Skip to content
Noroxi

thinksaas records

12 published records for vendor thinksaas.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

12 records
  • ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows

    CriticalCVSS 9.8No exploitEPSS 2%

    thinksaas · thinksaasMar 24, 2021

  • ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    thinksaas · thinksaasJul 16, 2024

  • An issue was discovered in ThinkSAAS 2.91.

    MediumCVSS 6.1No exploitEPSS 1%

    thinksaas · thinksaasSep 21, 2019

  • A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrar

    MediumCVSS 6.1No exploitEPSS 0%

    thinksaas · thinksaasApr 30, 2024

  • Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "

    MediumCVSS 5.3No exploitEPSS 1%

    thinksaas · thinksaasJul 8, 2021

  • ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter.

    MediumCVSS 5.4No exploitEPSS 1%

    thinksaas · thinksaasAug 7, 2018

  • ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.

    MediumCVSS 5.4No exploitEPSS 1%

    thinksaas · thinksaasAug 7, 2018

  • CVE-2024-6941
    21Monitor

    ThinkSAAS do.php cross site scripting

    MediumCVSS 5.3No exploitEPSS 0%

    thinksaas · thinksaasJul 21, 2024

  • CVE-2024-6942
    21Monitor

    ThinkSAAS Admin Panel Security Center anti.php cross site scripting

    MediumCVSS 5.3No exploitEPSS 0%

    thinksaas · thinksaasJul 21, 2024

  • A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitra

    MediumCVSS 5.4No exploitEPSS 0%

    thinksaas · thinksaasApr 30, 2024

  • An issue was discovered in ThinkSAAS 2.91.

    MediumCVSS 4.8No exploitEPSS 1%

    thinksaas · thinksaasSep 21, 2019

  • An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted request.

    LowCVSS 2.7No exploitEPSS 0%

    thinksaas · thinksaasJul 16, 2024