CVE-2026-103475 - yii2-starter-kit through 4.2.0 Debug and Gii Module Exposure
CVE ID :CVE-2026-103475 Published : Sept. 30, 2026, 6:18 p.m. | 20 minutes ago Description :yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can...