Known Vulnerabilities for products from Yiiframework

Listed below are 19 of the newest known vulnerabilities associated with the vendor "Yiiframework".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-47130 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 9.8 - CRITICAL 2023-11-14 2023-11-20
CVE-2023-26750 json ** DISPUTED ** SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacke... 9.8 - CRITICAL 2023-04-04 2023-11-07
CVE-2022-41922 json `yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on... 9.8 - CRITICAL 2022-11-23 2022-11-30
CVE-2022-34297 json Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field. 5.4 - MEDIUM 2022-12-09 2022-12-13
CVE-2022-31454 json ** DISPUTED ** Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NO... 6.1 - MEDIUM 2023-07-28 2023-11-07
CVE-2021-3692 json yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator 5.3 - MEDIUM 2021-08-10 2022-04-25
CVE-2021-3689 json yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator 7.5 - HIGH 2021-08-10 2022-04-25
CVE-2020-36655 json Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The ... 8.8 - HIGH 2023-01-21 2023-01-30
CVE-2020-15148 json Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on... 10 - CRITICAL 2020-09-15 2020-09-22
CVE-2018-20745 json Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is ... 5.9 - MEDIUM 2019-01-28 2019-02-20
CVE-2018-8074 json Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attac... 8.1 - HIGH 2018-03-21 2018-04-20
CVE-2018-8073 json Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conj... 9.8 - CRITICAL 2018-03-21 2018-04-17
CVE-2018-7269 json The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL... 9.8 - CRITICAL 2018-03-21 2018-04-20
CVE-2018-6010 json In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, ... 7.5 - HIGH 2018-01-22 2020-08-24
CVE-2018-6009 json In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a chan... 8.8 - HIGH 2018-01-22 2018-02-09
CVE-2017-11516 json An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception scr... Not Provided 2017-07-21 2025-04-20
CVE-2015-5467 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 9.8 - CRITICAL 2023-09-21 2023-09-22
CVE-2015-3397 json Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.4 allows remote attackers to inject arbitrary web script... Not Provided 2015-05-14 2026-05-06
CVE-2014-4672 json The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors relat... Not Provided 2014-07-03 2026-05-06

Known software with vulnerabilities from Yiiframework

Type Vendor Product Version
ApplicationYiiframeworkYii2.0.0
ApplicationYiiframeworkYiiframework1.1.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report