Showing 19 vulnerabilities on this page for topthink/framework

Signals CISA KEV Ransomware Nuclei
Packagist vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

ThinkPHP Path Traversal Vulnerability

An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function

CWE-22CWE-94Aug 5, 2025
CVSS-v4.0EPSS1.03%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ThinkPHP deserialization vulnerability

A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

CWE-502Sep 9, 2024
CVSS-v4.0EPSS4.21%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ThinkPHP Cross-Site Scripting Vulnerability

ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.

CWE-79May 4, 2024
CVSS6.1v3.1EPSS0.417%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ThinkPHP Framework vulnerable to remote code execution

ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.

CWE-22Dec 23, 20221 related artifact
CVSS9.8v3.1EPSS16.4%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Thinkphp has a code logic error

Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.

CWE-434Dec 6, 2022
CVSS8.8v3.1EPSS2.93%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ThinkPHP deserialization vulnerability

ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

CWE-502Sep 15, 2022
CVSS9.8v3.1EPSS20.2%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Deserialization of Untrusted Data in topthink/framework

ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

CWE-502Jun 29, 2022
CVSS9.8v3.1EPSS22.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Deserialization of Untrusted Data

The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.

CWE-502May 6, 2022
CVSS7.7v3.1EPSS1.66%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Exposure of Resource to Wrong Sphere in ThinkPHP Framework

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.

CWE-284CWE-668Mar 20, 20221 related artifact
CVSS7.5v3.1EPSS4.75%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

ThinkPHP Remote Code Execution (RCE) vulnerability

A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.

Feb 10, 2022
CVSS8.8v3.1EPSS2.02%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ThinkPHP5 SQL Injection vulnerability

SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.

CWE-89Dec 15, 2021
CVSS9.8v3.1EPSS1.37%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Deserialization of Untrusted Data in topthink/framework

ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.

CWE-502Dec 6, 2021
CVSS9.8v3.1EPSS2.41%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Deserialization of Untrusted Data in topthink/framework

ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapter.php.

CWE-502Dec 6, 2021
CVSS9.8v3.1EPSS1.84%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ThinkPHP SQLi Vulnerability

ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the key variable.

CWE-89Oct 21, 2018
CVSS9.8v3.0EPSS1.66%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ThinkPHP SQLi Vulnerability

ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate variable. NOTE: a backquote character is required in the attack URI.

CWE-89Oct 19, 2018
CVSS9.8v3.0EPSS1.2%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ThinkPHP SQLi Vulnerability

ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles the key variable. NOTE: a backquote character is not required in the attack URI.

CWE-89Oct 19, 2018
CVSS9.8v3.0EPSS1.2%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ThinkPHP SQL injection vulnerability

In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's request.

CWE-89Sep 26, 2018
CVSS9.8v3.0EPSS1.54%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

ThinkPHP SQL Injection vulnerability

ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.

CWE-89Sep 3, 2018
CVSS9.8v3.0EPSS2.13%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

thinkphp SQL Injection via the index.php s parameter

thinkphp 3.1.3 has SQL Injection via the index.php s parameter.

CWE-89Apr 19, 2018
CVSS9.8v3.0EPSS1.14%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX