Product Referenceproduct
https://github.com/top-think/framework CVE-2018-25270
CRITICAL
ThinkPHP 5.0.23 Remote Code Execution via invokefunction
Record summary
CVE-2018-25270 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter. Attackers can craft requests to the index.php endpoint with malicious function parameters to execute system commands with application privileges.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 4, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ThinkPHPBrowse Thinkphp / ThinkPHP | CVE List, VulnCheck | 5.0.23 | affected |
| 5.1.31 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBThinkPHP 5.0.23/5.1.31 - Remote Code ExecutionExploitDB exploitby VulnSpyNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-25270 Official Product Homepageproduct
https://thinkphp.cn/ ExploitDB-45978exploit
https://www.exploit-db.com/exploits/45978 VulnCheck Advisory: ThinkPHP 5.0.23 Remote Code Execution via invokefunctionThird-party advisory
https://www.vulncheck.com/advisories/thinkphp-remote-code-execution-via-invokefunction