Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-58136

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.286
EPSS Ranking 96.3%
CVSS Severity
CVSS v3 Score 9.0
Proposed Action
Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement Yii, including—but not limited to—Craft CMS, as represented by CVE-2025-32432.
Ransomware Campaign
Unknown
Products affected by CVE-2024-58136


Contact Us

Shodan ® - All rights reserved