Skip to content
COOEY

EXPOSURES › CVE-2024-58136

CVE-2024-58136

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-05-02 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-58136 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wild

A vulnerability in the Yii framework allows remote code execution, impacting systems using it like Craft CMS and actively being exploited in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement Yii, including—but not limited to—Craft CMS, as represented by CVE-2025-32432.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.