Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. Upgrade yiisoft/yii to version 1.1.31 or higher.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-10695 Yii does not prevent XSS in scenarios where fallback error renderer is used
Github GHSA Github GHSA GHSA-7r2v-8wxr-3ch5 Yii does not prevent XSS in scenarios where fallback error renderer is used
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 17 Sep 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Yiiframework
Yiiframework yii
CPEs cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:*
Vendors & Products Yiiframework
Yiiframework yii

Thu, 10 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Apr 2025 14:45:00 +0000

Type Values Removed Values Added
Description Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. Upgrade yiisoft/yii to version 1.1.31 or higher.
Title Yii does not prevent XSS in scenarios where fallback error renderer is used
Weaknesses CWE-79
CWE-80
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-10T14:54:23.272Z

Reserved: 2025-04-01T21:57:32.957Z

Link: CVE-2025-32027

cve-icon Vulnrichment

Updated: 2025-04-10T14:54:13.967Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-10T15:16:05.297

Modified: 2025-09-17T18:30:17.217

Link: CVE-2025-32027

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.