Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

yiisoft — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting yiisoft. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2025-48493 Yii 2 Redis may expose AUTH paramters in logs in case of connection failure — yii2-redisCWE-532 6.5AIMediumAI2025-06-05
CVE-2025-32027 Yii does not prevent XSS in scenarios where fallback error renderer is used — yiiCWE-79 6.1 Medium2025-04-10
CVE-2025-2690 yiisoft Yii2 MockClass.php generate deserialization — Yii2CWE-502 6.3 Medium2025-03-24
CVE-2025-2689 yiisoft Yii2 SortableIterator.php getIterator deserialization — Yii2CWE-502 6.3 Medium2025-03-24
CVE-2024-4990 Unsafe Reflection in base Component class in yiisoft/yii2 — yiisoft/yii2CWE-470 9.8 -2025-03-20
CVE-2024-32877 Reflected Cross-site Scripting in yiisoft/yii2 Debug mode — yii2CWE-79 4.2 Medium2024-05-30
CVE-2023-50714 The Oauth2 PKCE implementation is vulnerable — yii2-authclientCWE-918 6.8 Medium2023-12-22
CVE-2023-50708 yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation — yii2-authclientCWE-203 6.1 Medium2023-12-22
CVE-2023-47130 Unsafe deserialization of user data in yiisoft/yii — yiiCWE-502 8.1 High2023-11-14
CVE-2022-41922 yiisoft/yii before v1.1.27 vulnerable to Remote Code Execution if the application calls `unserialize()` on arbitrary user input — yiiCWE-502 8.1 High2022-11-23
CVE-2021-3692 Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2 — yiisoft/yii2CWE-1241--2021-08-10
CVE-2021-3689 Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2 — yiisoft/yii2CWE-1241--2021-08-10
CVE-2020-15148 Unsafe deserialization in Yii 2 — yii2CWE-502 8.9 High2020-09-15

This page lists every published CVE security advisory associated with yiisoft. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.