Known vulnerabilities in Yii
Vendor:
Yii Software
Software:
Yii
Software CPE:
cpe:2.3:a:yii_software:yii:*:*:*:*:*:*:*:*
Website:
https://www.yiiframework.com/
Total vulnerabilities:
5
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.0.55
2.0.54
2.0.53
2.0.52
2.0.51
2.0.49.4
2.0.50
2.0.49.3
2.0.49.2
2.0.49.1
2.0.49
2.0.48.1
2.0.48
2.0.47
2.0.46
2.0.45
2.0.44
2.0.43
2.0.42.1
2.0.42
2.0.41.1
2.0.41
2.0.40
2.0.39.3
2.0.39.2
2.0.39.1
2.0.39
2.0.38
2.0.37
2.0.36
2.0.35
2.0.34
2.0.33
2.0.32
2.0.31
2.0.30
2.0.29
2.0.28
2.0.27
2.0.26
2.0.25
2.0.24
2.0.23
2.0.22
2.0.21
2.0.20
2.0.19
2.0.18
2.0.17
2.0.16.1
2.0.16
2.0.15.1
2.0.15
2.0.14.2
2.0.14.1
2.0.14
2.0.13.3
2.0.13.2
2.0.13.1
2.0.13
2.0.12.2
2.0.12.1
2.0.12
2.0.11.2
2.0.11.1
2.0.11
2.0.10
2.0.9
2.0.8
2.0.7
2.0.6
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
2.0.0
1.1.22
1.1.21
1.1.20
1.1.19
1.1.18
1.1.17
1.1.16
1.1.15
1.1.14
1.1.13
1.1.12
1.1.11
1.1.10
1.1.9
1.1.8
1.1.7
1.1.6
1.1.5
1.1.4
1.1.3
1.1.2
1.1.1
1.1.0
1.0.12
1.0.11
1.0.10
1.0.9
1.0.8
1.0.7
1.0.6
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU130923 - Improper Control of Filename for Include/Require Statement in PHP Program CVE-2026-39850 |
CWE-98 | High | 2.0.55 | 11.05.2026 |
SB2026051142 |
||
| #VU107992 - Improper Protection of Alternate Path CVE-2024-58136 |
CWE-424 | Critical | 2.0.52 | 28.04.2025 |
SB2025042836 |
||
| #VU90111 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') CVE-2024-4990 |
CWE-470 | High | 2.0.50 | 31.05.2024 |
SB2024053138 |
||
| #VU90108 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-32877 |
CWE-79 | Low | 2.0.50 | 31.05.2024 |
SB2024053138 |
||
| #VU47003 - Deserialization of Untrusted Data CVE-2020-15148 |
CWE-502 | Critical | 2.0.38 | 15.09.2020 |
SB2020092402 |