CVE-2015-5467: Yiiframework Yii

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.

Affected products

Published 2023-09-21. Last modified 2026-06-17.