CVE Tools

Thinkphp

6 CVEs tracked since 2018. Since Oct 2018, none of them reached CISA KEV.

Thinkphp CVEs per month

Oct 2018 to Dec 2021. Point at a month, or focus the strip and use the arrow keys.
Thinkphp CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-1030
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-1230

Products

The products that kept showing up in Thinkphp's monthly top three, with their CVEs summed over those months.

  1. Thinkphp62 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Thinkphp.

  1. CVE-2018-25270ThinkPHP 5.0.23 Remote Code Execution via invokefunction9.8
  2. CVE-2025-63888The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.9.8
  3. CVE-2025-63889The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary files via crafted file path in a template value.7.5
  4. CVE-2025-50707An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component9.8
  5. CVE-2025-50706An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function9.8
  6. CVE-2024-48112A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.9.8
  7. CVE-2024-44902A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.9.8
  8. CVE-2024-34467ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.6.1
  9. CVE-2022-45982thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.9.8
  10. CVE-2022-47945ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can explo...9.8
  11. CVE-2022-44289Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.8.8
  12. CVE-2022-38352ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerability allows attackers to execute arbitrary code...9.8
  13. CVE-2022-33107ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerability allows attacker...9.8
  14. CVE-2021-23592Deserialization of Untrusted Data7.7
  15. CVE-2022-25481ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed b...7.5

The record

Peak rank
#147 in Oct 2018
Busiest month shown
Oct 2018, 3 CVEs
Months with a KEV entry
0 since Oct 2018
Monthly snapshots
2 since 2018
Thinkphp's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store