thinkphp Vulnerabilities and Affected Products
Vulnerabilities associated with ThinkPHP.
Products
Clear product| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-25270CRITICAL | ThinkPHP 5.0.23 Remote Code Execution via invokefunctionThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter. Attackers can craft requests to the index.php endpoint with malicious function parameters to execute system commands with application privileges. CWE-639Apr 22, 2026 | CVSS9.3v4.0 | EPSS0.89% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
ThinkPHP deserialization vulnerabilityA deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code. CWE-502Oct 30, 2024 | CVSS-v4.0 | EPSS0.885% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
ThinkPHP deserialization vulnerabilityA deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code. CWE-502Sep 9, 2024 | CVSS-v4.0 | EPSS4.21% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-34467MEDIUM | ThinkPHP Cross-Site Scripting VulnerabilityThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl. CWE-79May 4, 2024 | CVSS6.1v3.1 | EPSS0.417% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-47945CRITICAL | ThinkPHP Framework vulnerable to remote code executionThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php. | CVSS9.8v3.1 | EPSS16.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-25481HIGH | Exposure of Resource to Wrong Sphere in ThinkPHP FrameworkThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode. | CVSS7.5v3.1 | EPSS4.75% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-44892HIGH | ThinkPHP Remote Code Execution (RCE) vulnerabilityA Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges. Feb 10, 2022 | CVSS8.8v3.1 | EPSS2.02% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-9082HIGH | ThinkPHP Remote Code Execution VulnerabilityThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command. | CVSS8.8v3.1 | EPSS97.4% | PoCs3 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2018-10225CRITICAL | thinkphp SQL Injection via the index.php s parameterthinkphp 3.1.3 has SQL Injection via the index.php s parameter. CWE-89Apr 19, 2018 | CVSS9.8v3.0 | EPSS1.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |