Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Thinkcmf CRITICAL 9.8
CVE-2024-31615

ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.

No fix yet
Fix from $2,300 2024-04-25
Thinkcmf MEDIUM 5.4
CVE-2020-25915

Cross Site Scripting (XSS) vulnerability in UserController.php in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via crafted user…

Mitigation only
Fix from $1,600 2023-08-11
Thinkcmf HIGH 8.8
CVE-2022-40489

ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into ad…

No fix yet
Fix from $1,950 2022-12-01
Thinkcmf MEDIUM 5.4
CVE-2022-40849

ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Per…

No fix yet
Fix from $1,600 2022-12-01
Thinkcmf MEDIUM 6.5
CVE-2021-40616

thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background…

No fix yet
Fix from $1,600 2022-06-14
Thinkcmf CRITICAL 9.8
CVE-2020-20601EPSS 8%

An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.

No fix yet
Fix from $2,300 2021-12-22
Thinkcmf MEDIUM 6.5
CVE-2020-18151

Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account.

No fix yet
Fix from $1,600 2021-07-14
Thinkcmf HIGH 8.8
CVE-2019-7580EPSS 10%

ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mish…

No fix yet
Fix from $1,950 2019-02-07
Thinkcmf CRITICAL 9.8
CVE-2019-6713

app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving port…

Mitigation only
Fix from $2,300 2019-01-23
Thinkcmf HIGH 8.8
CVE-2018-19898

ThinkCMF X2.2.2 has SQL Injection via the method edit_post in ArticleController.class.php and is exploitable by normal authenticated users via the po…

No fix yet
Fix from $1,950 2018-12-06
Thinkcmf HIGH 7.2
CVE-2018-19894

ThinkCMF X2.2.2 has SQL Injection via the functions check() and delete() in CommentadminController.class.php and is exploitable with the manager priv…

No fix yet
Fix from $1,950 2018-12-06
Thinkcmf HIGH 7.2
CVE-2018-19895

ThinkCMF X2.2.2 has SQL Injection via the function edit_post() in NavController.class.php and is exploitable with the manager privilege via the paren…

No fix yet
Fix from $1,950 2018-12-06
Thinkcmf HIGH 7.2
CVE-2018-19896

ThinkCMF X2.2.2 has SQL Injection via the function delete() in SlideController.class.php and is exploitable with the manager privilege via the ids[] …

No fix yet
Fix from $1,950 2018-12-06
Thinkcmf HIGH 7.2
CVE-2018-19897

ThinkCMF X2.2.2 has SQL Injection via the function _listorders() in AdminbaseController.class.php and is exploitable with the manager privilege via t…

No fix yet
Fix from $1,950 2018-12-06
Thinkcmfx MEDIUM 6.5
CVE-2018-16141

ThinkCMF X2.2.3 has an arbitrary file deletion vulnerability in do_avatar in \application\User\Controller\ProfileController.class.php via an imgurl p…

No fix yet
Fix from $1,600 2018-08-30