yiisoft/yii2
[READ ONLY] Yii 2 framework core code only. This is a subtree split off the "yii2" repository
Activity
- Latest release
- May 09, 2026
- Total releases
- 80
- Cadence
- ~29 days
- Last 12 months
- 2
Reach
- Stars
- 234
Details
- License
- BSD-3-Clause
- First release
- Dec 01, 2013
| Version | Released | |
|---|---|---|
2.0.55
patch
|
2.0.55
patch
Dependencies (7)
Changelog
Compare changes
|
|
2.0.54
patch
1 CVE
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev | ||
2.0.53
patch
1 CVE
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev |
2.0.53
patch
Dependencies (7)
Changelog
Compare changes
|
|
2.0.52
patch
1 CVE
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev | ||
2.0.51
patch
2 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev |
2.0.51
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.0.49.4
patch
2 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev |
2.0.49.4
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.0.50
patch
2 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev | ||
2.0.49.3
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2024-32877
GHSA-qg5r-95m4-mjgj
Jun 02, 2024
Reflected Cross-site Scripting in yiisoft/yii2 Debug mode
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
During the internal penetration testing of our product based on Yii2, we discovered an XSS vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). Conditions for vulnerability reproduction
Vulnerability descriptionThe issue lies in the mechanism for displaying function argument values in the stack trace. The vulnerability manifests when an argument's value exceeds 32 characters. For convenience, argument values exceeding this limit are truncated and displayed with an added "...". The full argument value becomes visible when hovering over it with the mouse, as it is displayed in the title attribute of a span tag. However, the use of a double quote (") allows an attacker to break out of the title attribute's value context and inject their own attributes into the span tag, including malicious JavaScript code through event handlers such as onmousemove. Demonstration example: http://31.184.254.143/about/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa%22%20onmousemove=alert(1)%20style=%22width:%20100000px;%20height:%20100000px;%20position:%20absolute;%20top:%20-10000px;%20left:%200;%22 Impact of the vulnerabilityThis vulnerability allows an attacker to execute arbitrary JavaScript code in the security context of the victim's site via a specially crafted link. This could lead to the theft of cookies (including httpOnly cookies, which are accessible on the page), content substitution, or complete takeover of user accounts. Technical analysis and mitigation suggestionUpon analyzing the framework's source code, it was found that data handling for the title attribute is performed in the file framework/web/ErrorHandler.php. The identified problem is related to changes made in the commit https://github.com/yiisoft/yii2/commit/8cc9aeb2f0b2ffe02fb54a817064e9da75512706 , which led to the disabling of encoding for single and double quotes in the htmlEncode method (https://github.com/yiisoft/yii2/blob/8cc9aeb2f0b2ffe02fb54a817064e9da75512706/framework/web/ErrorHandler.php#L183) due to the addition of the ENT_NOQUOTES flag. To address this issue while preserving the functionality intended by the commit, we suggest modifying the htmlEncode method as follows:
This change will effectively prevent the XSS vulnerability while maintaining the targeted functionality of the previous changes. ConclusionBased on the above, we strongly recommend implementing the suggested changes to the project's main code as soon as possible to protect framework users from potential attacks. I am ready to provide further information or assistance, including creating a pull request if necessary. Affected versions
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
Fixed in
2.0.49.4
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
2.0.49.2
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2024-32877
GHSA-qg5r-95m4-mjgj
Jun 02, 2024
Reflected Cross-site Scripting in yiisoft/yii2 Debug mode
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
During the internal penetration testing of our product based on Yii2, we discovered an XSS vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). Conditions for vulnerability reproduction
