Yiiframework
28 known vulnerabilities
Top Products
The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, t
Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenari
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regres
A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Gen
A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue i
In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does
Yii 2 is a PHP application framework. During internal penetration testing of a product based on Yii2, users discovered a
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0.
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0.
Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE)
web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in
Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NOTE: this i
SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execu
Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field.
Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field.
`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize(
yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator
yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator
Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize(
Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, whic
Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269
Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in
The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduc
In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messa
In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a
An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exceptio
Frequently Asked Questions
How many CVEs affect Yiiframework?
Yiiframework has 28 CVE records in our database, including 6 critical and 9 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Yiiframework vulnerabilities?
Yiiframework has 6 critical severity (CVSS 9.0+) and 9 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Yiiframework vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Yiiframework products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Yiiframework Vulnerabilities
CyberStrike scans your infrastructure for Yiiframework vulnerabilities and provides real-time remediation guidance.
Get Started