CVE-2025-32027

All FrameworksYiiCWE-79CVE-2025-32027

CVE-2025-32027

State: PUBLISHED · Published: 2025-04-10 · Updated: 2025-04-10 · Assigner: GitHub_M
Description
Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. Upgrade yiisoft/yii to version 1.1.31 or higher.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2025/32xxx/CVE-2025-32027.json