Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
thinkphp thinkphp vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2022-45982
thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows malicious users to execute arbitrary code via a crafted payload.
Thinkphp Thinkphp 6.1.0
Thinkphp Thinkphp
8.8
CVSSv3
CVE-2022-44289
Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.
Thinkphp Thinkphp 5.0.24
Thinkphp Thinkphp 5.1.41
9.8
CVSSv3
CVE-2021-44350
SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.
Thinkphp Thinkphp
9.8
CVSSv3
CVE-2021-23592
The package topthink/framework prior to 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.
Thinkphp Thinkphp
9.8
CVSSv3
CVE-2020-20120
ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.
Thinkphp Thinkphp
9.8
CVSSv3
CVE-2018-16385
ThinkPHP prior to 5.1.23 allows SQL Injection via the public/index/index/test/index query string.
Thinkphp Thinkphp
9.8
CVSSv3
CVE-2022-47945
ThinkPHP Framework prior to 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by includ...
Thinkphp Thinkphp
1 Github repository
9.8
CVSSv3
CVE-2021-36564
ThinkPHP v6.0.8 exists to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapter.php.
Thinkphp Thinkphp 6.0.8
9.8
CVSSv3
CVE-2021-36567
ThinkPHP v6.0.8 exists to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.
Thinkphp Thinkphp 6.0.8
9.8
CVSSv3
CVE-2018-10225
thinkphp 3.1.3 has SQL Injection via the index.php s parameter.
Thinkphp Thinkphp 3.1.3
1 Github repository
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3080
log injection
CVE-2024-6041
CVE-2024-37661
XML external entity
CVE-2024-0845
privilege escalation
CVE-2023-37057
CVE-2024-27801
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »