Report a Security Issue

Report vulnerabilities privately to the maintainers of the affected project.

Do not open a public issue or disclose the vulnerability before it has been addressed.

Yii3

Find the repository containing the affected package.

Find the affected package

In the repository, select Security, then “Report a vulnerability.”

Yii 2

Report vulnerabilities in the core framework privately.

Yii 1.1

Report vulnerabilities in the maintained Yii 1.1 framework.

Website

Report vulnerabilities in yiiframework.com or its accounts.

Include affected versions, reproduction steps, impact, and a suggested fix when available. GitHub reporting requires an account. As a non-commercial open-source project, Yii cannot offer bug bounties.