Medium severity6.1NVD Advisory· Published Jun 13, 2018· Updated Jun 17, 2026
CVE-2018-12290
CVE-2018-12290
Description
The Yii2-StateMachine extension v2.x.x for Yii2 has XSS.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ptheofan/yii2-statemachinePackagist | >= 2.0.0-RC1, <= 2.0.0 | — |
Affected products
2- cpe:2.3:a:yii2-statemachine:yii2-statemachine:2.x.x:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- www.iwantacve.cn/index.php/archives/40/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-65qg-f77j-cccfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-12290ghsaADVISORY
- web.archive.org/web/20180624194633/http://www.iwantacve.cn/index.php/archives/40ghsaWEB
News mentions
0No linked articles in our index yet.