Packagist Package Vulnerabilities
Vulnerabilities associated with topthink/framework.
Packages
Clear package- moodle/moodle437 vulnerabilities
- magento/community-edition362 vulnerabilities
- typo3/cms188 vulnerabilities
- magento/project-community-edition161 vulnerabilities
- wwbn/avideo144 vulnerabilities
- pimcore/pimcore132 vulnerabilities
- craftcms/cms128 vulnerabilities
- typo3/cms-core127 vulnerabilities
- dolibarr/dolibarr126 vulnerabilities
- concrete5/concrete5119 vulnerabilities
- drupal/core109 vulnerabilities
- phpmyadmin/phpmyadmin107 vulnerabilities
- thorsten/phpmyfaq106 vulnerabilities
- microweber/microweber105 vulnerabilities
- librenms/librenms101 vulnerabilities
- symfony/symfony100 vulnerabilities
- silverstripe/framework90 vulnerabilities
- drupal/drupal81 vulnerabilities
- mantisbt/mantisbt74 vulnerabilities
- shopware/platform74 vulnerabilities
- getgrav/grav69 vulnerabilities
- shopware/core65 vulnerabilities
- snipe/snipe-it57 vulnerabilities
- baserproject/basercms56 vulnerabilities
- mautic/core56 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
ThinkPHP Path Traversal VulnerabilityAn issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function | CVSS-v4.0 | EPSS1.03% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ThinkPHP deserialization vulnerabilityA deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code. CWE-502Sep 9, 2024 | CVSS-v4.0 | EPSS4.21% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-34467MEDIUM | ThinkPHP Cross-Site Scripting VulnerabilityThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl. CWE-79May 4, 2024 | CVSS6.1v3.1 | EPSS0.417% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-47945CRITICAL | ThinkPHP Framework vulnerable to remote code executionThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php. | CVSS9.8v3.1 | EPSS16.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-44289HIGH | Thinkphp has a code logic errorThinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell. CWE-434Dec 6, 2022 | CVSS8.8v3.1 | EPSS2.93% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38352CRITICAL | ThinkPHP deserialization vulnerabilityThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerability allows attackers to execute arbitrary code via a crafted payload. CWE-502Sep 15, 2022 | CVSS9.8v3.1 | EPSS20.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-33107CRITICAL | Deserialization of Untrusted Data in topthink/frameworkThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted payload. CWE-502Jun 29, 2022 | CVSS9.8v3.1 | EPSS22.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-23592HIGH | Deserialization of Untrusted DataThe package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class. CWE-502May 6, 2022 | CVSS7.7v3.1 | EPSS1.66% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-25481HIGH | Exposure of Resource to Wrong Sphere in ThinkPHP FrameworkThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode. | CVSS7.5v3.1 | EPSS4.75% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-44892HIGH | ThinkPHP Remote Code Execution (RCE) vulnerabilityA Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges. Feb 10, 2022 | CVSS8.8v3.1 | EPSS2.02% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-44350CRITICAL | ThinkPHP5 SQL Injection vulnerabilitySQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php. CWE-89Dec 15, 2021 | CVSS9.8v3.1 | EPSS1.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-36567CRITICAL | Deserialization of Untrusted Data in topthink/frameworkThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache. CWE-502Dec 6, 2021 | CVSS9.8v3.1 | EPSS2.41% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-36564CRITICAL | Deserialization of Untrusted Data in topthink/frameworkThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapter.php. CWE-502Dec 6, 2021 | CVSS9.8v3.1 | EPSS1.84% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-18546CRITICAL | ThinkPHP SQLi VulnerabilityThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the key variable. CWE-89Oct 21, 2018 | CVSS9.8v3.0 | EPSS1.66% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-18530CRITICAL | ThinkPHP SQLi VulnerabilityThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate variable. NOTE: a backquote character is required in the attack URI. CWE-89Oct 19, 2018 | CVSS9.8v3.0 | EPSS1.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-18529CRITICAL | ThinkPHP SQLi VulnerabilityThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles the key variable. NOTE: a backquote character is not required in the attack URI. CWE-89Oct 19, 2018 | CVSS9.8v3.0 | EPSS1.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-17566CRITICAL | ThinkPHP SQL injection vulnerabilityIn ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's request. CWE-89Sep 26, 2018 | CVSS9.8v3.0 | EPSS1.54% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-16385CRITICAL | ThinkPHP SQL Injection vulnerabilityThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string. CWE-89Sep 3, 2018 | CVSS9.8v3.0 | EPSS2.13% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-10225CRITICAL | thinkphp SQL Injection via the index.php s parameterthinkphp 3.1.3 has SQL Injection via the index.php s parameter. CWE-89Apr 19, 2018 | CVSS9.8v3.0 | EPSS1.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |