๐Ÿ” CVE Alert

CVE-2026-103475

CRITICAL 9.1

yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory.

CWE CWE-489
Vendor yii2-starter-kit
Product yii2-starter-kit
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for yii2-starter-kit yii2-starter-kit

Be the first to know when new critical vulnerabilities affecting yii2-starter-kit yii2-starter-kit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

yii2-starter-kit / yii2-starter-kit
0 โ‰ค 4.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/yii-starter-kit/yii2-starter-kit/issues/797 github.com: https://github.com/yii-starter-kit/yii2-starter-kit github.com: https://github.com/yii-starter-kit/yii2-starter-kit/blob/cc2c451e8c959c7300b04efea597706a38609f58/common/config/web.php#L21 vulncheck.com: https://www.vulncheck.com/advisories/yii2-starter-kit-through-4.2.0-debug-and-gii-module-exposure

Credits

Vikash Gupta