Записи yiiframework
28 опубликованных записей вендора yiiframework.
Профиль для исследователя
- Попали в KEV
- 1 · 3,6 %
- С эксплойтом
- 1 · 3,6 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 85,7 %
- Медиана: публикация → KEV
- 23 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-502 Deserialization of Untrusted Data3
- CWE-1241 Use of Predictable Algorithm in Random Number Generator2
- CWE-20 Improper Input Validation2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
28 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
95Срочно | CVE-2024-58136Готовый эксплойт | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited iyiiframework · yii · CWE-424 | Критическая9,8 | KEV | 87,8 % | 9 апр. 2025 г. |
64На этой неделе | CVE-2020-15148Proof of concept | Unsafe deserialization in Yii 2yiiframework · yii · CWE-502 | Критическая10,0 | — | 78,8 % | 15 сент. 2020 г. |
60На этой неделе | CVE-2024-4990Эксплойта нет | Unsafe Reflection in base Component class in yiisoft/yii2yiiframework · yii · CWE-470 | Критическая9,1 | — | 80,2 % | 20 мар. 2025 г. |
40В плане | CVE-2023-47130Эксплойта нет | Unsafe deserialization of user data in yiisoft/yiiyiiframework · yii · CWE-502 | Критическая9,8 | — | 3,1 % | 14 нояб. 2023 г. |
40В плане | CVE-2018-7269Эксплойта нет | The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attayiiframework · yii · CWE-89 | Критическая9,8 | — | 1,9 % | 21 мар. 2018 г. |
40В плане | CVE-2023-26750Эксплойта нет | SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code viyiiframework · yii · CWE-89 | Критическая9,8 | — | 1,8 % | 4 апр. 2023 г. |
39Наблюдать | CVE-2018-8073Эксплойта нет | Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with thyiiframework · yii · CWE-94 | Критическая9,8 | — | 1,6 % | 21 мар. 2018 г. |
39Наблюдать | CVE-2022-41922Эксплойта нет | yiisoft/yii before v1.1.27 vulnerable to Remote Code Execution if the application calls `unserialize()` on arbitrary user inputyiiframework · yii · CWE-502 | Критическая9,8 | — | 1,2 % | 23 нояб. 2022 г. |
39Наблюдать | CVE-2015-5467Эксплойта нет | web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeteryiiframework · yii · CWE-22 | Критическая9,8 | — | 0,9 % | 21 сент. 2023 г. |
39Наблюдать | CVE-2023-50708Эксплойта нет | yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementationyiiframework · yii2-authclient · CWE-203 | Критическая9,8 | — | 0,7 % | 22 дек. 2023 г. |
35Наблюдать | CVE-2020-36655Эксплойта нет | Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field.yiiframework · gii · CWE-94 | Высокая8,8 | — | 1,5 % | 20 янв. 2023 г. |
35Наблюдать | CVE-2018-6009Эксплойта нет | In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.yiiframework · yiiframework · CWE-352 | Высокая8,8 | — | 0,6 % | 22 янв. 2018 г. |
35Наблюдать | CVE-2023-50714Эксплойта нет | The Oauth2 PKCE implementation is vulnerableyiiframework · yii2-authclient · CWE-347 | Высокая8,8 | — | 0,5 % | 22 дек. 2023 г. |
32Наблюдать | CVE-2018-8074Эксплойта нет | Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunctioyiiframework · yii · CWE-94 | Высокая8,1 | — | 1,5 % | 21 мар. 2018 г. |
31Наблюдать | CVE-2018-6010Эксплойта нет | In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit reflyiiframework · yiiframework · CWE-79 | Высокая7,5 | — | 2,9 % | 22 янв. 2018 г. |
31Наблюдать | CVE-2014-4672Эксплойта нет | The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the valueyiiframework · yiiframework · CWE-94 | Высокая7,5 | — | 2,1 % | 3 июл. 2014 г. |
31Наблюдать | CVE-2021-3689Эксплойта нет | Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2yiiframework · yii · CWE-1241 | Высокая7,5 | — | 1,9 % | 10 авг. 2021 г. |
24Наблюдать | CVE-2017-11516Эксплойта нет | An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug yiiframework · yii · CWE-79 | Средняя6,1 | — | 0,8 % | 21 июл. 2017 г. |
24Наблюдать | CVE-2022-31454Эксплойта нет | Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books.yiiframework · yii · CWE-79 | Средняя6,1 | — | 0,4 % | 27 июл. 2023 г. |
24Наблюдать | CVE-2025-32027Эксплойта нет | Yii does not prevent XSS in scenarios where fallback error renderer is usedyiiframework · yii · CWE-79 | Средняя6,1 | — | 0,2 % | 10 апр. 2025 г. |
23Наблюдать | CVE-2018-20745Эксплойта нет | Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible wiyiiframework · yii · CWE-346 | Средняя5,9 | — | 0,5 % | 28 янв. 2019 г. |
22Наблюдать | CVE-2021-3692Эксплойта нет | Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2yiiframework · yii · CWE-1241 | Средняя5,3 | — | 1,7 % | 10 авг. 2021 г. |
21Наблюдать | CVE-2025-2690Эксплойта нет | yiisoft Yii2 MockClass.php generate deserializationyiiframework · yii · CWE-20 | Средняя5,3 | — | 0,7 % | 24 мар. 2025 г. |
21Наблюдать | CVE-2025-2689Эксплойта нет | yiisoft Yii2 SortableIterator.php getIterator deserializationyiiframework · yii · CWE-20 | Средняя5,3 | — | 0,6 % | 24 мар. 2025 г. |
21Наблюдать | CVE-2022-34297Эксплойта нет | Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field.yiiframework · gii · CWE-79 | Средняя5,4 | — | 0,6 % | 9 дек. 2022 г. |
- CVE-2024-5813695Срочно
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited i
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 88 %yiiframework · yii9 апр. 2025 г.
