yiisoft/yii2 Security Advisories for 2.0.51 (2)
-
[HIGH] Yii 2: Local file inclusion via view parameter name collision
PKSA-mxtc-f5ct-dqqd CVE-2026-39850 GHSA-5vpg-rj7q-qpw2
Affected version: <2.0.55
Reported by:
GitHub -
[CRITICAL] yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
PKSA-zmx9-v1jv-dy8s CVE-2024-58136 GHSA-ggwg-cmwp-46r5
Affected version: <2.0.52
Reported by:
GitHub