CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

yiiframework

gii

2 known vulnerabilities · sorted by CVSS score

CVE-2020-36655
HIGH8.8

Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.

yiiframework / gii
Network
Published Jan 21, 2023
CVE-2022-34297
MEDIUM5.4

Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field.

yiiframework / gii
Network
Published Dec 9, 2022