Thinkphp records
27 published records for vendor thinkphp.
Researcher profile
- Entered KEV
- 1 · 3.7%
- Weaponized
- 1 · 3.7%
- Pre-auth RCE
- 11
- With a fix record
- 18.5%
- Median publish → KEV
- 983 days
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-502 Deserialization of Untrusted Data8
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-668 Exposure of Resource to Wrong Sphere1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
94Now | CVE-2019-9082Weaponized | ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\appthinkphp · thinkphp · CWE-94 | High8.8 | KEV | 97.4% | Feb 24, 2019 |
47Plan | CVE-2022-47945Proof of concept | ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_othinkphp · thinkphp · CWE-22 | Critical9.8 | — | 28.3% | Dec 23, 2022 |
46Plan | CVE-2022-33107No exploit | ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storthinkphp · thinkphp · CWE-502 | Critical9.8 | — | 23.9% | Jun 29, 2022 |
45Plan | CVE-2022-38352No exploit | ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache.thinkphp · thinkphp · CWE-502 | Critical9.8 | — | 20.6% | Sep 14, 2022 |
40Plan | CVE-2024-44902Proof of concept | A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.thinkphp · thinkphp · CWE-502 | Critical9.8 | — | 4.2% | Sep 9, 2024 |
40Plan | CVE-2021-36567No exploit | ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.thinkphp · thinkphp · CWE-502 | Critical9.8 | — | 2.5% | Dec 6, 2021 |
40Plan | CVE-2018-16385Proof of concept | ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.thinkphp · thinkphp · CWE-89 | Critical9.8 | — | 2.2% | Sep 2, 2018 |
40Plan | CVE-2021-36564No exploit | ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storathinkphp · thinkphp · CWE-502 | Critical9.8 | — | 1.9% | Dec 6, 2021 |
40Plan | CVE-2020-20120No exploit | ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" thinkphp · thinkphp · CWE-89 | Critical9.8 | — | 1.8% | Sep 28, 2021 |
40Plan | CVE-2021-23592No exploit | Deserialization of Untrusted Datathinkphp · thinkphp · CWE-502 | Critical9.8 | — | 1.7% | May 6, 2022 |
39Monitor | CVE-2018-18546No exploit | ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the kethinkphp · thinkphp · CWE-89 | Critical9.8 | — | 1.7% | Oct 20, 2018 |
39Monitor | CVE-2018-17566No exploit | In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's rthinkphp · thinkphp · CWE-89 | Critical9.8 | — | 1.5% | Sep 26, 2018 |
39Monitor | CVE-2021-44350No exploit | SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.thinkphp · thinkphp · CWE-89 | Critical9.8 | — | 1.4% | Dec 15, 2021 |
39Monitor | CVE-2022-45982No exploit | thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability.thinkphp · thinkphp · CWE-502 | Critical9.8 | — | 1.2% | Feb 8, 2023 |
39Monitor | CVE-2018-18530No exploit | ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregatethinkphp · thinkphp · CWE-89 | Critical9.8 | — | 1.2% | Oct 19, 2018 |
39Monitor | CVE-2018-18529No exploit | ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles ththinkphp · thinkphp · CWE-89 | Critical9.8 | — | 1.2% | Oct 19, 2018 |
39Monitor | CVE-2018-10225No exploit | thinkphp 3.1.3 has SQL Injection via the index.php s parameter.thinkphp · thinkphp · CWE-89 | Critical9.8 | — | 1.1% | Apr 19, 2018 |
39Monitor | CVE-2025-50706No exploit | An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck functionthinkphp · thinkphp · CWE-94 | Critical9.8 | — | 1.0% | Aug 5, 2025 |
39Monitor | CVE-2025-50707No exploit | An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php componentthinkphp · thinkphp · CWE-94 | Critical9.8 | — | 1.0% | Aug 5, 2025 |
39Monitor | CVE-2024-48112No exploit | A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary cothinkphp · thinkphp · CWE-502 | Critical9.8 | — | 0.9% | Oct 30, 2024 |
39Monitor | CVE-2025-63888Proof of concept | The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.thinkphp · thinkphp · CWE-98 | Critical9.8 | — | 0.6% | Nov 20, 2025 |
37Monitor | CVE-2018-25270No exploit | ThinkPHP 5.0.23 Remote Code Execution via invokefunctionthinkphp · thinkphp · CWE-639 | Critical9.3 | — | 0.9% | Apr 22, 2026 |
36Monitor | CVE-2022-44289No exploit | Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.thinkphp · thinkphp · CWE-434 | High8.8 | — | 3.0% | Dec 6, 2022 |
36Monitor | CVE-2021-44892No exploit | A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtthinkphp · thinkphp | High8.8 | — | 2.0% | Feb 10, 2022 |
31Monitor | CVE-2022-25481Proof of concept | ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter.thinkphp · thinkphp · CWE-668 | High7.5 | — | 4.7% | Mar 20, 2022 |
- CVE-2019-908294Now
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app
HighCVSS 8.8KEVWeaponizedEPSS 97%thinkphp · thinkphpFeb 24, 2019
- CVE-2022-4794547Plan
ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_o
CriticalCVSS 9.8Proof of conceptEPSS 28%thinkphp · thinkphpDec 23, 2022
- CVE-2022-3310746Plan
ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Stor
CriticalCVSS 9.8No exploitEPSS 24%thinkphp · thinkphpJun 29, 2022
- CVE-2022-3835245Plan
ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache.
