thinkjs records
2 published records for vendor thinkjs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-21176No exploit | SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrathinkjs · thinkjs · CWE-89 | Critical9.8 | — | 1.5% | Feb 1, 2021 |
30Monitor | CVE-2021-32736No exploit | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in think-helperthinkjs · think-helper · CWE-1321 | High7.5 | — | 1.0% | Jun 30, 2021 |
- CVE-2020-2117639Monitor
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitra
CriticalCVSS 9.8No exploitEPSS 1%thinkjs · thinkjsFeb 1, 2021
- CVE-2021-3273630Monitor
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in think-helper
HighCVSS 7.5No exploitEPSS 1%thinkjs · think-helperJun 30, 2021