Yiiframework is a widely embedded PHP application framework with a modest but concentrated product footprint centered on the Yii core and its ecosystem components such as Gii and the Yii2 authentication client library. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit tooling, reflecting the framework's pervasive role in server-side web application logic. The recurring exposure centers on application-layer input handling and data-deserialization weaknesses—including cross-site scripting, SQL injection, code injection, and untrusted deserialization—that arise from the framework's processing of user input and dynamic code generation patterns. Because Yii is embedded as a dependency across a broad downstream ecosystem of applications, flaws in the framework can propagate across many production deployments, making patch velocity a material concern for defenders maintaining Yii-based services. Live exploitation activity, severity distributions, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yiiframework over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-58136CRITICAL Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 202 | Apr 10, 2025 | 9.8 | 97 | YES | YES |
CVE-2020-15148CRITICAL Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. This is fixed in version 2.0.38. | Sep 15, 2020 | 10.0 | 78 | NO | YES |
CVE-2024-4990CRITICAL In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value passed is a valid Behavior class | Mar 20, 2025 | 9.1 | 70 | NO | NO |
CVE-2022-41922CRITICAL `yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27. | Nov 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-8073CRITICAL Yii 2.x before 2.0.15 allows remote attackers to execute arbitrary LUA code via a variant of the CVE-2018-7269 attack in conjunction with the Redis extension. | Mar 21, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-7269CRITICAL The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, u | Mar 21, 2018 | 9.8 | 30 | NO | NO |
CVE-2025-2689CRITICAL A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterat | Mar 24, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-47130CRITICAL Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user | Nov 14, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-26750CRITICAL SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the soft | Apr 4, 2023 | 9.8 | 29 | NO | NO |
CVE-2015-5467CRITICAL web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter. | Sep 21, 2023 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yiiframework.
Media articles that mention a CVE ID that affects a product developed by Yiiframework — matched by CVE ID, not by vendor name.