VYPR

Yii2 Starter Kit

by Yii Starter Kit

CVEs (3)

  • CVE-2026-103475CriSep 30, 2026
    risk 0.59cvss 9.1epss —

    yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and…

  • CVE-2026-103474HigSep 30, 2026
    risk 0.57cvss 8.8epss —

    yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute…

  • CVE-2026-103476MedSep 30, 2026
    risk 0.34cvss 5.3epss —

    yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished…