018-6009No exploit | In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.yiiframework · yiiframework · CWE-352 | High8.8 | — | 0.6% | Jan 22, 2018 |
35Monitor | CVE-2023-50714No exploit | The Oauth2 PKCE implementation is vulnerableyiiframework · yii2-authclient · CWE-347 | High8.8 | — | 0.5% | Dec 22, 2023 |
32Monitor | CVE-2018-8074No exploit | Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunctioyiiframework · yii · CWE-94 | High8.1 | — | 1.5% | Mar 21, 2018 |
31Monitor | CVE-2018-6010No exploit | In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit reflyiiframework · yiiframework · CWE-79 | High7.5 | — | 2.9% | Jan 22, 2018 |
31Monitor | CVE-2014-4672No exploit | The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the valueyiiframework · yiiframework · CWE-94 | High7.5 | — | 2.1% | Jul 3, 2014 |
31Monitor | CVE-2021-3689No exploit | Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2yiiframework · yii · CWE-1241 | High7.5 | — | 1.9% | Aug 10, 2021 |
24Monitor | CVE-2017-11516No exploit | An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug yiiframework · yii · CWE-79 | Medium6.1 | — | 0.8% | Jul 21, 2017 |
24Monitor | CVE-2022-31454No exploit | Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books.yiiframework · yii · CWE-79 | Medium6.1 | — | 0.4% | Jul 27, 2023 |
24Monitor | CVE-2025-32027No exploit | Yii does not prevent XSS in scenarios where fallback error renderer is usedyiiframework · yii · CWE-79 | Medium6.1 | — | 0.2% | Apr 10, 2025 |
23Monitor | CVE-2018-20745No exploit | Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible wiyiiframework · yii · CWE-346 | Medium5.9 | — | 0.5% | Jan 28, 2019 |
22Monitor | CVE-2021-3692No exploit | Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2yiiframework · yii · CWE-1241 | Medium5.3 | — | 1.7% | Aug 10, 2021 |
21Monitor | CVE-2025-2690No exploit | yiisoft Yii2 MockClass.php generate deserializationyiiframework · yii · CWE-20 | Medium5.3 | — | 0.7% | Mar 24, 2025 |
21Monitor | CVE-2025-2689No exploit | yiisoft Yii2 SortableIterator.php getIterator deserializationyiiframework · yii · CWE-20 | Medium5.3 | — | 0.6% | Mar 24, 2025 |
21Monitor | CVE-2022-34297No exploit | Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field.yiiframework · gii · CWE-79 | Medium5.4 | — | 0.6% | Dec 9, 2022 |
- CVE-2024-5813695Now
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited i
CriticalCVSS 9.8KEVWeaponizedEPSS 88%yiiframework · yiiApr 9, 2025
- CVE-2020-1514864This week
Unsafe deserialization in Yii 2
CriticalCVSS 10.0Proof of conceptEPSS 79%yiiframework · yiiSep 15, 2020
- CVE-2024-499060This week
Unsafe Reflection in base Component class in yiisoft/yii2
CriticalCVSS 9.1No exploitEPSS 80%yiiframework · yiiMar 20, 2025
- CVE-2023-4713040Plan
Unsafe deserialization of user data in yiisoft/yii
CriticalCVSS 9.8No exploitEPSS 3%yiiframework · yiiNov 14, 2023
- CVE-2018-726940Plan
The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection atta
CriticalCVSS 9.8No exploitEPSS 2%yiiframework · yiiMar 21, 2018
- CVE-2023-2675040Plan
SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code vi
CriticalCVSS 9.8No exploitEPSS 2%yiiframework · yiiApr 4, 2023
- CVE-2018-807339Monitor
Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with th
CriticalCVSS 9.8No exploitEPSS 2%yiiframework · yiiMar 21, 2018
- CVE-2022-4192239Monitor
yiisoft/yii before v1.1.27 vulnerable to Remote Code Execution if the application calls `unserialize()` on arbitrary user input
CriticalCVSS 9.8No exploitEPSS 1%yiiframework · yiiNov 23, 2022
- CVE-2015-546739Monitor
web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter
CriticalCVSS 9.8No exploitEPSS 1%yiiframework · yiiSep 21, 2023
- CVE-2023-5070839Monitor
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
CriticalCVSS 9.8No exploitEPSS 1%yiiframework · yii2-authclientDec 22, 2023
- CVE-2020-3665535Monitor
Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field.
HighCVSS 8.8No exploitEPSS 1%yiiframework · giiJan 20, 2023
- CVE-2018-600935Monitor
In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.
HighCVSS 8.8No exploitEPSS 1%yiiframework · yiiframeworkJan 22, 2018
- CVE-2023-5071435Monitor
The Oauth2 PKCE implementation is vulnerable
HighCVSS 8.8No exploitEPSS 0%yiiframework · yii2-authclientDec 22, 2023
- CVE-2018-807432Monitor
Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunctio
HighCVSS 8.1No exploitEPSS 1%yiiframework · yiiMar 21, 2018
- CVE-2018-601031Monitor
In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit refl
HighCVSS 7.5No exploitEPSS 3%yiiframework · yiiframeworkJan 22, 2018
- CVE-2014-467231Monitor
The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value
HighCVSS 7.5No exploitEPSS 2%yiiframework · yiiframeworkJul 3, 2014
- CVE-2021-368931Monitor
Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2
HighCVSS 7.5No exploitEPSS 2%yiiframework · yiiAug 10, 2021
- CVE-2017-1151624Monitor
An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug
MediumCVSS 6.1No exploitEPSS 1%yiiframework · yiiJul 21, 2017
- CVE-2022-3145424Monitor
Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books.
MediumCVSS 6.1No exploitEPSS 0%yiiframework · yiiJul 27, 2023
- CVE-2025-3202724Monitor
Yii does not prevent XSS in scenarios where fallback error renderer is used
MediumCVSS 6.1No exploitEPSS 0%yiiframework · yiiApr 10, 2025
- CVE-2018-2074523Monitor
Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible wi
MediumCVSS 5.9No exploitEPSS 1%yiiframework · yiiJan 28, 2019
- CVE-2021-369222Monitor
Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2
MediumCVSS 5.3No exploitEPSS 2%yiiframework · yiiAug 10, 2021
- CVE-2025-269021Monitor
yiisoft Yii2 MockClass.php generate deserialization
MediumCVSS 5.3No exploitEPSS 1%yiiframework · yiiMar 24, 2025
- CVE-2025-268921Monitor
yiisoft Yii2 SortableIterator.php getIterator deserialization
MediumCVSS 5.3No exploitEPSS 1%yiiframework · yiiMar 24, 2025
- CVE-2022-3429721Monitor
Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field.
MediumCVSS 5.4No exploitEPSS 1%yiiframework · giiDec 9, 2022