thinkphp kayıtları
thinkphp üreticisine ait 27 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %3,7
- Silahlaştırılmış
- 1 · %3,7
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %18,5
- Yayından KEV’e ortanca
- 983 gün
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')8
- CWE-502 Deserialization of Untrusted Data8
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-668 Exposure of Resource to Wrong Sphere1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
27 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
94Hemen | CVE-2019-9082Silahlaştırılmış | ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\appthinkphp · thinkphp · CWE-94 | Yüksek8,8 | KEV | %97,4 | 24 Şub 2019 |
47Planlayın | CVE-2022-47945Kavram kanıtı | ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_othinkphp · thinkphp · CWE-22 | Kritik9,8 | — | %28,3 | 23 Ara 2022 |
46Planlayın | CVE-2022-33107İstismar yok | ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storthinkphp · thinkphp · CWE-502 | Kritik9,8 | — | %23,9 | 29 Haz 2022 |
45Planlayın | CVE-2022-38352İstismar yok | ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache.thinkphp · thinkphp · CWE-502 | Kritik9,8 | — | %20,6 | 14 Eyl 2022 |
40Planlayın | CVE-2024-44902Kavram kanıtı | A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.thinkphp · thinkphp · CWE-502 | Kritik9,8 | — | %4,2 | 9 Eyl 2024 |
40Planlayın | CVE-2021-36567İstismar yok | ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.thinkphp · thinkphp · CWE-502 | Kritik9,8 | — | %2,4 | 6 Ara 2021 |
40Planlayın | CVE-2018-16385Kavram kanıtı | ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.thinkphp · thinkphp · CWE-89 | Kritik9,8 | — | %2,2 | 2 Eyl 2018 |
40Planlayın | CVE-2021-36564İstismar yok | ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storathinkphp · thinkphp · CWE-502 | Kritik9,8 | — | %1,8 | 6 Ara 2021 |
40Planlayın | CVE-2020-20120İstismar yok | ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" thinkphp · thinkphp · CWE-89 | Kritik9,8 | — | %1,8 | 28 Eyl 2021 |
40Planlayın | CVE-2021-23592İstismar yok | Deserialization of Untrusted Datathinkphp · thinkphp · CWE-502 | Kritik9,8 | — | %1,7 | 6 May 2022 |
39İzleyin | CVE-2018-18546İstismar yok | ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the kethinkphp · thinkphp · CWE-89 | Kritik9,8 | — | %1,7 | 20 Eki 2018 |
39İzleyin | CVE-2018-17566İstismar yok | In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's rthinkphp · thinkphp · CWE-89 | Kritik9,8 | — | %1,5 | 26 Eyl 2018 |
39İzleyin | CVE-2021-44350İstismar yok | SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.thinkphp · thinkphp · CWE-89 | Kritik9,8 | — | %1,4 | 15 Ara 2021 |
39İzleyin | CVE-2022-45982İstismar yok | thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability.thinkphp · thinkphp · CWE-502 | Kritik9,8 | — | %1,2 | 8 Şub 2023 |
39İzleyin | CVE-2018-18530İstismar yok | ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregatethinkphp · thinkphp · CWE-89 | Kritik9,8 | — | %1,2 | 19 Eki 2018 |
39İzleyin | CVE-2018-18529İstismar yok | ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles ththinkphp · thinkphp · CWE-89 | Kritik9,8 | — | %1,2 | 19 Eki 2018 |
39İzleyin | CVE-2018-10225İstismar yok | thinkphp 3.1.3 has SQL Injection via the index.php s parameter.thinkphp · thinkphp · CWE-89 | Kritik9,8 | — | %1,1 | 19 Nis 2018 |
39İzleyin | CVE-2025-50706İstismar yok | An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck functionthinkphp · thinkphp · CWE-94 | Kritik9,8 | — | %1,0 | 5 Ağu 2025 |
39İzleyin | CVE-2025-50707İstismar yok | An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php componentthinkphp · thinkphp · CWE-94 | Kritik9,8 | — | %1,0 | 5 Ağu 2025 |
39İzleyin | CVE-2024-48112İstismar yok | A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary cothinkphp · thinkphp · CWE-502 | Kritik9,8 | — | %0,9 | 30 Eki 2024 |
39İzleyin | CVE-2025-63888Kavram kanıtı | The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.thinkphp · thinkphp · CWE-98 | Kritik9,8 | — | %0,6 | 20 Kas 2025 |
37İzleyin | CVE-2018-25270İstismar yok | ThinkPHP 5.0.23 Remote Code Execution via invokefunctionthinkphp · thinkphp · CWE-639 | Kritik9,3 | — | %0,9 | 22 Nis 2026 |
36İzleyin | CVE-2022-44289İstismar yok | Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.thinkphp · thinkphp · CWE-434 | Yüksek8,8 | — | %3,0 | 6 Ara 2022 |
36İzleyin | CVE-2021-44892İstismar yok | A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtthinkphp · thinkphp | Yüksek8,8 | — | %2,0 | 10 Şub 2022 |
31İzleyin | CVE-2022-25481Kavram kanıtı | ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter.thinkphp · thinkphp · CWE-668 | Yüksek7,5 | — | %4,7 | 20 Mar 2022 |
- CVE-2019-908294Hemen
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %97thinkphp · thinkphp24 Şub 2019
- CVE-2022-4794547Planlayın
ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_o
KritikCVSS 9,8Kavram kanıtıEPSS %28thinkphp · thinkphp23 Ara 2022
- CVE-2022-3310746Planlayın
ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Stor
KritikCVSS 9,8İstismar yokEPSS %24thinkphp · thinkphp29 Haz 2022
- CVE-2022-3835245Planlayın
ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache.
