Skip to content
Noroxi

thinkcmf records

15 published records for vendor thinkcmf.

All records

15 records
  • An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.

    CriticalCVSS 9.8Proof of conceptEPSS 8%

    thinkcmf · thinkcmfDec 22, 2021

  • app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors invol

    CriticalCVSS 9.8No exploitEPSS 2%

    thinkcmf · thinkcmfJan 23, 2019

  • ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    thinkcmf · thinkcmfApr 25, 2024

  • CVE-2019-7580
    38Monitor

    ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because

    HighCVSS 8.8No exploitEPSS 10%

    thinkcmf · thinkcmfFeb 7, 2019

  • ThinkCMF X2.2.2 has SQL Injection via the method edit_post in ArticleController.class.php and is exploitable by normal authenticated users v

    HighCVSS 8.8No exploitEPSS 1%

    thinkcmf · thinkcmfDec 6, 2018

  • ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injecte

    HighCVSS 8.8No exploitEPSS 0%

    thinkcmf · thinkcmfDec 1, 2022

  • ThinkCMF X2.2.2 has SQL Injection via the functions check() and delete() in CommentadminController.class.php and is exploitable with the man

    HighCVSS 7.2No exploitEPSS 1%

    thinkcmf · thinkcmfDec 6, 2018

  • ThinkCMF X2.2.2 has SQL Injection via the function delete() in SlideController.class.php and is exploitable with the manager privilege via t

    HighCVSS 7.2No exploitEPSS 1%

    thinkcmf · thinkcmfDec 6, 2018

  • ThinkCMF X2.2.2 has SQL Injection via the function edit_post() in NavController.class.php and is exploitable with the manager privilege via

    HighCVSS 7.2No exploitEPSS 1%

    thinkcmf · thinkcmfDec 6, 2018

  • ThinkCMF X2.2.2 has SQL Injection via the function _listorders() in AdminbaseController.class.php and is exploitable with the manager privil

    HighCVSS 7.2No exploitEPSS 1%

    thinkcmf · thinkcmfDec 6, 2018

  • ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in \application\User\Controller\ProfileController.class.php via an

    MediumCVSS 6.5No exploitEPSS 1%

    thinkcmf · thinkcmfxAug 30, 2018

  • thinkcmf v5.1.7 has an unauthorized vulnerability.

    MediumCVSS 6.5No exploitEPSS 1%

    thinkcmf · thinkcmfJun 14, 2022

  • Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account.

    MediumCVSS 6.5No exploitEPSS 0%

    thinkcmf · thinkcmfJul 14, 2021

  • Cross Site Scripting (XSS) vulnerability in UserController.php in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via cra

    MediumCVSS 5.4No exploitEPSS 0%

    thinkcmf · thinkcmfAug 11, 2023

  • ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS).

    MediumCVSS 5.4No exploitEPSS 0%

    thinkcmf · thinkcmfDec 1, 2022