CVE-2015-5467: Yiiframework Yii
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.
Affected products
- Yiiframework Yii: from 2.0.0, before 2.0.5 (fixed in 2.0.5)
Published 2023-09-21. Last modified 2026-06-17.