📦

thinkphp

Vendor: thinkphp

Actively Exploited 1 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 9 Remote Access
Total CVEs 34 Total Indexed
Avg. EPSS 7.22% Exploit Prob.
Latest CVE CVE-2018-25270 Apr 22

Security Vulnerability Index

Page 2 / 4
8.8 CVSS

Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.

EPSS: 2.91%
9.8 CVSS

ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

EPSS: 20.20%
9.8 CVSS

ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

EPSS: 22.79%
7.7 CVSS

The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.

EPSS: 1.65%
7.5 CVSS

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.

EPSS: 4.75%
8.8 CVSS

A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.

EPSS: 2.02%
9.8 CVSS

SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.

EPSS: 1.37%
9.8 CVSS

ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.

EPSS: 2.41%
9.8 CVSS

ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapter.php.

EPSS: 1.84%
9.8 CVSS

ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.

EPSS: 1.81%