VendorsYii Frameworkyiiany version
Vulnerabilities

Yii Framework Yiiframework Yii any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2020-15148
Unsafe deserialization in Yii 2
Published 2020-09-15 · Modified
10.0EPSS 0.788
CVE-2024-58136
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
Published 2025-04-10 · Analyzed
9.8KEVEPSS 0.878
CVE-2023-47130
Unsafe deserialization of user data in yiisoft/yii
Published 2023-11-14 · Modified
9.8EPSS 0.031
CVE-2018-7269
The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input.
Published 2018-03-21 · Modified
9.8EPSS 0.019
CVE-2023-26750
SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.
Published 2023-04-04 · Modified
9.8EPSS 0.018
CVE-2018-8073
Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with the Redis extension.
Published 2018-03-21 · Modified
9.8EPSS 0.016
CVE-2022-41922
yiisoft/yii before v1.1.27 vulnerable to Remote Code Execution if the application calls `unserialize()` on arbitrary user input
Published 2022-11-23 · Modified
9.8EPSS 0.012
CVE-2015-5467
web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.
Published 2023-09-21 · Modified
9.8EPSS 0.009
CVE-2025-2690
yiisoft Yii2 MockClass.php generate deserialization
Published 2025-03-24 · Analyzed
9.8EPSS 0.007
CVE-2025-2689
yiisoft Yii2 SortableIterator.php getIterator deserialization
Published 2025-03-24 · Analyzed
9.8EPSS 0.006
CVE-2021-3689
Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2
Published 2021-08-10 · Modified
8.1EPSS 0.019
CVE-2021-3692
Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2
Published 2021-08-10 · Modified
8.1EPSS 0.017
CVE-2018-8074
Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elasticsearch extension.
Published 2018-03-21 · Modified
8.1EPSS 0.015
CVE-2025-32027
Yii does not prevent XSS in scenarios where fallback error renderer is used
Published 2025-04-10 · Analyzed
6.1EPSS 0.002
CVE-2018-20745
Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.
Published 2019-01-28 · Modified
5.9EPSS 0.005