Browse all 13 CVE security advisories affecting yiisoft. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Yii Framework is a PHP-based web application development platform focused on building secure and efficient web applications. Historically, common vulnerabilities include cross-site scripting (XSS), remote code execution (RCE), and privilege escalation issues, often stemming from improper input validation and access control flaws. The framework has experienced several security incidents, including a 2019 vulnerability in its debug module that allowed RCE, and a 2021 XSS flaw in its GridView component. Despite these issues, the project maintains active security practices, with regular patches and a CVE count of 13 as of current records, reflecting its ongoing commitment to addressing security concerns in its ecosystem.
This page lists every published CVE security advisory associated with yiisoft. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.