- CVE-2020-1514864На этой неделе
Unsafe deserialization in Yii 2
КритическаяCVSS 10,0Proof of conceptEPSS 79 %yiiframework · yii15 сент. 2020 г.
- CVE-2024-499060На этой неделе
Unsafe Reflection in base Component class in yiisoft/yii2
КритическаяCVSS 9,1Эксплойта нетEPSS 80 %yiiframework · yii20 мар. 2025 г.
- CVE-2023-4713040В плане
Unsafe deserialization of user data in yiisoft/yii
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %yiiframework · yii14 нояб. 2023 г.
- CVE-2018-726940В плане
The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection atta
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %yiiframework · yii21 мар. 2018 г.
- CVE-2023-2675040В плане
SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code vi
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %yiiframework · yii4 апр. 2023 г.
- CVE-2018-807339Наблюдать
Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with th
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %yiiframework · yii21 мар. 2018 г.
- CVE-2022-4192239Наблюдать
yiisoft/yii before v1.1.27 vulnerable to Remote Code Execution if the application calls `unserialize()` on arbitrary user input
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %yiiframework · yii23 нояб. 2022 г.
- CVE-2015-546739Наблюдать
web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %yiiframework · yii21 сент. 2023 г.
- CVE-2023-5070839Наблюдать
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %yiiframework · yii2-authclient22 дек. 2023 г.
- CVE-2020-3665535Наблюдать
Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %yiiframework · gii20 янв. 2023 г.
- CVE-2018-600935Наблюдать
In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %yiiframework · yiiframework22 янв. 2018 г.
- CVE-2023-5071435Наблюдать
The Oauth2 PKCE implementation is vulnerable
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %yiiframework · yii2-authclient22 дек. 2023 г.
- CVE-2018-807432Наблюдать
Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunctio
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %yiiframework · yii21 мар. 2018 г.
- CVE-2018-601031Наблюдать
In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit refl
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %yiiframework · yiiframework22 янв. 2018 г.
- CVE-2014-467231Наблюдать
The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %yiiframework · yiiframework3 июл. 2014 г.
- CVE-2021-368931Наблюдать
Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %yiiframework · yii10 авг. 2021 г.
- CVE-2017-1151624Наблюдать
An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug
СредняяCVSS 6,1Эксплойта нетEPSS 1 %yiiframework · yii21 июл. 2017 г.
- CVE-2022-3145424Наблюдать
Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %yiiframework · yii27 июл. 2023 г.
- CVE-2025-3202724Наблюдать
Yii does not prevent XSS in scenarios where fallback error renderer is used
СредняяCVSS 6,1Эксплойта нетEPSS 0 %yiiframework · yii10 апр. 2025 г.
- CVE-2018-2074523Наблюдать
Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible wi
СредняяCVSS 5,9Эксплойта нетEPSS 1 %yiiframework · yii28 янв. 2019 г.
- CVE-2021-369222Наблюдать
Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2
СредняяCVSS 5,3Эксплойта нетEPSS 2 %yiiframework · yii10 авг. 2021 г.
- CVE-2025-269021Наблюдать
yiisoft Yii2 MockClass.php generate deserialization
СредняяCVSS 5,3Эксплойта нетEPSS 1 %yiiframework · yii24 мар. 2025 г.
- CVE-2025-268921Наблюдать
yiisoft Yii2 SortableIterator.php getIterator deserialization
СредняяCVSS 5,3Эксплойта нетEPSS 1 %yiiframework · yii24 мар. 2025 г.
- CVE-2022-3429721Наблюдать
Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %yiiframework · gii9 дек. 2022 г.