composer›yidashi/yii2cmf›CVE-2018-107046.1 MEDIUMImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')yidashi yii2cmf 2.0 has XSS via the /search q parameter.