CVE-2024-58136 is a critical vulnerability affecting Yii 2 before version 2.0.52, stemming from improper handling of behavior defined by an __class array key, and is a regression of CVE-2024-4990. This flaw allows for unauthenticated remote code execution with high impact on confidentiality, integrity, and availability, as indicated by its CVSS score of 9.8. The vulnerability is actively exploited in the wild, with evidence of exploitation in February through April 2025, and has garnered significant community attention and media coverage, including its use in Craft CMS zero-day attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.52CPE matchmatch criteria | cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:* | ||
>= 2, < 2.0.52CPE match | cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.