📦

thinkphp

Vendor: thinkphp

Actively Exploited 1 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 9 Remote Access
Total CVEs 34 Total Indexed
Avg. EPSS 7.22% Exploit Prob.
Latest CVE CVE-2018-25270 Apr 22

Security Vulnerability Index

Page 1 / 4
9.3 CVSS

ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter. Attackers can craft requests to the index.php endpoint with malicious function parameters to execute system commands with application privileges.

EPSS: 0.89%
7.5 CVSS

The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary files via crafted file path in a template value.

EPSS: 0.30%
9.8 CVSS
CVE-2025-63888
Exploit Found

The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.

EPSS: 0.55%
9.8 CVSS

An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component

EPSS: 1.03%
9.8 CVSS

An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function

EPSS: 1.03%
9.8 CVSS

A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

EPSS: 0.86%
9.8 CVSS
CVE-2024-44902
RCE Exploit Found

A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

EPSS: 4.21%
6.1 CVSS

ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.

EPSS: 0.42%
9.8 CVSS

thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

EPSS: 1.23%
9.8 CVSS

ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.

EPSS: 16.38%