Report vulnerabilities privately to the maintainers of the affected project.
Do not open a public issue or disclose the vulnerability before it has been addressed.
Find the repository containing the affected package.
In the repository, select Security, then “Report a vulnerability.”
Report vulnerabilities in the core framework privately.
Report vulnerabilities in the maintained Yii 1.1 framework.
Report vulnerabilities in yiiframework.com or its accounts.
Include affected versions, reproduction steps, impact, and a suggested fix when available. GitHub reporting requires an account. As a non-commercial open-source project, Yii cannot offer bug bounties.