Vulnerability descriptionThe issue lies in the mechanism for displaying function argument values in the stack trace. The vulnerability manifests when an argument's value exceeds 32 characters. For convenience, argument values exceeding this limit are truncated and displayed with an added "...". The full argument value becomes visible when hovering over it with the mouse, as it is displayed in the title attribute of a span tag. However, the use of a double quote (") allows an attacker to break out of the title attribute's value context and inject their own attributes into the span tag, including malicious JavaScript code through event handlers such as onmousemove. Demonstration example: http://31.184.254.143/about/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa%22%20onmousemove=alert(1)%20style=%22width:%20100000px;%20height:%20100000px;%20position:%20absolute;%20top:%20-10000px;%20left:%200;%22 Impact of the vulnerabilityThis vulnerability allows an attacker to execute arbitrary JavaScript code in the security context of the victim's site via a specially crafted link. This could lead to the theft of cookies (including httpOnly cookies, which are accessible on the page), content substitution, or complete takeover of user accounts. Technical analysis and mitigation suggestionUpon analyzing the framework's source code, it was found that data handling for the title attribute is performed in the file framework/web/ErrorHandler.php. The identified problem is related to changes made in the commit https://github.com/yiisoft/yii2/commit/8cc9aeb2f0b2ffe02fb54a817064e9da75512706 , which led to the disabling of encoding for single and double quotes in the htmlEncode method (https://github.com/yiisoft/yii2/blob/8cc9aeb2f0b2ffe02fb54a817064e9da75512706/framework/web/ErrorHandler.php#L183) due to the addition of the ENT_NOQUOTES flag. To address this issue while preserving the functionality intended by the commit, we suggest modifying the htmlEncode method as follows:
This change will effectively prevent the XSS vulnerability while maintaining the targeted functionality of the previous changes. ConclusionBased on the above, we strongly recommend implementing the suggested changes to the project's main code as soon as possible to protect framework users from potential attacks. I am ready to provide further information or assistance, including creating a pull request if necessary. Affected versions
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
Fixed in
2.0.49.4
References
Updated Jul 08, 2024 · Source: OSV.dev |
2.0.49.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.0.49.1
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2024-32877
GHSA-qg5r-95m4-mjgj
Jun 02, 2024
Reflected Cross-site Scripting in yiisoft/yii2 Debug mode
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
During the internal penetration testing of our product based on Yii2, we discovered an XSS vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). Conditions for vulnerability reproduction
Vulnerability descriptionThe issue lies in the mechanism for displaying function argument values in the stack trace. The vulnerability manifests when an argument's value exceeds 32 characters. For convenience, argument values exceeding this limit are truncated and displayed with an added "...". The full argument value becomes visible when hovering over it with the mouse, as it is displayed in the title attribute of a span tag. However, the use of a double quote (") allows an attacker to break out of the title attribute's value context and inject their own attributes into the span tag, including malicious JavaScript code through event handlers such as onmousemove. Demonstration example: http://31.184.254.143/about/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa%22%20onmousemove=alert(1)%20style=%22width:%20100000px;%20height:%20100000px;%20position:%20absolute;%20top:%20-10000px;%20left:%200;%22 Impact of the vulnerabilityThis vulnerability allows an attacker to execute arbitrary JavaScript code in the security context of the victim's site via a specially crafted link. This could lead to the theft of cookies (including httpOnly cookies, which are accessible on the page), content substitution, or complete takeover of user accounts. Technical analysis and mitigation suggestionUpon analyzing the framework's source code, it was found that data handling for the title attribute is performed in the file framework/web/ErrorHandler.php. The identified problem is related to changes made in the commit https://github.com/yiisoft/yii2/commit/8cc9aeb2f0b2ffe02fb54a817064e9da75512706 , which led to the disabling of encoding for single and double quotes in the htmlEncode method (https://github.com/yiisoft/yii2/blob/8cc9aeb2f0b2ffe02fb54a817064e9da75512706/framework/web/ErrorHandler.php#L183) due to the addition of the ENT_NOQUOTES flag. To address this issue while preserving the functionality intended by the commit, we suggest modifying the htmlEncode method as follows:
This change will effectively prevent the XSS vulnerability while maintaining the targeted functionality of the previous changes. ConclusionBased on the above, we strongly recommend implementing the suggested changes to the project's main code as soon as possible to protect framework users from potential attacks. I am ready to provide further information or assistance, including creating a pull request if necessary. Affected versions
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
Fixed in
2.0.49.4
References
