Critical severity9.8NVD Advisory· Published Apr 4, 2023· Updated Jun 17, 2026
CVE-2023-26750
CVE-2023-26750
Description
SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
yiisoft/yii2Packagist | < 2.0.47 | 2.0.47 |
Affected products
3- Yii Framework/Yii 2 Frameworkdescription
Patches
Vulnerability mechanics
References
6- github.com/yiisoft/yii2/issues/19755nvdExploitIssue TrackingWEB
- github.com/advisories/GHSA-gq63-p39p-jrjfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-26750ghsaADVISORY
- github.com/yiisoft/yii2/issues/19755nvdWEB
- github.com/yiisoft/yii2/issues/19755nvdWEB
- github.com/yiisoft/yii2/issues/19755nvdWEB
News mentions
0No linked articles in our index yet.