CRITICAL
9.1 CVE-2026-103475 Published 30 Sept 2026
Yii2 Starter Kit Debug and Gii Modules Exposed to Remote Attacks
Worried this affects your website?
yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration.
Unauthenticated remote attackers can exploit this exposure to:
- Access the debug endpoint and read sensitive data including session cookies and database queries.
- Access the Gii endpoint to generate and write PHP files into the application directory.
Reference: CVE-2026-103475 on NVD
← Back to Security News