CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “thinkphp”

30 vulnerabilities found for “thinkphp”

Page 1 of 2

CVE-2025-63889
HIGH7.5

The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary files via crafted file path in a template value.

thinkphp / thinkphp
Network
Published Nov 20, 2025
Page 1 of 2
CVE-2025-63888
CRITICAL9.8

The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.

thinkphp / thinkphp
Network
Published Nov 20, 2025
CVE-2025-50707
CRITICAL9.8

An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component

thinkphp / thinkphp
Network
Published Aug 5, 2025
CVE-2025-50706
CRITICAL9.8

An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function

thinkphp / thinkphp
Network
Published Aug 5, 2025
CVE-2024-48112
CRITICAL9.8

A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

thinkphp / thinkphp
Network
Published Oct 30, 2024
CVE-2024-44902
CRITICAL9.8

A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

thinkphp / thinkphp
Network
Published Sep 9, 2024
CVE-2024-34467
MEDIUM6.1

ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.

thinkphp / thinkphp
Network
Published May 4, 2024
CVE-2022-45982
CRITICAL9.8

thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

thinkphp / thinkphp+1
Network
Published Feb 8, 2023
CVE-2022-47945
CRITICAL9.8

ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.

thinkphp / thinkphp
Network
Published Dec 23, 2022
CVE-2022-44289
HIGH8.8

Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.

thinkphp / thinkphp+1
Network
Published Dec 6, 2022
CVE-2022-38352
CRITICAL9.8

ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

thinkphp / thinkphp
Network
Published Sep 15, 2022
CVE-2022-33107
CRITICAL9.8

ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

thinkphp / thinkphp
Network
Published Jun 29, 2022
CVE-2021-23592
HIGH7.7

The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.

thinkphp / thinkphp
Network
Published May 6, 2022
CVE-2022-25481
HIGH7.5

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.

thinkphp / thinkphp
Network
Published Mar 21, 2022
CVE-2021-44892
HIGH8.8

A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.

thinkphp / thinkphp
Network
Published Feb 10, 2022
CVE-2021-44350
CRITICAL9.8

SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.

thinkphp / thinkphp
Network
Published Dec 15, 2021
CVE-2021-36567
CRITICAL9.8

ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.

thinkphp / thinkphp
Network
Published Dec 6, 2021
CVE-2021-36564
CRITICAL9.8

ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapter.php.

thinkphp / thinkphp
Network
Published Dec 6, 2021
CVE-2020-20120
CRITICAL9.8

ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.

thinkphp / thinkphp
Network
Published Sep 28, 2021
CVE-2018-10225
CRITICAL9.8

thinkphp 3.1.3 has SQL Injection via the index.php s parameter.

thinkphp / thinkphp
Network
Published Apr 19, 2018