CVE-2018-6010: Yiiframework

High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.

In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit reflected XSS on the error handler page in non-debug mode. Related to base/ErrorHandler.php, log/Dispatcher.php, and views/errorHandler/exception.php.

Affected products

  • Yiiframework Yiiframework: version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; version 2.0.5 only; …

Published 2018-01-22. Last modified 2026-06-17.