Skip to content
Noroxi

yiiframework records

28 published records for vendor yiiframework.

All records

28 records
  • Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited i

    CriticalCVSS 9.8KEVWeaponizedEPSS 88%

    yiiframework · yiiApr 9, 2025

  • CVE-2020-15148
    64This week

    Unsafe deserialization in Yii 2

    CriticalCVSS 10.0Proof of conceptEPSS 79%

    yiiframework · yiiSep 15, 2020

  • CVE-2024-4990
    60This week

    Unsafe Reflection in base Component class in yiisoft/yii2

    CriticalCVSS 9.1No exploitEPSS 80%

    yiiframework · yiiMar 20, 2025

  • Unsafe deserialization of user data in yiisoft/yii

    CriticalCVSS 9.8No exploitEPSS 3%

    yiiframework · yiiNov 14, 2023

  • The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection atta

    CriticalCVSS 9.8No exploitEPSS 2%

    yiiframework · yiiMar 21, 2018

  • SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code vi

    CriticalCVSS 9.8No exploitEPSS 2%

    yiiframework · yiiApr 4, 2023

  • CVE-2018-8073
    39Monitor

    Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with th

    CriticalCVSS 9.8No exploitEPSS 2%

    yiiframework · yiiMar 21, 2018

  • yiisoft/yii before v1.1.27 vulnerable to Remote Code Execution if the application calls `unserialize()` on arbitrary user input

    CriticalCVSS 9.8No exploitEPSS 1%

    yiiframework · yiiNov 23, 2022

  • CVE-2015-5467
    39Monitor

    web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter

    CriticalCVSS 9.8No exploitEPSS 1%

    yiiframework · yiiSep 21, 2023

  • yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation

    CriticalCVSS 9.8No exploitEPSS 1%

    yiiframework · yii2-authclientDec 22, 2023

  • Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field.

    HighCVSS 8.8No exploitEPSS 1%

    yiiframework · giiJan 20, 2023

  • CVE-2018-6009
    35Monitor

    In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.

    HighCVSS 8.8No exploitEPSS 1%

    yiiframework · yiiframeworkJan 22, 2018

  • The Oauth2 PKCE implementation is vulnerable

    HighCVSS 8.8No exploitEPSS 0%

    yiiframework · yii2-authclientDec 22, 2023

  • CVE-2018-8074
    32Monitor

    Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunctio

    HighCVSS 8.1No exploitEPSS 1%

    yiiframework · yiiMar 21, 2018

  • CVE-2018-6010
    31Monitor

    In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit refl

    HighCVSS 7.5No exploitEPSS 3%

    yiiframework · yiiframeworkJan 22, 2018

  • CVE-2014-4672
    31Monitor

    The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value

    HighCVSS 7.5No exploitEPSS 2%

    yiiframework · yiiframeworkJul 3, 2014

  • CVE-2021-3689
    31Monitor

    Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2

    HighCVSS 7.5No exploitEPSS 2%

    yiiframework · yiiAug 10, 2021

  • An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug

    MediumCVSS 6.1No exploitEPSS 1%

    yiiframework · yiiJul 21, 2017

  • Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books.

    MediumCVSS 6.1No exploitEPSS 0%

    yiiframework · yiiJul 27, 2023

  • Yii does not prevent XSS in scenarios where fallback error renderer is used

    MediumCVSS 6.1No exploitEPSS 0%

    yiiframework · yiiApr 10, 2025

  • Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible wi

    MediumCVSS 5.9No exploitEPSS 1%

    yiiframework · yiiJan 28, 2019

  • CVE-2021-3692
    22Monitor

    Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2

    MediumCVSS 5.3No exploitEPSS 2%

    yiiframework · yiiAug 10, 2021

  • CVE-2025-2690
    21Monitor

    yiisoft Yii2 MockClass.php generate deserialization

    MediumCVSS 5.3No exploitEPSS 1%

    yiiframework · yiiMar 24, 2025

  • CVE-2025-2689
    21Monitor

    yiisoft Yii2 SortableIterator.php getIterator deserialization

    MediumCVSS 5.3No exploitEPSS 1%

    yiiframework · yiiMar 24, 2025

  • Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field.

    MediumCVSS 5.4No exploitEPSS 1%

    yiiframework · giiDec 9, 2022