yiisoft/yii2-dev vulnerabilities

Yii PHP Framework Version 2 - Development Package

Latest version: 2.0.26

Continuously find & fix vulnerabilities like these in your dependencies. Test and protect your applications

Direct Vulnerabilities

Known vulnerabilities in the yiisoft/yii2-dev package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable versions Snyk patch Published
  • M
Cross-site Scripting (XSS)
<2.0.13 Not available 12 Jun, 2019
  • H
SQL Injection
<2.0.12.1,>=2.0.13, <2.0.13.2,>=2.0.14, <2.0.15 Not available 21 Mar, 2018
  • M
Cross-site Scripting (XSS)
<2.0.4 Not available 01 Mar, 2018
  • L
Arbitrary File Inclusion
<2.0.5 Not available 01 Mar, 2018
  • H
Cross-site Request Forgery (CSRF)
<2.0.14 Not available 01 Mar, 2018
  • H
Information Exposure
<2.0.14 Not available 01 Mar, 2018
  • M
Cross-site Scripting (XSS)
<2.0.4 Not available 10 May, 2015