GHSA-ggwg-cmwp-46r5 · Severity: critical · Ecosystem: composer — yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
Conclusion & alert: CVE-2024-58136 is rated Critical Active Threat (100/100): CVSS Critical severity, with high exploitation likelihood (EPSS 78.95%, 99th percentile). Core evidence: CISA KEV confirms active exploitation (added 2025-05-02) affecting Yiiframework / Yii. a weakness (CWE-424) Unauthenticated remote administrative access may be possible. EPSS rose +19.92% over the last day, indicating growing attacker interest. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Yiiframework Yii Improper Protection of Alternate Path Vulnerability · CISA KEV detail
: 2025-05-02
: 2025-05-23
: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-19 | 59.03% | 78.95% | +19.92% |
| 2 | 2026-05-18 | 57.53% | 59.03% | +1.49% |
| 3 | 2026-03-24 | — | 57.53% | — |
Full EPSS history (31 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.0 | 3.1 | CRITICAL |
|
2.2 | 6.0 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-ggwg-cmwp-46r5 · Severity: critical · Ecosystem: composer — yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| yiiframework | yii | < 2.0.52 | cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/yiisoft/yii2/commit/40fe496eda529fd1d933b56a1022ec32d3cd0b12 | Patch |
| https://github.com/yiisoft/yii2/compare/2.0.51...2.0.52 | Issue Tracking |
| https://github.com/yiisoft/yii2/pull/20232 | Patch |
| https://github.com/yiisoft/yii2/pull/20232#issuecomment-2252459709 | Issue Tracking |
| https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52 | Vendor Advisory |
| https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce-in-craftcms/ | Exploit Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-58136 | US Government Resource |