{"id":"CVE-2018-7269","aliases":["GHSA-hhg2-g6h6-c266"],"url":"https://o3.security/vulnerability/CVE-2018-7269","summary":"Yii SQL injection vulnerability","details":"The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input.","published":"2018-03-21T18:29:00.237Z","modified":"2026-08-07T14:49:41.554734Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01338,"percentile":0.69871,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"yiisoft/yii2-dev","fixedVersion":"2.0.12.1"},{"ecosystem":"Packagist","name":"yiisoft/yii2-dev","fixedVersion":"2.0.13.2"},{"ecosystem":"Packagist","name":"yiisoft/yii2-dev","fixedVersion":"2.0.15"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.yiiframework.com/news/168/releasing-yii-2-0-15-and-database-extensions-with-security-fixes/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-7269"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/yiisoft/yii2-dev/CVE-2018-7269.yaml"},{"type":"PACKAGE","url":"https://github.com/yiisoft/yii2"},{"type":"WEB","url":"https://www.yiiframework.com/news/168/releasing-yii-2-0-15-and-database-extensions-with-security-fixes"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:49:41.554734Z"}}