Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. Upgrade yiisoft/yii to version 1.1.31 or higher.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-10695 Yii does not prevent XSS in scenarios where fallback error renderer is used
Github GHSA Github GHSA GHSA-7r2v-8wxr-3ch5 Yii does not prevent XSS in scenarios where fallback error renderer is used
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 18 Sep 2025 03:45:00 +0900

Type Values Removed Values Added
First Time appeared Yiiframework
Yiiframework yii
CPEs cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:*
Vendors & Products Yiiframework
Yiiframework yii

Fri, 11 Apr 2025 00:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Apr 2025 23:45:00 +0900

Type Values Removed Values Added
Description Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. Upgrade yiisoft/yii to version 1.1.31 or higher.
Title Yii does not prevent XSS in scenarios where fallback error renderer is used
Weaknesses CWE-79
CWE-80
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-10T14:54:23.272Z

Reserved: 2025-04-01T21:57:32.957Z

Link: CVE-2025-32027

cve-icon Vulnrichment

Updated: 2025-04-10T14:54:13.967Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-10T15:16:05.297

Modified: 2025-09-17T18:30:17.217

Link: CVE-2025-32027

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses