Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

World Economic Forum Cybersecurity Articles

Explore the Forum’s latest opinion articles, timely analyses and explainers from leaders in business, politics, and civil society.