Composer package intelligence

yiisoft/yii2 Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Composer package yiisoft/yii2, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting yiisoft/yii2
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
yiisoft/yii2 KEVs with sensor-observed exploitation activity

Review yiisoft/yii2 exploitation against the versions you run

All one exploited yiisoft/yii2 vulnerability tracked here is also listed in CISA KEV.

100%
Covered by CISA
0%
Beyond CISA

Attested yiisoft/yii2 vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2024-58136

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the...

In CISA 05 May 2025

Recurring weakness patterns

Improper Protection of Alternate Path account for mapped occurrences across this yiisoft/yii2 KEV portfolio.

Browse all KEVs →