VendorsYii Frameworkyiiall versions
Vulnerabilities

Yii Framework Yiiframework Yii

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2020-15148
Unsafe deserialization in Yii 2
Published 2020-09-15 · Modified
10.0EPSS 0.788
CVE-2024-58136
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
Published 2025-04-10 · Analyzed
9.8KEVEPSS 0.878
CVE-2023-47130
Unsafe deserialization of user data in yiisoft/yii
Published 2023-11-14 · Modified
9.8EPSS 0.031
CVE-2018-7269
The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input.
Published 2018-03-21 · Modified
9.8EPSS 0.019
CVE-2023-26750
SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.
Published 2023-04-04 · Modified
9.8EPSS 0.018
CVE-2018-8073
Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with the Redis extension.
Published 2018-03-21 · Modified
9.8EPSS 0.016
CVE-2022-41922
yiisoft/yii before v1.1.27 vulnerable to Remote Code Execution if the application calls `unserialize()` on arbitrary user input
Published 2022-11-23 · Modified
9.8EPSS 0.012
CVE-2015-5467
web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.
Published 2023-09-21 · Modified
9.8EPSS 0.009
CVE-2025-2690
yiisoft Yii2 MockClass.php generate deserialization
Published 2025-03-24 · Analyzed
9.8EPSS 0.007
CVE-2025-2689
yiisoft Yii2 SortableIterator.php getIterator deserialization
Published 2025-03-24 · Analyzed
9.8EPSS 0.006
CVE-2024-4990
Unsafe Reflection in base Component class in yiisoft/yii2
Published 2025-03-20 · Analyzed
9.1EPSS 0.802
CVE-2021-3689
Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2
Published 2021-08-10 · Modified
8.1EPSS 0.019
CVE-2021-3692
Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2
Published 2021-08-10 · Modified
8.1EPSS 0.017
CVE-2018-8074
Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elasticsearch extension.
Published 2018-03-21 · Modified
8.1EPSS 0.015
CVE-2017-11516
An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception->errorInfo is mishandled.
Published 2017-07-21 · Modified
6.1EPSS 0.008
CVE-2022-31454
Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NOTE: this is disputed by the vendor because the cve-2022-31454-8e8555c31fd3 page does not describe why /books has a relationship to Yii 2.
Published 2023-07-28 · Modified
6.1EPSS 0.004
CVE-2025-32027
Yii does not prevent XSS in scenarios where fallback error renderer is used
Published 2025-04-10 · Analyzed
6.1EPSS 0.002
CVE-2018-20745
Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.
Published 2019-01-28 · Modified
5.9EPSS 0.005
CVE-2024-32877
Reflected Cross-site Scripting in yiisoft/yii2 Debug mode
Published 2024-05-30 · Analyzed
4.7EPSS 0.003