CRITICAL 9.1 CVE-2026-103475 Published 30 Sept 2026

Yii2 Starter Kit Debug and Gii Modules Exposed to Remote Attacks

Worried this affects your website?

yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration.

Unauthenticated remote attackers can exploit this exposure to:

  • Access the debug endpoint and read sensitive data including session cookies and database queries.
  • Access the Gii endpoint to generate and write PHP files into the application directory.

Reference: CVE-2026-103475 on NVD

← Back to Security News