Yii PHP Framework Version 2
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2024-58136 yiisoft/yii2 is vulnerable to Improper Protection of Alternate Path in versions 0.0.0 - 2.0.52. | 0.0.0 - 2.0.52 | Critical |
CVE-2024-4990 yiisoft/yii2 is vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in versions 0.0.0 - 2.0.49.4. | 0.0.0 - 2.0.49.4 | High |
CVE-2024-32877 yiisoft/yii2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.0.43 - 2.0.49.4. | 2.0.43 - 2.0.49.4 | Medium |
CVE-2015-5467 yiisoft/yii2 is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 2.0.0 - 2.0.5. | 2.0.0 - 2.0.5 | Critical |
CVE-2023-26750 yiisoft/yii2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.0.47. | 0.0.0 - 2.0.47 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
cebe/markdown Version ~1.0.0 | ~1.1.0 | ~1.2.0 | — | — |
bower-asset/jquery Version 3.7.*@stable | 3.6.*@stable | 3.5.*@stable | 3.4.*@stable | 3.3.*@stable | 3.2.*@stable | 3.1.*@stable | 2.2.*@stable | 2.1.*@stable | 1.11.*@stable | 1.12.*@stable | — | — |
ezyang/htmlpurifier Version ^4.17 | — | — |
bower-asset/punycode Version ^2.2 | — | — |
bower-asset/inputmask Version ^5.0.8 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant