Перейти к содержимому
Noroxi

Записи thinkcmf

15 опубликованных записей вендора thinkcmf.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
33,3 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

15 записей
  • CVE-2020-20601
    41В плане

    An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.

    КритическаяCVSS 9,8Proof of conceptEPSS 8 %

    thinkcmf · thinkcmf22 дек. 2021 г.

  • CVE-2019-6713
    40В плане

    app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors invol

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    thinkcmf · thinkcmf23 янв. 2019 г.

  • CVE-2024-31615
    39Наблюдать

    ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    thinkcmf · thinkcmf25 апр. 2024 г.

  • CVE-2019-7580
    38Наблюдать

    ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because

    ВысокаяCVSS 8,8Эксплойта нетEPSS 10 %

    thinkcmf · thinkcmf7 февр. 2019 г.

  • CVE-2018-19898
    35Наблюдать

    ThinkCMF X2.2.2 has SQL Injection via the method edit_post in ArticleController.class.php and is exploitable by normal authenticated users v

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    thinkcmf · thinkcmf6 дек. 2018 г.

  • CVE-2022-40489
    35Наблюдать

    ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injecte

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    thinkcmf · thinkcmf1 дек. 2022 г.

  • CVE-2018-19894
    28Наблюдать

    ThinkCMF X2.2.2 has SQL Injection via the functions check() and delete() in CommentadminController.class.php and is exploitable with the man

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    thinkcmf · thinkcmf6 дек. 2018 г.

  • CVE-2018-19896
    28Наблюдать

    ThinkCMF X2.2.2 has SQL Injection via the function delete() in SlideController.class.php and is exploitable with the manager privilege via t

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    thinkcmf · thinkcmf6 дек. 2018 г.

  • CVE-2018-19895
    28Наблюдать

    ThinkCMF X2.2.2 has SQL Injection via the function edit_post() in NavController.class.php and is exploitable with the manager privilege via

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    thinkcmf · thinkcmf6 дек. 2018 г.

  • CVE-2018-19897
    28Наблюдать

    ThinkCMF X2.2.2 has SQL Injection via the function _listorders() in AdminbaseController.class.php and is exploitable with the manager privil

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    thinkcmf · thinkcmf6 дек. 2018 г.

  • CVE-2018-16141
    26Наблюдать

    ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in \application\User\Controller\ProfileController.class.php via an

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    thinkcmf · thinkcmfx30 авг. 2018 г.

  • CVE-2021-40616
    26Наблюдать

    thinkcmf v5.1.7 has an unauthorized vulnerability.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    thinkcmf · thinkcmf14 июн. 2022 г.

  • CVE-2020-18151
    26Наблюдать

    Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account.

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    thinkcmf · thinkcmf14 июл. 2021 г.

  • CVE-2020-25915
    21Наблюдать

    Cross Site Scripting (XSS) vulnerability in UserController.php in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via cra

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    thinkcmf · thinkcmf11 авг. 2023 г.

  • CVE-2022-40849
    21Наблюдать

    ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS).

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    thinkcmf · thinkcmf1 дек. 2022 г.