Updated Jul 08, 2024 · Source: OSV.dev |
2.0.49.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.0.49
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2024-32877
GHSA-qg5r-95m4-mjgj
Jun 02, 2024
Reflected Cross-site Scripting in yiisoft/yii2 Debug mode
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
During the internal penetration testing of our product based on Yii2, we discovered an XSS vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). Conditions for vulnerability reproduction
Vulnerability descriptionThe issue lies in the mechanism for displaying function argument values in the stack trace. The vulnerability manifests when an argument's value exceeds 32 characters. For convenience, argument values exceeding this limit are truncated and displayed with an added "...". The full argument value becomes visible when hovering over it with the mouse, as it is displayed in the title attribute of a span tag. However, the use of a double quote (") allows an attacker to break out of the title attribute's value context and inject their own attributes into the span tag, including malicious JavaScript code through event handlers such as onmousemove. Demonstration example: http://31.184.254.143/about/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa%22%20onmousemove=alert(1)%20style=%22width:%20100000px;%20height:%20100000px;%20position:%20absolute;%20top:%20-10000px;%20left:%200;%22 Impact of the vulnerabilityThis vulnerability allows an attacker to execute arbitrary JavaScript code in the security context of the victim's site via a specially crafted link. This could lead to the theft of cookies (including httpOnly cookies, which are accessible on the page), content substitution, or complete takeover of user accounts. Technical analysis and mitigation suggestionUpon analyzing the framework's source code, it was found that data handling for the title attribute is performed in the file framework/web/ErrorHandler.php. The identified problem is related to changes made in the commit https://github.com/yiisoft/yii2/commit/8cc9aeb2f0b2ffe02fb54a817064e9da75512706 , which led to the disabling of encoding for single and double quotes in the htmlEncode method (https://github.com/yiisoft/yii2/blob/8cc9aeb2f0b2ffe02fb54a817064e9da75512706/framework/web/ErrorHandler.php#L183) due to the addition of the ENT_NOQUOTES flag. To address this issue while preserving the functionality intended by the commit, we suggest modifying the htmlEncode method as follows:
This change will effectively prevent the XSS vulnerability while maintaining the targeted functionality of the previous changes. ConclusionBased on the above, we strongly recommend implementing the suggested changes to the project's main code as soon as possible to protect framework users from potential attacks. I am ready to provide further information or assistance, including creating a pull request if necessary. Affected versions
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
Fixed in
2.0.49.4
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
2.0.48.1
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2024-32877
GHSA-qg5r-95m4-mjgj
Jun 02, 2024
Reflected Cross-site Scripting in yiisoft/yii2 Debug mode
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
During the internal penetration testing of our product based on Yii2, we discovered an XSS vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). Conditions for vulnerability reproduction
Vulnerability descriptionThe issue lies in the mechanism for displaying function argument values in the stack trace. The vulnerability manifests when an argument's value exceeds 32 characters. For convenience, argument values exceeding this limit are truncated and displayed with an added "...". The full argument value becomes visible when hovering over it with the mouse, as it is displayed in the title attribute of a span tag. However, the use of a double quote (") allows an attacker to break out of the title attribute's value context and inject their own attributes into the span tag, including malicious JavaScript code through event handlers such as onmousemove. Demonstration example: http://31.184.254.143/about/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa%22%20onmousemove=alert(1)%20style=%22width:%20100000px;%20height:%20100000px;%20position:%20absolute;%20top:%20-10000px;%20left:%200;%22 Impact of the vulnerabilityThis vulnerability allows an attacker to execute arbitrary JavaScript code in the security context of the victim's site via a specially crafted link. This could lead to the theft of cookies (including httpOnly cookies, which are accessible on the page), content substitution, or complete takeover of user accounts. Technical analysis and mitigation suggestionUpon analyzing the framework's source code, it was found that data handling for the title attribute is performed in the file framework/web/ErrorHandler.php. The identified problem is related to changes made in the commit https://github.com/yiisoft/yii2/commit/8cc9aeb2f0b2ffe02fb54a817064e9da75512706 , which led to the disabling of encoding for single and double quotes in the htmlEncode method (https://github.com/yiisoft/yii2/blob/8cc9aeb2f0b2ffe02fb54a817064e9da75512706/framework/web/ErrorHandler.php#L183) due to the addition of the ENT_NOQUOTES flag. To address this issue while preserving the functionality intended by the commit, we suggest modifying the htmlEncode method as follows:
