CVE-2026-103474 - yii2-starter-kit through 4.2.0 Unrestricted File Upload RCE
CVE ID :CVE-2026-103474 Published : Sept. 30, 2026, 6:18 p.m. | 20 minutes ago Description :yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP...