CVE-2014-4672: Yiiframework
High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.
The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value property.
Affected products
- Yiiframework Yiiframework: version 1.1.14 only
Published 2014-07-03. Last modified 2026-06-17.