thinksaas records
12 published records for vendor thinksaas.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-35337No exploit | ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows thinksaas · thinksaas · CWE-89 | Critical9.8 | — | 1.9% | Mar 24, 2021 |
39Monitor | CVE-2024-40456No exploit | ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.thinksaas · thinksaas · CWE-89 | Critical9.8 | — | 0.5% | Jul 16, 2024 |
24Monitor | CVE-2019-16665No exploit | An issue was discovered in ThinkSAAS 2.91.thinksaas · thinksaas · CWE-79 | Medium6.1 | — | 0.7% | Sep 21, 2019 |
24Monitor | CVE-2024-33101No exploit | A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrarthinksaas · thinksaas · CWE-79 | Medium6.1 | — | 0.4% | Apr 30, 2024 |
21Monitor | CVE-2020-18741No exploit | Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "thinksaas · thinksaas | Medium5.3 | — | 0.9% | Jul 8, 2021 |
21Monitor | CVE-2018-15129No exploit | ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter.thinksaas · thinksaas · CWE-79 | Medium5.4 | — | 0.7% | Aug 7, 2018 |
21Monitor | CVE-2018-15130No exploit | ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.thinksaas · thinksaas · CWE-79 | Medium5.4 | — | 0.7% | Aug 7, 2018 |
21Monitor | CVE-2024-6941No exploit | ThinkSAAS do.php cross site scriptingthinksaas · thinksaas · CWE-79 | Medium5.3 | — | 0.4% | Jul 21, 2024 |
21Monitor | CVE-2024-6942No exploit | ThinkSAAS Admin Panel Security Center anti.php cross site scriptingthinksaas · thinksaas · CWE-79 | Medium5.3 | — | 0.4% | Jul 21, 2024 |
21Monitor | CVE-2024-33102No exploit | A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrathinksaas · thinksaas · CWE-79 | Medium5.4 | — | 0.4% | Apr 30, 2024 |
19Monitor | CVE-2019-16664No exploit | An issue was discovered in ThinkSAAS 2.91.thinksaas · thinksaas · CWE-79 | Medium4.8 | — | 0.6% | Sep 21, 2019 |
10Monitor | CVE-2024-40455No exploit | An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted request.thinksaas · thinksaas · CWE-352 | Low2.7 | — | 0.2% | Jul 16, 2024 |
- CVE-2020-3533740Plan
ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows
CriticalCVSS 9.8No exploitEPSS 2%thinksaas · thinksaasMar 24, 2021
- CVE-2024-4045639Monitor
ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.
CriticalCVSS 9.8No exploitEPSS 1%thinksaas · thinksaasJul 16, 2024
- CVE-2019-1666524Monitor
An issue was discovered in ThinkSAAS 2.91.
MediumCVSS 6.1No exploitEPSS 1%thinksaas · thinksaasSep 21, 2019
- CVE-2024-3310124Monitor
A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrar
MediumCVSS 6.1No exploitEPSS 0%thinksaas · thinksaasApr 30, 2024
- CVE-2020-1874121Monitor
Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "
MediumCVSS 5.3No exploitEPSS 1%thinksaas · thinksaasJul 8, 2021
- CVE-2018-1512921Monitor
ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter.
MediumCVSS 5.4No exploitEPSS 1%thinksaas · thinksaasAug 7, 2018
- CVE-2018-1513021Monitor
ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.
MediumCVSS 5.4No exploitEPSS 1%thinksaas · thinksaasAug 7, 2018
- CVE-2024-694121Monitor
ThinkSAAS do.php cross site scripting
MediumCVSS 5.3No exploitEPSS 0%thinksaas · thinksaasJul 21, 2024
- CVE-2024-694221Monitor
ThinkSAAS Admin Panel Security Center anti.php cross site scripting
MediumCVSS 5.3No exploitEPSS 0%thinksaas · thinksaasJul 21, 2024
- CVE-2024-3310221Monitor
A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitra
MediumCVSS 5.4No exploitEPSS 0%thinksaas · thinksaasApr 30, 2024
- CVE-2019-1666419Monitor
An issue was discovered in ThinkSAAS 2.91.
MediumCVSS 4.8No exploitEPSS 1%thinksaas · thinksaasSep 21, 2019
- CVE-2024-4045510Monitor
An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted request.
LowCVSS 2.7No exploitEPSS 0%thinksaas · thinksaasJul 16, 2024