{"id":"GHSA-7r2v-8wxr-3ch5","summary":"Yii does not prevent XSS in scenarios where fallback error renderer is used","details":"### Impact\nAffected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used.\n\n### Patches\nUpgrade yiisoft/yii to version 1.1.31 or higher.\n\n### References\n- [Git commit](https://github.com/yiisoft/yii/commit/d386d737861c9014269b7ed8c36c65eadb387368)\n\nIf you have any questions or comments about this advisory, [contact us through security form](https://www.yiiframework.com/security).","aliases":["CVE-2025-32027"],"modified":"2025-04-11T14:43:22.403665Z","published":"2025-04-11T14:05:18Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-04-11T14:05:18Z","nvd_published_at":"2025-04-10T15:16:05Z","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/yiisoft/yii/security/advisories/GHSA-7r2v-8wxr-3ch5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32027"},{"type":"WEB","url":"https://github.com/yiisoft/yii/commit/d386d737861c9014269b7ed8c36c65eadb387368"},{"type":"PACKAGE","url":"https://github.com/yiisoft/yii"}],"affected":[{"package":{"name":"yiisoft/yii","ecosystem":"Packagist","purl":"pkg:composer/yiisoft/yii"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.31"}]}],"versions":["1.1.14","1.1.14-rc","1.1.15","1.1.16","1.1.17","1.1.18","1.1.19","1.1.20","1.1.21","1.1.22","1.1.23","1.1.24","1.1.25","1.1.26","1.1.27","1.1.28","1.1.29","1.1.30"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-7r2v-8wxr-3ch5/GHSA-7r2v-8wxr-3ch5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}