This change will effectively prevent the XSS vulnerability while maintaining the targeted functionality of the previous changes. ConclusionBased on the above, we strongly recommend implementing the suggested changes to the project's main code as soon as possible to protect framework users from potential attacks. I am ready to provide further information or assistance, including creating a pull request if necessary. Affected versions
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
Fixed in
2.0.49.4
References
Updated Jul 08, 2024 · Source: OSV.dev |
2.0.48.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.0.48
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2024-32877
GHSA-qg5r-95m4-mjgj
Jun 02, 2024
Reflected Cross-site Scripting in yiisoft/yii2 Debug mode
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
During the internal penetration testing of our product based on Yii2, we discovered an XSS vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). Conditions for vulnerability reproduction
Vulnerability descriptionThe issue lies in the mechanism for displaying function argument values in the stack trace. The vulnerability manifests when an argument's value exceeds 32 characters. For convenience, argument values exceeding this limit are truncated and displayed with an added "...". The full argument value becomes visible when hovering over it with the mouse, as it is displayed in the title attribute of a span tag. However, the use of a double quote (") allows an attacker to break out of the title attribute's value context and inject their own attributes into the span tag, including malicious JavaScript code through event handlers such as onmousemove. Demonstration example: http://31.184.254.143/about/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa%22%20onmousemove=alert(1)%20style=%22width:%20100000px;%20height:%20100000px;%20position:%20absolute;%20top:%20-10000px;%20left:%200;%22 Impact of the vulnerabilityThis vulnerability allows an attacker to execute arbitrary JavaScript code in the security context of the victim's site via a specially crafted link. This could lead to the theft of cookies (including httpOnly cookies, which are accessible on the page), content substitution, or complete takeover of user accounts. Technical analysis and mitigation suggestionUpon analyzing the framework's source code, it was found that data handling for the title attribute is performed in the file framework/web/ErrorHandler.php. The identified problem is related to changes made in the commit https://github.com/yiisoft/yii2/commit/8cc9aeb2f0b2ffe02fb54a817064e9da75512706 , which led to the disabling of encoding for single and double quotes in the htmlEncode method (https://github.com/yiisoft/yii2/blob/8cc9aeb2f0b2ffe02fb54a817064e9da75512706/framework/web/ErrorHandler.php#L183) due to the addition of the ENT_NOQUOTES flag. To address this issue while preserving the functionality intended by the commit, we suggest modifying the htmlEncode method as follows:
This change will effectively prevent the XSS vulnerability while maintaining the targeted functionality of the previous changes. ConclusionBased on the above, we strongly recommend implementing the suggested changes to the project's main code as soon as possible to protect framework users from potential attacks. I am ready to provide further information or assistance, including creating a pull request if necessary. Affected versions
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
Fixed in
2.0.49.4
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
2.0.47
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2024-32877
GHSA-qg5r-95m4-mjgj
Jun 02, 2024
Reflected Cross-site Scripting in yiisoft/yii2 Debug mode
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
During the internal penetration testing of our product based on Yii2, we discovered an XSS vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). Conditions for vulnerability reproduction
