CVE-2014-4672: Yiiframework

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value property.

Affected products

Published 2014-07-03. Last modified 2026-06-17.