Yiiframework
Yiiframework YII: vulnerabilidades y CVE
Yiiframework YII tiene 20 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 9 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses1
Críticas9
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-58136 | Crítica (9.8) | 88% | ⚠ Explotación activa | 10 abr 2025 | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-39850 | Alta (7.4) | 0.50% | — | 20 may 2026 | Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local File Inclusion. The function calls extract($_params_,… |
| CVE-2025-32027 | Media (6.1) | 0.24% | — | 10 abr 2025 | Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. Upgrade yiisoft/yii to version 1.1.31 or higher. |
| CVE-2024-58136 | Crítica (9.8) | 88% | ⚠ Explotación activa | 10 abr 2025 | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. |
| CVE-2025-2690 | Media (5.3) | 0.66% | — | 24 mar 2025 | A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src\Framework\MockObject\MockClass.php. The manipulation leads to… |
| CVE-2025-2689 | Media (5.3) | 0.62% | — | 24 mar 2025 | A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The… |
| CVE-2024-4990 | Crítica (9.1) | 80% | — | 20 mar 2025 | In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value passed is a valid Behavior class name or configuration. This allows an… |
| CVE-2024-32877 | Media (4.7) | 0.35% | — | 30 may 2024 | Yii 2 is a PHP application framework. During internal penetration testing of a product based on Yii2, users discovered a Cross-site Scripting (XSS) vulnerability within the framework itself. This issue is relevant for… |
| CVE-2023-47130 | Crítica (9.8) | 3.1% | — | 14 nov 2023 | Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. An attacker may leverage this… |
| CVE-2015-5467 | Crítica (9.8) | 0.88% | — | 21 sept 2023 | web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter. |
| CVE-2022-31454 | Media (6.1) | 0.40% | — | 28 jul 2023 | Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NOTE: this is disputed by the vendor because the cve-2022-31454-8e8555c31fd3 page does not describe why /books… |
| CVE-2023-26750 | Crítica (9.8) | 1.8% | — | 4 abr 2023 | SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the… |
| CVE-2022-41922 | Crítica (9.8) | 1.2% | — | 23 nov 2022 | `yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27. |
| CVE-2021-3692 | Media (5.3) | 1.7% | — | 10 ago 2021 | yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator |
| CVE-2021-3689 | Alta (7.5) | 1.9% | — | 10 ago 2021 | yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator |
| CVE-2020-15148 | Crítica (10) | 79% | — | 15 sept 2020 | Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. This is fixed in version 2.0.38. A possible workaround without… |
| CVE-2018-20745 | Media (5.9) | 0.54% | — | 28 ene 2019 | Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security… |
| CVE-2018-8074 | Alta (8.1) | 1.5% | — | 21 mar 2018 | Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elasticsearch extension. |
| CVE-2018-8073 | Crítica (9.8) | 1.6% | — | 21 mar 2018 | Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with the Redis extension. |
| CVE-2018-7269 | Crítica (9.8) | 1.9% | — | 21 mar 2018 | The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an… |
| CVE-2017-11516 | Media (6.1) | 0.83% | — | 21 jul 2017 | An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception->errorInfo is mishandled. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.