Vulnerability descriptionThe issue lies in the mechanism for displaying function argument values in the stack trace. The vulnerability manifests when an argument's value exceeds 32 characters. For convenience, argument values exceeding this limit are truncated and displayed with an added "...". The full argument value becomes visible when hovering over it with the mouse, as it is displayed in the title attribute of a span tag. However, the use of a double quote (") allows an attacker to break out of the title attribute's value context and inject their own attributes into the span tag, including malicious JavaScript code through event handlers such as onmousemove. Demonstration example: http://31.184.254.143/about/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa%22%20onmousemove=alert(1)%20style=%22width:%20100000px;%20height:%20100000px;%20position:%20absolute;%20top:%20-10000px;%20left:%200;%22 Impact of the vulnerabilityThis vulnerability allows an attacker to execute arbitrary JavaScript code in the security context of the victim's site via a specially crafted link. This could lead to the theft of cookies (including httpOnly cookies, which are accessible on the page), content substitution, or complete takeover of user accounts. Technical analysis and mitigation suggestionUpon analyzing the framework's source code, it was found that data handling for the title attribute is performed in the file framework/web/ErrorHandler.php. The identified problem is related to changes made in the commit https://github.com/yiisoft/yii2/commit/8cc9aeb2f0b2ffe02fb54a817064e9da75512706 , which led to the disabling of encoding for single and double quotes in the htmlEncode method (https://github.com/yiisoft/yii2/blob/8cc9aeb2f0b2ffe02fb54a817064e9da75512706/framework/web/ErrorHandler.php#L183) due to the addition of the ENT_NOQUOTES flag. To address this issue while preserving the functionality intended by the commit, we suggest modifying the htmlEncode method as follows:
This change will effectively prevent the XSS vulnerability while maintaining the targeted functionality of the previous changes. ConclusionBased on the above, we strongly recommend implementing the suggested changes to the project's main code as soon as possible to protect framework users from potential attacks. I am ready to provide further information or assistance, including creating a pull request if necessary. Affected versions
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
Fixed in
2.0.49.4
References
Updated Jul 08, 2024 · Source: OSV.dev |
2.0.47
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.0.46
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2024-32877
GHSA-qg5r-95m4-mjgj
Jun 02, 2024
Reflected Cross-site Scripting in yiisoft/yii2 Debug mode
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
During the internal penetration testing of our product based on Yii2, we discovered an XSS vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). Conditions for vulnerability reproduction
Vulnerability descriptionThe issue lies in the mechanism for displaying function argument values in the stack trace. The vulnerability manifests when an argument's value exceeds 32 characters. For convenience, argument values exceeding this limit are truncated and displayed with an added "...". The full argument value becomes visible when hovering over it with the mouse, as it is displayed in the title attribute of a span tag. However, the use of a double quote (") allows an attacker to break out of the title attribute's value context and inject their own attributes into the span tag, including malicious JavaScript code through event handlers such as onmousemove. Demonstration example: http://31.184.254.143/about/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa%22%20onmousemove=alert(1)%20style=%22width:%20100000px;%20height:%20100000px;%20position:%20absolute;%20top:%20-10000px;%20left:%200;%22 Impact of the vulnerabilityThis vulnerability allows an attacker to execute arbitrary JavaScript code in the security context of the victim's site via a specially crafted link. This could lead to the theft of cookies (including httpOnly cookies, which are accessible on the page), content substitution, or complete takeover of user accounts. Technical analysis and mitigation suggestionUpon analyzing the framework's source code, it was found that data handling for the title attribute is performed in the file framework/web/ErrorHandler.php. The identified problem is related to changes made in the commit https://github.com/yiisoft/yii2/commit/8cc9aeb2f0b2ffe02fb54a817064e9da75512706 , which led to the disabling of encoding for single and double quotes in the htmlEncode method (https://github.com/yiisoft/yii2/blob/8cc9aeb2f0b2ffe02fb54a817064e9da75512706/framework/web/ErrorHandler.php#L183) due to the addition of the ENT_NOQUOTES flag. To address this issue while preserving the functionality intended by the commit, we suggest modifying the htmlEncode method as follows:
This change will effectively prevent the XSS vulnerability while maintaining the targeted functionality of the previous changes. ConclusionBased on the above, we strongly recommend implementing the suggested changes to the project's main code as soon as possible to protect framework users from potential attacks. I am ready to provide further information or assistance, including creating a pull request if necessary. Affected versions
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
Fixed in
