CVE-2021-3692
yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.36%
- CWE
- CWE-1241
- Published
- 2021-08-10
- Last modified
- 2026-03-13
Affected products
- yiisoft yiisoft/yii2
Weakness type
Related vulnerabilities
- CVE-2026-73576 — In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability...
- CVE-2026-57869 — Broken object-level access controls and the use of a deterministic pattern during random ID...
- CVE-2026-6420 — Keylime: keylime: security bypass due to hardcoded tpm quote nonce
- CVE-2025-13079 — Popup Builder - Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens
- CVE-2025-32056 — Anti-Theft Bypass for Infotainment ECU
- CVE-2023-4695 — Use of Predictable Algorithm in Random Number Generator in pkp/pkp-lib
- CVE-2021-3689 — Use of Predictable Algorithm in Random Number Generator in yiisoft/yii2