CVE-2024-58136: Yiiframework Yii Improper Protection of Alternate Path Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-05-02. EPSS: 87.8% chance of exploitation in the next 30 days.

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

Affected products

Published 2025-04-10. Last modified 2026-06-17.