2.0.49.4
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
2.0.45
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2024-32877
GHSA-qg5r-95m4-mjgj
Jun 02, 2024
Reflected Cross-site Scripting in yiisoft/yii2 Debug mode
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
During the internal penetration testing of our product based on Yii2, we discovered an XSS vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). Conditions for vulnerability reproduction
Vulnerability descriptionThe issue lies in the mechanism for displaying function argument values in the stack trace. The vulnerability manifests when an argument's value exceeds 32 characters. For convenience, argument values exceeding this limit are truncated and displayed with an added "...". The full argument value becomes visible when hovering over it with the mouse, as it is displayed in the title attribute of a span tag. However, the use of a double quote (") allows an attacker to break out of the title attribute's value context and inject their own attributes into the span tag, including malicious JavaScript code through event handlers such as onmousemove. Demonstration example: http://31.184.254.143/about/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa%22%20onmousemove=alert(1)%20style=%22width:%20100000px;%20height:%20100000px;%20position:%20absolute;%20top:%20-10000px;%20left:%200;%22 Impact of the vulnerabilityThis vulnerability allows an attacker to execute arbitrary JavaScript code in the security context of the victim's site via a specially crafted link. This could lead to the theft of cookies (including httpOnly cookies, which are accessible on the page), content substitution, or complete takeover of user accounts. Technical analysis and mitigation suggestionUpon analyzing the framework's source code, it was found that data handling for the title attribute is performed in the file framework/web/ErrorHandler.php. The identified problem is related to changes made in the commit https://github.com/yiisoft/yii2/commit/8cc9aeb2f0b2ffe02fb54a817064e9da75512706 , which led to the disabling of encoding for single and double quotes in the htmlEncode method (https://github.com/yiisoft/yii2/blob/8cc9aeb2f0b2ffe02fb54a817064e9da75512706/framework/web/ErrorHandler.php#L183) due to the addition of the ENT_NOQUOTES flag. To address this issue while preserving the functionality intended by the commit, we suggest modifying the htmlEncode method as follows:
This change will effectively prevent the XSS vulnerability while maintaining the targeted functionality of the previous changes. ConclusionBased on the above, we strongly recommend implementing the suggested changes to the project's main code as soon as possible to protect framework users from potential attacks. I am ready to provide further information or assistance, including creating a pull request if necessary. Affected versions
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
Fixed in
2.0.49.4
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
2.0.44
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2024-32877
GHSA-qg5r-95m4-mjgj
Jun 02, 2024
Reflected Cross-site Scripting in yiisoft/yii2 Debug mode
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
During the internal penetration testing of our product based on Yii2, we discovered an XSS vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). Conditions for vulnerability reproduction
Vulnerability descriptionThe issue lies in the mechanism for displaying function argument values in the stack trace. The vulnerability manifests when an argument's value exceeds 32 characters. For convenience, argument values exceeding this limit are truncated and displayed with an added "...". The full argument value becomes visible when hovering over it with the mouse, as it is displayed in the title attribute of a span tag. However, the use of a double quote (") allows an attacker to break out of the title attribute's value context and inject their own attributes into the span tag, including malicious JavaScript code through event handlers such as onmousemove. Demonstration example: http://31.184.254.143/about/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa%22%20onmousemove=alert(1)%20style=%22width:%20100000px;%20height:%20100000px;%20position:%20absolute;%20top:%20-10000px;%20left:%200;%22 Impact of the vulnerabilityThis vulnerability allows an attacker to execute arbitrary JavaScript code in the security context of the victim's site via a specially crafted link. This could lead to the theft of cookies (including httpOnly cookies, which are accessible on the page), content substitution, or complete takeover of user accounts. Technical analysis and mitigation suggestionUpon analyzing the framework's source code, it was found that data handling for the title attribute is performed in the file framework/web/ErrorHandler.php. The identified problem is related to changes made in the commit https://github.com/yiisoft/yii2/commit/8cc9aeb2f0b2ffe02fb54a817064e9da75512706 , which led to the disabling of encoding for single and double quotes in the htmlEncode method (https://github.com/yiisoft/yii2/blob/8cc9aeb2f0b2ffe02fb54a817064e9da75512706/framework/web/ErrorHandler.php#L183) due to the addition of the ENT_NOQUOTES flag. To address this issue while preserving the functionality intended by the commit, we suggest modifying the htmlEncode method as follows:
