İçeriğe atla
Noroxi

thinkphp kayıtları

thinkphp üreticisine ait 27 yayımlanmış kayıt.

Tüm kayıtlar

27 kayıt
  • ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %97

    thinkphp · thinkphp24 Şub 2019

  • CVE-2022-47945
    47Planlayın

    ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_o

    KritikCVSS 9,8Kavram kanıtıEPSS %28

    thinkphp · thinkphp23 Ara 2022

  • CVE-2022-33107
    46Planlayın

    ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Stor

    KritikCVSS 9,8İstismar yokEPSS %24

    thinkphp · thinkphp29 Haz 2022

  • CVE-2022-38352
    45Planlayın

    ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache.

    KritikCVSS 9,8İstismar yokEPSS %21

    thinkphp · thinkphp14 Eyl 2022

  • CVE-2024-44902
    40Planlayın

    A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    thinkphp · thinkphp9 Eyl 2024

  • CVE-2021-36567
    40Planlayın

    ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.

    KritikCVSS 9,8İstismar yokEPSS %2

    thinkphp · thinkphp6 Ara 2021

  • CVE-2018-16385
    40Planlayın

    ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    thinkphp · thinkphp2 Eyl 2018

  • CVE-2021-36564
    40Planlayın

    ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Stora

    KritikCVSS 9,8İstismar yokEPSS %2

    thinkphp · thinkphp6 Ara 2021

  • CVE-2020-20120
    40Planlayın

    ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query"

    KritikCVSS 9,8İstismar yokEPSS %2

    thinkphp · thinkphp28 Eyl 2021

  • CVE-2021-23592
    40Planlayın

    Deserialization of Untrusted Data

    KritikCVSS 9,8İstismar yokEPSS %2

    thinkphp · thinkphp6 May 2022

  • CVE-2018-18546
    39İzleyin

    ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the ke

    KritikCVSS 9,8İstismar yokEPSS %2

    thinkphp · thinkphp20 Eki 2018

  • CVE-2018-17566
    39İzleyin

    In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's r

    KritikCVSS 9,8İstismar yokEPSS %2

    thinkphp · thinkphp26 Eyl 2018

  • CVE-2021-44350
    39İzleyin

    SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.

    KritikCVSS 9,8İstismar yokEPSS %1

    thinkphp · thinkphp15 Ara 2021

  • CVE-2022-45982
    39İzleyin

    thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %1

    thinkphp · thinkphp8 Şub 2023

  • CVE-2018-18530
    39İzleyin

    ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate

    KritikCVSS 9,8İstismar yokEPSS %1

    thinkphp · thinkphp19 Eki 2018

  • CVE-2018-18529
    39İzleyin

    ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles th

    KritikCVSS 9,8İstismar yokEPSS %1

    thinkphp · thinkphp19 Eki 2018

  • CVE-2018-10225
    39İzleyin

    thinkphp 3.1.3 has SQL Injection via the index.php s parameter.

    KritikCVSS 9,8İstismar yokEPSS %1

    thinkphp · thinkphp19 Nis 2018

  • CVE-2025-50706
    39İzleyin

    An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function

    KritikCVSS 9,8İstismar yokEPSS %1

    thinkphp · thinkphp5 Ağu 2025

  • CVE-2025-50707
    39İzleyin

    An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component

    KritikCVSS 9,8İstismar yokEPSS %1

    thinkphp · thinkphp5 Ağu 2025

  • CVE-2024-48112
    39İzleyin

    A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary co

    KritikCVSS 9,8İstismar yokEPSS %1

    thinkphp · thinkphp30 Eki 2024

  • CVE-2025-63888
    39İzleyin

    The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    thinkphp · thinkphp20 Kas 2025

  • CVE-2018-25270
    37İzleyin

    ThinkPHP 5.0.23 Remote Code Execution via invokefunction

    KritikCVSS 9,3İstismar yokEPSS %1

    thinkphp · thinkphp22 Nis 2026

  • CVE-2022-44289
    36İzleyin

    Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.

    YüksekCVSS 8,8İstismar yokEPSS %3

    thinkphp · thinkphp6 Ara 2022

  • CVE-2021-44892
    36İzleyin

    A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obt

    YüksekCVSS 8,8İstismar yokEPSS %2

    thinkphp · thinkphp10 Şub 2022

  • CVE-2022-25481
    31İzleyin

    ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter.

    YüksekCVSS 7,5Kavram kanıtıEPSS %5

    thinkphp · thinkphp20 Mar 2022