Yii

Yiiframework · 19 CVEs

CVE-2025-32027
MEDIUM

Yii does not prevent XSS in scenarios where fallback error renderer is used

Apr 10, 2025

CVE-2024-58136
KEV CRITICAL

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regre…

Apr 10, 2025

CVE-2025-2690
MEDIUM

yiisoft Yii2 MockClass.php generate deserialization

Mar 24, 2025

CVE-2025-2689
MEDIUM

yiisoft Yii2 SortableIterator.php getIterator deserialization

Mar 24, 2025

CVE-2024-4990
CRITICAL

Unsafe Reflection in base Component class in yiisoft/yii2

Mar 20, 2025

CVE-2024-32877
MEDIUM

Reflected Cross-site Scripting in yiisoft/yii2 Debug mode

May 30, 2024

CVE-2023-47130
CRITICAL

Unsafe deserialization of user data in yiisoft/yii

Nov 14, 2023

CVE-2015-5467
CRITICAL

web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path i…

Sep 21, 2023

CVE-2022-31454
MEDIUM

Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NOTE: this…

Jul 28, 2023

CVE-2023-26750
CRITICAL

SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to exec…

Apr 4, 2023

CVE-2022-41922
CRITICAL

yiisoft/yii before v1.1.27 vulnerable to Remote Code Execution if the application calls `unserialize()` on arbitrary us…

Nov 23, 2022

CVE-2021-3692
MEDIUM

Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2

Aug 10, 2021

CVE-2021-3689
HIGH

Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2

Aug 10, 2021

CVE-2020-15148
CRITICAL

Unsafe deserialization in Yii 2

Sep 15, 2020

CVE-2018-20745
MEDIUM

Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, whi…

Jan 28, 2019

CVE-2018-8074
HIGH

Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269…

Mar 21, 2018

CVE-2018-8073
CRITICAL

Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack i…

Mar 21, 2018

CVE-2018-7269
CRITICAL

The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to condu…

Mar 21, 2018

CVE-2017-11516
MEDIUM

An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the excepti…

Jul 21, 2017

Showing 1 to 19 of 19 CVEs