This change will effectively prevent the XSS vulnerability while maintaining the targeted functionality of the previous changes. ConclusionBased on the above, we strongly recommend implementing the suggested changes to the project's main code as soon as possible to protect framework users from potential attacks. I am ready to provide further information or assistance, including creating a pull request if necessary. Affected versions
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
Fixed in
2.0.49.4
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
2.0.43
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2024-32877
GHSA-qg5r-95m4-mjgj
Jun 02, 2024
Reflected Cross-site Scripting in yiisoft/yii2 Debug mode
4.2
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
None
During the internal penetration testing of our product based on Yii2, we discovered an XSS vulnerability within the framework itself. This issue is relevant for the latest version of Yii2 (2.0.49.3). Conditions for vulnerability reproduction
Vulnerability descriptionThe issue lies in the mechanism for displaying function argument values in the stack trace. The vulnerability manifests when an argument's value exceeds 32 characters. For convenience, argument values exceeding this limit are truncated and displayed with an added "...". The full argument value becomes visible when hovering over it with the mouse, as it is displayed in the title attribute of a span tag. However, the use of a double quote (") allows an attacker to break out of the title attribute's value context and inject their own attributes into the span tag, including malicious JavaScript code through event handlers such as onmousemove. Demonstration example: http://31.184.254.143/about/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa%22%20onmousemove=alert(1)%20style=%22width:%20100000px;%20height:%20100000px;%20position:%20absolute;%20top:%20-10000px;%20left:%200;%22 Impact of the vulnerabilityThis vulnerability allows an attacker to execute arbitrary JavaScript code in the security context of the victim's site via a specially crafted link. This could lead to the theft of cookies (including httpOnly cookies, which are accessible on the page), content substitution, or complete takeover of user accounts. Technical analysis and mitigation suggestionUpon analyzing the framework's source code, it was found that data handling for the title attribute is performed in the file framework/web/ErrorHandler.php. The identified problem is related to changes made in the commit https://github.com/yiisoft/yii2/commit/8cc9aeb2f0b2ffe02fb54a817064e9da75512706 , which led to the disabling of encoding for single and double quotes in the htmlEncode method (https://github.com/yiisoft/yii2/blob/8cc9aeb2f0b2ffe02fb54a817064e9da75512706/framework/web/ErrorHandler.php#L183) due to the addition of the ENT_NOQUOTES flag. To address this issue while preserving the functionality intended by the commit, we suggest modifying the htmlEncode method as follows:
This change will effectively prevent the XSS vulnerability while maintaining the targeted functionality of the previous changes. ConclusionBased on the above, we strongly recommend implementing the suggested changes to the project's main code as soon as possible to protect framework users from potential attacks. I am ready to provide further information or assistance, including creating a pull request if necessary. Affected versions
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
Fixed in
2.0.49.4
References
Updated Jul 08, 2024 · Source: OSV.dev | ||
2.0.42.1
patch
3 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev |
2.0.42.1
patch
Dependencies (7)
Changelog
Compare changes
|
|
2.0.42
patch
3 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev | ||
2.0.41.1
patch
3 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev | ||
2.0.41
patch
3 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev | ||
2.0.40
patch
3 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev | ||
2.0.39.3
patch
3 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev | ||
2.0.39.2
patch
3 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev | ||
2.0.39.1
patch
3 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev | ||
2.0.39
patch
3 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev | ||
2.0.38
patch
3 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev | ||
2.0.37
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.36
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.35
