Yii
Yiiframework · 19 CVEs
Yii does not prevent XSS in scenarios where fallback error renderer is used
Apr 10, 2025
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regre…
Apr 10, 2025
yiisoft Yii2 MockClass.php generate deserialization
Mar 24, 2025
yiisoft Yii2 SortableIterator.php getIterator deserialization
Mar 24, 2025
Unsafe Reflection in base Component class in yiisoft/yii2
Mar 20, 2025
Reflected Cross-site Scripting in yiisoft/yii2 Debug mode
May 30, 2024
Unsafe deserialization of user data in yiisoft/yii
Nov 14, 2023
web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path i…
Sep 21, 2023
Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NOTE: this…
Jul 28, 2023
SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to exec…
Apr 4, 2023
yiisoft/yii before v1.1.27 vulnerable to Remote Code Execution if the application calls `unserialize()` on arbitrary us…
Nov 23, 2022
Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2
Aug 10, 2021
Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2
Aug 10, 2021
Unsafe deserialization in Yii 2
Sep 15, 2020
Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, whi…
Jan 28, 2019
Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269…
Mar 21, 2018
Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack i…
Mar 21, 2018
The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to condu…
Mar 21, 2018
An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the excepti…
Jul 21, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-32027 | Yii does not prevent XSS in scenarios where fallback error renderer is used | MEDIUM | 0.24% | Apr 10, 2025 |
| CVE-2024-58136 KEV | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in Febru… | CRITICAL | 87.76% | Apr 10, 2025 |
| CVE-2025-2690 | yiisoft Yii2 MockClass.php generate deserialization | MEDIUM | 0.66% | Mar 24, 2025 |
| CVE-2025-2689 | yiisoft Yii2 SortableIterator.php getIterator deserialization | MEDIUM | 0.62% | Mar 24, 2025 |
| CVE-2024-4990 | Unsafe Reflection in base Component class in yiisoft/yii2 | CRITICAL | 80.23% | Mar 20, 2025 |
| CVE-2024-32877 | Reflected Cross-site Scripting in yiisoft/yii2 Debug mode | MEDIUM | 0.35% | May 30, 2024 |
| CVE-2023-47130 | Unsafe deserialization of user data in yiisoft/yii | CRITICAL | 3.15% | Nov 14, 2023 |
| CVE-2015-5467 | web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter. | CRITICAL | 0.88% | Sep 21, 2023 |
| CVE-2022-31454 | Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NOTE: this is disputed by the vendor because the cv… | MEDIUM | 0.40% | Jul 28, 2023 |
| CVE-2023-26750 | SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction fun… | CRITICAL | 1.82% | Apr 4, 2023 |
| CVE-2022-41922 | yiisoft/yii before v1.1.27 vulnerable to Remote Code Execution if the application calls `unserialize()` on arbitrary user input | CRITICAL | 1.22% | Nov 23, 2022 |
| CVE-2021-3692 | Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2 | MEDIUM | 1.70% | Aug 10, 2021 |
| CVE-2021-3689 | Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2 | HIGH | 1.90% | Aug 10, 2021 |
| CVE-2020-15148 | Unsafe deserialization in Yii 2 | CRITICAL | 77.54% | Sep 15, 2020 |
| CVE-2018-20745 | Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS securit… | MEDIUM | 0.54% | Jan 28, 2019 |
| CVE-2018-8074 | Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elastics… | HIGH | 1.49% | Mar 21, 2018 |
| CVE-2018-8073 | Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with the Redis extension. | CRITICAL | 1.56% | Mar 21, 2018 |
| CVE-2018-7269 | The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne()… | CRITICAL | 1.90% | Mar 21, 2018 |
| CVE-2017-11516 | An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, be… | MEDIUM | 0.83% | Jul 21, 2017 |
Showing 1 to 19 of 19 CVEs