yii2-starter-kit
3 known vulnerabilities in yii2-starter-kit, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-103476 CVSS 6.9 medium yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated…
- CVE-2026-103475 CVSS 9.3 critical yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default…
- CVE-2026-103474 CVSS 8.7 high yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to…