CVE-2024-58136
Yiiframework Yii
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
- CVSS
- 9.8
- EPSS
- 84.8% 99.7% percentile
- CISA KEV
- Listed
- Published
- 2025.04.10