Record summary

CVE-2018-25270 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter. Attackers can craft requests to the index.php endpoint with malicious function parameters to execute system commands with application privileges.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 4, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List, VulnCheck5.0.23affected
5.1.31affected

Proofs of concept

1

Catalogued exploits

ExploitDBThinkPHP 5.0.23/5.1.31 - Remote Code ExecutionExploitDB exploitby VulnSpyNot analyzed1 file
ExploitDB

PoC details

References

5