Skip to content
Noroxi

thinkjs records

2 published records for vendor thinkjs.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
50%
Median publish → KEV
No record has entered KEV

All records

2 records
  • SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitra

    CriticalCVSS 9.8No exploitEPSS 1%

    thinkjs · thinkjsFeb 1, 2021

  • Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in think-helper

    HighCVSS 7.5No exploitEPSS 1%

    thinkjs · think-helperJun 30, 2021