EUVD-2025-10502
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 2 May 2025. Evidence sources: cisa_kev.
- ENISA score
- 9.0 · CVSS 3.1
- Advisory evidence
- No linked advisory details stored yet
