Technology · Packagist
yiisoft/yii2 (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 13 vulnerabilities in yiisoft/yii2 (Packagist): 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2026-39850, was published on 20 May 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 1
- Exploited in the wild
- 1
About yiisoft/yii2 (Packagist)
An object-oriented PHP framework used for developing large-scale web applications.
Latest yiisoft/yii2 (Packagist) vulnerabilities
- CVE-2026-39850: Yii 2 Local File Inclusion in View renderinghighCVSS 7.4EPSS 0.5%
- CVE-2024-58136: yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Keycriticalexploited in the wildCVSS 3.1EPSS 87.8%
- CVE-2024-4990: Unsafe Reflection in base Component class in yiisoft/yii2lowCVSS 3.1EPSS 80.2%
- CVE-2024-32877: Reflected Cross-site Scripting in yiisoft/yii2 Debug modelowCVSS 3.1EPSS 0.4%
- CVE-2015-5467: Yii2 allows attackers to execute any local .php file via a relative path in the view parameterlowCVSS 3.1EPSS 0.9%
- CVE-2023-26750: Withdrawn: SQL injection in Yii 2lowCVSS 3.1EPSS 1.8%
- CVE-2015-3397: Yii Framework Cross-site Scripting VulnerabilityinfoEPSS 2.4%
- CVE-2017-7271: Yii Framework Reflected XSSlowCVSS 3EPSS 1.0%
- CVE-2017-11516: Yii Cross-site Scripting Framework vulnerabilitylowCVSS 3EPSS 0.8%
- CVE-2018-6009: Yii Framework Cross-Site Request Forgery (CSRF)lowCVSS 3EPSS 0.6%
- CVE-2018-20745: Yii Incorrectly Implements CORSlowCVSS 3EPSS 0.5%
- CVE-2018-6010: Yii Framework reflected Cross-site ScriptinglowCVSS 3EPSS 2.9%
- CVE-2020-15148: Unsafe deserialization in Yii 2lowCVSS 3.1EPSS 78.8%
Most severe yiisoft/yii2 (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-58136: yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Keycriticalexploited in the wildCVSS 3.1EPSS 87.8%
- CVE-2026-39850: Yii 2 Local File Inclusion in View renderinghighCVSS 7.4EPSS 0.5%
- CVE-2024-4990: Unsafe Reflection in base Component class in yiisoft/yii2lowCVSS 3.1EPSS 80.2%
- CVE-2020-15148: Unsafe deserialization in Yii 2lowCVSS 3.1EPSS 78.8%
- CVE-2023-26750: Withdrawn: SQL injection in Yii 2lowCVSS 3.1EPSS 1.8%
- CVE-2015-5467: Yii2 allows attackers to execute any local .php file via a relative path in the view parameterlowCVSS 3.1EPSS 0.9%
- CVE-2024-32877: Reflected Cross-site Scripting in yiisoft/yii2 Debug modelowCVSS 3.1EPSS 0.4%
- CVE-2018-6010: Yii Framework reflected Cross-site ScriptinglowCVSS 3EPSS 2.9%
- CVE-2017-7271: Yii Framework Reflected XSSlowCVSS 3EPSS 1.0%
- CVE-2017-11516: Yii Cross-site Scripting Framework vulnerabilitylowCVSS 3EPSS 0.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/yiisoft-yii2.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "yiisoft/yii2 (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/yiisoft-yii2, 28 September 2026.