Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

Yii Software

Yii PHP framework
Collective - Host: opensource - https://opencollective.com/yiisoft - Website: https://www.yiiframework.com/ - Code: https://github.com/yiisoft

High
yii2: GSA_kwCzR0hTQS1jamNjLXA2N20tN3F4bc4AA8mV
Unsafe Reflection in base Component class in yiisoft/yii2
Ecosystems: packagist
Packages: yiisoft/yii2
Source: github
Published: 7 months ago
Moderate
yii2: GSA_kwCzR0hTQS1xZzVyLTk1bTQtbWpnas4AA8mM
Reflected Cross-site Scripting in yiisoft/yii2 Debug mode
Ecosystems: packagist
Packages: yiisoft/yii2
Source: github
Published: 7 months ago
Low
yii2-authclient: GSA_kwCzR0hTQS13OHZoLXA3NGoteDl4cM4AA34Q
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
Ecosystems: packagist
Packages: yiisoft/yii2-authclient
Source: github
Published: about 1 year ago
Moderate
yii2-authclient: GSA_kwCzR0hTQS1ydzU0LTY4MjYtYzhqNc4AA34O
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
Ecosystems: packagist
Packages: yiisoft/yii2-authclient
Source: github
Published: about 1 year ago
High
yii: GSA_kwCzR0hTQS1tdzJ3LTJoajItZmc4cc4AA3Kz
yiisoft/yii deserializing untrusted user input can lead to remote code execution
Ecosystems: packagist
Packages: yiisoft/yii
Source: github
Published: about 1 year ago
Critical
yii2: GSA_kwCzR0hTQS1ncTYzLXAzOXAtanJqZs4AAyiN
Withdrawn: SQL injection in Yii 2
Ecosystems: packagist
Packages: yiisoft/yii2
Source: github
Published: over 1 year ago
High
yii2-gii: GSA_kwCzR0hTQS0zbXBnLXEyNmotODNqNc4AAxHH
Command injection in yiisoft/yii2-gii
Ecosystems: packagist
Packages: yiisoft/yii2-gii
Source: github
Published: almost 2 years ago
High
yii: GSA_kwCzR0hTQS00NDJmLXdjd3EtZnBjZs4AAv_K
Prevent RCE when deserializing untrusted user input
Ecosystems: packagist
Packages: yiisoft/yii
Source: github
Published: about 2 years ago
Moderate
yii2: GSA_kwCzR0hTQS13Mnh4LWpwOWYtZ3A4Z84AActh
Yii Framework Cross-site Scripting Vulnerability
Ecosystems: packagist
Packages: yiisoft/yii2
Source: github
Published: over 2 years ago
Moderate
yii2: GSA_kwCzR0hTQS00eGg5LTV2aDgtM3A1OM4AAbo9
Yii Framework Reflected XSS
Ecosystems: packagist
Packages: yiisoft/yii2
Source: github
Published: over 2 years ago
Moderate
yii2: GSA_kwCzR0hTQS00YzY0LXc4ZmcteGNxMs4AAbIO
Yii Cross-site Scripting Framework vulnerability
Ecosystems: packagist
Packages: yiisoft/yii2, yiisoft/yii2-dev
Source: github
Published: over 2 years ago
High
yii2: GSA_kwCzR0hTQS1jd2htLTI3MnAtM3dqOc4AAXbQ
Yii Framework Cross-Site Request Forgery (CSRF)
Ecosystems: packagist
Packages: yiisoft/yii2-dev, yiisoft/yii2
Source: github
Published: over 2 years ago
Moderate
yii2: GSA_kwCzR0hTQS1jcjZyLTZ4bTktd3cyMs4AAUL8
Yii Incorrectly Implements CORS
Ecosystems: packagist
Packages: yiisoft/yii2
Source: github
Published: over 2 years ago
High
yii2: GSA_kwCzR0hTQS04Z2ZxLWM1NG0tM3JmNs3_HQ
Yii Framework reflected Cross-site Scripting
Ecosystems: packagist
Packages: yiisoft/yii2
Source: github
Published: over 2 years ago
High
yii2: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhxM3Ytcmc2Zi02aHg0
Use of Insufficiently Random Values in yiisoft/yii2-dev
Ecosystems: packagist
Packages: yiisoft/yii2-dev
Source: github
Published: over 3 years ago
Moderate
yii2: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXd3dnYteDVtcS1oM2pq
Use of Cryptographically Weak Pseudo-Random Number Generator in yiisoft/yii2-dev
Ecosystems: packagist
Packages: yiisoft/yii2-dev
Source: github
Published: over 3 years ago
High
yii2: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTY5OXEtd2NmZi1nOW1q
Unsafe deserialization in Yii 2
Ecosystems: packagist
Packages: yiisoft/yii2
Source: github
Published: over 4 years ago