It's another issue of Yii development notes. This time it's short but news are good.
Yii team made two patch releases for 2.0.14 and then released 2.0.15 fixing security issue. Extra patch releases were made for 2.0.12 and 2.0.13 in case developers can't upgrade right now. The issue itself was described in a news announcement.
There is some progress on 2.1 branch. Paul Klimov made a post about it recently. You can already try installing 2.1.
Yii-related websites got HTTPS
Official website launched!