CVE-2024-58136: Yiiframework Yii Improper Protection of Alternate Path Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-05-02. EPSS: 87.8% chance of exploitation in the next 30 days.
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
Affected products
- Yiiframework Yii: before 2.0.52 (fixed in 2.0.52)
Published 2025-04-10. Last modified 2026-06-17.