{"id":"CVE-2018-7269","aliases":["GHSA-hhg2-g6h6-c266"],"url":"https://o3.security/vulnerability/CVE-2018-7269","summary":"Yii SQL injection vulnerability","details":"The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input.","published":"2018-03-21T18:29:00.237Z","modified":"2026-08-07T14:49:41.554734Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"yiisoft/yii2-dev","fixedVersion":"2.0.12.1"},{"ecosystem":"Packagist","name":"yiisoft/yii2-dev","fixedVersion":"2.0.13.2"},{"ecosystem":"Packagist","name":"yiisoft/yii2-dev","fixedVersion":"2.0.15"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.yiiframework.com/news/168/releasing-yii-2-0-15-and-database-extensions-with-security-fixes/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:49:41.554734Z"}}