CVE-2024-31615
- EPSS 0.14%
- Veröffentlicht 25.04.2024 20:15:07
- Zuletzt bearbeitet 16.04.2025 18:43:40
ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.
CVE-2020-25915
- EPSS 0.43%
- Veröffentlicht 11.08.2023 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:18:59
Cross Site Scripting (XSS) vulnerability in UserController.php in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via crafted user_login.
CVE-2022-40489
- EPSS 0.05%
- Veröffentlicht 01.12.2022 05:15:11
- Zuletzt bearbeitet 24.04.2025 21:15:19
ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into administrative users.
CVE-2022-40849
- EPSS 0.2%
- Veröffentlicht 01.12.2022 05:15:11
- Zuletzt bearbeitet 24.04.2025 21:15:19
ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute arbitrary JavaScript code on the...
CVE-2021-40616
- EPSS 0.12%
- Veröffentlicht 14.06.2022 10:15:17
- Zuletzt bearbeitet 21.11.2024 06:24:28
thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group au...
CVE-2020-20601
- EPSS 48.11%
- Veröffentlicht 22.12.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 05:12:10
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
CVE-2020-18151
- EPSS 0.11%
- Veröffentlicht 14.07.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 05:08:25
Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account.
CVE-2019-7580
- EPSS 54.99%
- Veröffentlicht 07.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:48:22
ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection.
CVE-2019-6713
- EPSS 1.16%
- Veröffentlicht 23.01.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:59
app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated by a file_pu...
CVE-2018-19894
- EPSS 0.28%
- Veröffentlicht 06.12.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:46
ThinkCMF X2.2.2 has SQL Injection via the functions check() and delete() in CommentadminController.class.php and is exploitable with the manager privilege via the ids[] parameter in a commentadmin action.