Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Yiiframework

First CVE: Jul 3, 2014Active for: 12 yearsTotal CVEs: 28
67.8
VTI Score
TOP TARGET

Yiiframework is a widely embedded PHP application framework with a modest but concentrated product footprint centered on the Yii core and its ecosystem components such as Gii and the Yii2 authentication client library. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit tooling, reflecting the framework's pervasive role in server-side web application logic. The recurring exposure centers on application-layer input handling and data-deserialization weaknesses—including cross-site scripting, SQL injection, code injection, and untrusted deserialization—that arise from the framework's processing of user input and dynamic code generation patterns. Because Yii is embedded as a dependency across a broad downstream ecosystem of applications, flaws in the framework can propagate across many production deployments, making patch velocity a material concern for defenders maintaining Yii-based services. Live exploitation activity, severity distributions, and exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
3.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Yiiframework over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2014
12 years ago
Most Recent CVE
Jun 5, 2025
414 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-58136CRITICAL
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 202
Apr 10, 20259.897YESYES
CVE-2020-15148CRITICAL
Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. This is fixed in version 2.0.38.
Sep 15, 202010.078NOYES
CVE-2024-4990CRITICAL
In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value passed is a valid Behavior class
Mar 20, 20259.170NONO
CVE-2022-41922CRITICAL
`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27.
Nov 23, 20229.831NONO
CVE-2018-8073CRITICAL
Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with the Redis extension.
Mar 21, 20189.831NONO
CVE-2018-7269CRITICAL
The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, u
Mar 21, 20189.830NONO
CVE-2025-2689CRITICAL
A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterat
Mar 24, 20259.829NONO
CVE-2023-47130CRITICAL
Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user
Nov 14, 20239.829NONO
CVE-2023-26750CRITICAL
SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the soft
Apr 4, 20239.829NONO
CVE-2015-5467CRITICAL
web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.
Sep 21, 20239.827NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
32%
25%
43%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (92.9%)
Unknown2 (7.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (82.1%)
High3 (10.7%)
Unknown2 (7.1%)
User Interaction
None19 (67.9%)
Unknown2 (7.1%)
Required7 (25.0%)
Privileges Required
Low3 (10.7%)
High0 (0.0%)
None23 (82.1%)
Unknown2 (7.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
1 CVE
3.6% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
7.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Yiiframework.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Yiiframework — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Yiiframework's Products

View all 4 CNAs →

Top CWEs