Vulnerabilities
15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-31615 | ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php. ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2020-25915 | Cross Site Scripting (XSS) vulnerability in UserController.php in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via crafted user_login. Cross Site Scripting (XSS) vulnerability in UserController.php in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via crafted user_login. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2022-40489 +1 in the same advisory: …40849 | ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into administrativ ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into administrative users. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2021-40616 | thinkcmf v5.1.7 has an unauthorized vulnerability. thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group authority is required. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2020-20601 | An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet. An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet. NVD description · AI analysis pending | 9.8 | 8% | PoC |
| — | |
| CVE-2020-18151 | Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account. Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2019-7580 | ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection. NVD description · AI analysis pending | 8.8 | 10% | PoC ×2 |
| — | |
| CVE-2019-6713 | app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/ind app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated by a file_put_contents call. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2018-19898 | ThinkCMF X2.2.2 has SQL Injection via the method edit_post in ArticleController.class.php and is exploitable by normal authenticated users via the post[id][1] p ThinkCMF X2.2.2 has SQL Injection via the method edit_post in ArticleController.class.php and is exploitable by normal authenticated users via the post[id][1] parameter in an article edit_post action. NVD description · AI analysis pending | 8.8 group max | 1% | PoC |
| — | |
| CVE-2018-16141 | ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in \application\User\Controller\ProfileController.class.php via an imgurl parameter wi ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in \application\User\Controller\ProfileController.class.php via an imgurl parameter with a ..\ sequence. A member user can delete any file on a Windows server. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — |