yiisoft/yii
Yii PHP Framework 1.1.x
Activity
- Latest release
- 8mo ago
- Total releases
- 20
- Cadence
- ~9 months
- Last 12 months
- 1
Reach
- Stars
- 4.8k
Details
- License
- BSD-3-Clause
- First release
- Jul 14, 2013
| Version | Released | |
|---|---|---|
1.1.32
patch
|
1.1.32
patch
Changelog
Compare changes
|
|
1.1.31
patch
| ||
1.1.30
patch
1 CVE
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev | ||
1.1.29
patch
1 CVE
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev | ||
1.1.28
patch
2 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.27
patch
2 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.26
patch
3 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-41922
GHSA-442f-wcwq-fpcf
Nov 21, 2022
Prevent RCE when deserializing untrusted user input
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 2 more Show less
1.1.25
1.1.26
Fixed in
1.1.27
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.1.25
patch
3 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-41922
GHSA-442f-wcwq-fpcf
Nov 21, 2022
Prevent RCE when deserializing untrusted user input
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 2 more Show less
1.1.25
1.1.26
Fixed in
1.1.27
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.1.24
patch
3 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-41922
GHSA-442f-wcwq-fpcf
Nov 21, 2022
Prevent RCE when deserializing untrusted user input
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 2 more Show less
1.1.25
1.1.26
Fixed in
1.1.27
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.1.23
patch
3 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-41922
GHSA-442f-wcwq-fpcf
Nov 21, 2022
Prevent RCE when deserializing untrusted user input
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 2 more Show less
1.1.25
1.1.26
Fixed in
1.1.27
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.1.22
patch
3 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-41922
GHSA-442f-wcwq-fpcf
Nov 21, 2022
Prevent RCE when deserializing untrusted user input
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 2 more Show less
1.1.25
1.1.26
Fixed in
1.1.27
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.1.21
patch
3 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-41922
GHSA-442f-wcwq-fpcf
Nov 21, 2022
Prevent RCE when deserializing untrusted user input
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 2 more Show less
1.1.25
1.1.26
Fixed in
1.1.27
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.1.20
patch
3 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-41922
GHSA-442f-wcwq-fpcf
Nov 21, 2022
Prevent RCE when deserializing untrusted user input
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 2 more Show less
1.1.25
1.1.26
Fixed in
1.1.27
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.1.19
patch
3 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-41922
GHSA-442f-wcwq-fpcf
Nov 21, 2022
Prevent RCE when deserializing untrusted user input
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 2 more Show less
1.1.25
1.1.26
Fixed in
1.1.27
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.1.18
patch
3 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-41922
GHSA-442f-wcwq-fpcf
Nov 21, 2022
Prevent RCE when deserializing untrusted user input
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 2 more Show less
1.1.25
1.1.26
Fixed in
1.1.27
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.1.17
patch
3 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-41922
GHSA-442f-wcwq-fpcf
Nov 21, 2022
Prevent RCE when deserializing untrusted user input
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 2 more Show less
1.1.25
1.1.26
Fixed in
1.1.27
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.1.16
patch
3 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-41922
GHSA-442f-wcwq-fpcf
Nov 21, 2022
Prevent RCE when deserializing untrusted user input
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 2 more Show less
1.1.25
1.1.26
Fixed in
1.1.27
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.1.15
patch
3 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-41922
GHSA-442f-wcwq-fpcf
Nov 21, 2022
Prevent RCE when deserializing untrusted user input
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 2 more Show less
1.1.25
1.1.26
Fixed in
1.1.27
References Updated Nov 08, 2023 · Source: OSV.dev | ||
1.1.14
initial
4 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-41922
GHSA-442f-wcwq-fpcf
Nov 21, 2022
Prevent RCE when deserializing untrusted user input
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 2 more Show less
1.1.25
1.1.26
Fixed in
1.1.27
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2014-4672
GHSA-74qv-rv53-5wcx
May 17, 2022
Yii PHP Framework arbitrary PHP scripts execution
High
The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value property. Affected versions
1.1.14
Fixed in
1.1.15
References Updated Dec 07, 2024 · Source: OSV.dev | ||
1.1.14-rc
pre
3 CVEs
CVE-2025-32027
GHSA-7r2v-8wxr-3ch5
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
ImpactAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. PatchesUpgrade yiisoft/yii to version 1.1.31 or higher. ReferencesIf you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 6 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
1.1.29
1.1.30
Fixed in
1.1.31
References Updated Apr 11, 2025 · Source: OSV.dev
CVE-2023-47130
GHSA-mw2w-2hj2-fg8q
Nov 14, 2023
yiisoft/yii deserializing untrusted user input can lead to remote code execution
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 4 more Show less
1.1.25
1.1.26
1.1.27
1.1.28
Fixed in
1.1.29
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2022-41922
GHSA-442f-wcwq-fpcf
Nov 21, 2022
Prevent RCE when deserializing untrusted user input
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactAffected versions of PatchesUpgrade For more informationSee the following links for more details:
If you have any questions or comments about this advisory, contact us through security form. Affected versions
1.1.14
1.1.14-rc
1.1.15
1.1.16
1.1.17
1.1.18
1.1.19
1.1.20
1.1.21
1.1.22
1.1.23
1.1.24
+ 2 more Show less
1.1.25
1.1.26
Fixed in
1.1.27
References Updated Nov 08, 2023 · Source: OSV.dev |