CriticalCVSS 9.8No exploitEPSS 21%thinkphp · thinkphpSep 14, 2022
- CVE-2024-4490240Plan
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
CriticalCVSS 9.8Proof of conceptEPSS 4%thinkphp · thinkphpSep 9, 2024
- CVE-2021-3656740Plan
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.
CriticalCVSS 9.8No exploitEPSS 2%thinkphp · thinkphpDec 6, 2021
- CVE-2018-1638540Plan
ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.
CriticalCVSS 9.8Proof of conceptEPSS 2%thinkphp · thinkphpSep 2, 2018
- CVE-2021-3656440Plan
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Stora
CriticalCVSS 9.8No exploitEPSS 2%thinkphp · thinkphpDec 6, 2021
- CVE-2020-2012040Plan
ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query"
CriticalCVSS 9.8No exploitEPSS 2%thinkphp · thinkphpSep 28, 2021
- CVE-2021-2359240Plan
Deserialization of Untrusted Data
CriticalCVSS 9.8No exploitEPSS 2%thinkphp · thinkphpMay 6, 2022
- CVE-2018-1854639Monitor
ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the ke
CriticalCVSS 9.8No exploitEPSS 2%thinkphp · thinkphpOct 20, 2018
- CVE-2018-1756639Monitor
In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's r
CriticalCVSS 9.8No exploitEPSS 2%thinkphp · thinkphpSep 26, 2018
- CVE-2021-4435039Monitor
SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.
CriticalCVSS 9.8No exploitEPSS 1%thinkphp · thinkphpDec 15, 2021
- CVE-2022-4598239Monitor
thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%thinkphp · thinkphpFeb 8, 2023
- CVE-2018-1853039Monitor
ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate
CriticalCVSS 9.8No exploitEPSS 1%thinkphp · thinkphpOct 19, 2018
- CVE-2018-1852939Monitor
ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles th
CriticalCVSS 9.8No exploitEPSS 1%thinkphp · thinkphpOct 19, 2018
- CVE-2018-1022539Monitor
thinkphp 3.1.3 has SQL Injection via the index.php s parameter.
CriticalCVSS 9.8No exploitEPSS 1%thinkphp · thinkphpApr 19, 2018
- CVE-2025-5070639Monitor
An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function
CriticalCVSS 9.8No exploitEPSS 1%thinkphp · thinkphpAug 5, 2025
- CVE-2025-5070739Monitor
An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component
CriticalCVSS 9.8No exploitEPSS 1%thinkphp · thinkphpAug 5, 2025
- CVE-2024-4811239Monitor
A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary co
CriticalCVSS 9.8No exploitEPSS 1%thinkphp · thinkphpOct 30, 2024
- CVE-2025-6388839Monitor
The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.
CriticalCVSS 9.8Proof of conceptEPSS 1%thinkphp · thinkphpNov 20, 2025
- CVE-2018-2527037Monitor
ThinkPHP 5.0.23 Remote Code Execution via invokefunction
CriticalCVSS 9.3No exploitEPSS 1%thinkphp · thinkphpApr 22, 2026
- CVE-2022-4428936Monitor
Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.
HighCVSS 8.8No exploitEPSS 3%thinkphp · thinkphpDec 6, 2022
- CVE-2021-4489236Monitor
A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obt
HighCVSS 8.8No exploitEPSS 2%thinkphp · thinkphpFeb 10, 2022
- CVE-2022-2548131Monitor
ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter.
HighCVSS 7.5Proof of conceptEPSS 5%thinkphp · thinkphpMar 20, 2022