KritikCVSS 9,8İstismar yokEPSS %21thinkphp · thinkphp14 Eyl 2022
- CVE-2024-4490240Planlayın
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
KritikCVSS 9,8Kavram kanıtıEPSS %4thinkphp · thinkphp9 Eyl 2024
- CVE-2021-3656740Planlayın
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.
KritikCVSS 9,8İstismar yokEPSS %2thinkphp · thinkphp6 Ara 2021
- CVE-2018-1638540Planlayın
ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.
KritikCVSS 9,8Kavram kanıtıEPSS %2thinkphp · thinkphp2 Eyl 2018
- CVE-2021-3656440Planlayın
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Stora
KritikCVSS 9,8İstismar yokEPSS %2thinkphp · thinkphp6 Ara 2021
- CVE-2020-2012040Planlayın
ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query"
KritikCVSS 9,8İstismar yokEPSS %2thinkphp · thinkphp28 Eyl 2021
- CVE-2021-2359240Planlayın
Deserialization of Untrusted Data
KritikCVSS 9,8İstismar yokEPSS %2thinkphp · thinkphp6 May 2022
- CVE-2018-1854639İzleyin
ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the ke
KritikCVSS 9,8İstismar yokEPSS %2thinkphp · thinkphp20 Eki 2018
- CVE-2018-1756639İzleyin
In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's r
KritikCVSS 9,8İstismar yokEPSS %2thinkphp · thinkphp26 Eyl 2018
- CVE-2021-4435039İzleyin
SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.
KritikCVSS 9,8İstismar yokEPSS %1thinkphp · thinkphp15 Ara 2021
- CVE-2022-4598239İzleyin
thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1thinkphp · thinkphp8 Şub 2023
- CVE-2018-1853039İzleyin
ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate
KritikCVSS 9,8İstismar yokEPSS %1thinkphp · thinkphp19 Eki 2018
- CVE-2018-1852939İzleyin
ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles th
KritikCVSS 9,8İstismar yokEPSS %1thinkphp · thinkphp19 Eki 2018
- CVE-2018-1022539İzleyin
thinkphp 3.1.3 has SQL Injection via the index.php s parameter.
KritikCVSS 9,8İstismar yokEPSS %1thinkphp · thinkphp19 Nis 2018
- CVE-2025-5070639İzleyin
An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function
KritikCVSS 9,8İstismar yokEPSS %1thinkphp · thinkphp5 Ağu 2025
- CVE-2025-5070739İzleyin
An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component
KritikCVSS 9,8İstismar yokEPSS %1thinkphp · thinkphp5 Ağu 2025
- CVE-2024-4811239İzleyin
A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary co
KritikCVSS 9,8İstismar yokEPSS %1thinkphp · thinkphp30 Eki 2024
- CVE-2025-6388839İzleyin
The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.
KritikCVSS 9,8Kavram kanıtıEPSS %1thinkphp · thinkphp20 Kas 2025
- CVE-2018-2527037İzleyin
ThinkPHP 5.0.23 Remote Code Execution via invokefunction
KritikCVSS 9,3İstismar yokEPSS %1thinkphp · thinkphp22 Nis 2026
- CVE-2022-4428936İzleyin
Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.
YüksekCVSS 8,8İstismar yokEPSS %3thinkphp · thinkphp6 Ara 2022
- CVE-2021-4489236İzleyin
A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obt
YüksekCVSS 8,8İstismar yokEPSS %2thinkphp · thinkphp10 Şub 2022
- CVE-2022-2548131İzleyin
ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter.
YüksekCVSS 7,5Kavram kanıtıEPSS %5thinkphp · thinkphp20 Mar 2022