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.0.35
patch
Dependencies (7)
Changelog
Compare changes
|
|
2.0.34
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.33
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.32
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.31
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.30
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.29
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.28
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.27
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.26
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.25
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.24
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.23
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.22
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.21
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.20
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.19
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.18
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.0.18
patch
Dependencies (7)
Changelog
Compare changes
|
|
2.0.17
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.16.1
patch
4 CVEs
CVE-2026-39850
GHSA-5vpg-rj7q-qpw2
May 11, 2026
Yii 2: Local file inclusion via view parameter name collision
7.4
/ 10
High
Network
High
None
None
Unchanged
High
High
None
The core view rendering method Impact
Patches2.0.55 WorkaroundsNo. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 67 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.55
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2024-58136
GHSA-ggwg-cmwp-46r5
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
9.0
/ 10
Critical
Network
High
None
None
Changed
High
High
High
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 64 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.49.4
2.0.5
2.0.50
2.0.51
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.52
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2024-4990
GHSA-cjcc-p67m-7qxm
Jun 02, 2024
Unsafe Reflection in base Component class in yiisoft/yii2
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
Yii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the ImpactWith some effort malicious code can be injected executed which might be anything ranging from deleting files to dropping database tables PatchesNot yet patched. WorkaroundsNo Work around available ReferencesReported Here in case the link is dead, here is the full description DescriptionYii2 supports attaching Behaviors to Components by setting properties having the format Internally this is done using the Depending on the installed dependencies various kind of attacks are possible. Proof of ConceptA PoC application was created using Yii JSON parser was enabled in the configuration:
A vulnerable controller was added:
Executing phpinfo()Following command stores the content of
It leverages the fact that Executing arbitrary MySQL queries (blind execution)If the application is connected to a MySQL database it is possible to exploit the
Notice that the server will always return a 500 Internal Server Error (because the instantiated class is not a Behavior), however the query is executed, even if we can't receive any output from it. If the query fails we might see a PDO error message (i.e. "Table 'test.foo' doesn't exist"), depending on the app configuration. ImpactIt is not trivial to exploit this bug, because it depends on peculiar characteristics of the target application. However, it looks that there is at least one very popular product built on Yii2 that is severely affected by this vulnerability (allowing to an anonymous user to gain admin access, with an easy exploit). The consequences of the exploitation could vary from retrieving sensitive information to DoS or unauthorized access. OccurrencesAffected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 61 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.39.1
2.0.39.2
2.0.39.3
2.0.4
2.0.40
2.0.41
2.0.41.1
2.0.42
2.0.42.1
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.48.1
2.0.49
2.0.49.1
2.0.49.2
2.0.49.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.49.4
References
Updated Apr 01, 2025 · Source: OSV.dev
CVE-2020-15148
GHSA-699q-wcff-g9mj
Sep 15, 2020
Unsafe deserialization in Yii 2
8.9
/ 10
High
Network
High
None
None
Changed
Low
High
High
ImpactRemote code execution in case application calls Patches2.0.38 WorkaroundsAdd the following to BatchQueryResult.php:
For more informationIf you have any questions or comments about this advisory, contact us through security form. Affected versions
2.0.0
2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.1
2.0.10
2.0.11
2.0.11.1
2.0.11.2
2.0.12
2.0.12.1
2.0.12.2
+ 40 more Show less
2.0.13
2.0.13.1
2.0.13.2
2.0.13.3
2.0.14
2.0.14.1
2.0.14.2
2.0.15
2.0.15.1
2.0.16
2.0.16.1
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
Fixed in
2.0.38
References
Updated Jul 08, 2026 · Source: OSV.dev |