Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-25270

32
FAUCET Score

BRIEFING NOTE: CVE-2018-25270 ThinkPHP 5.0.23 is affected by a critical remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through the routing parameter mechanism. By crafting malicious requests to the index.php endpoint with specially crafted function parameters, attackers can invoke arbitrary functions and execute system commands with full application privileges. The vulnerability carries a CVSS 3.1 score of 9.8 CRITICAL with network-based attack vector, low attack complexity, and no authentication or user interaction required. The impact is severe across all security dimensions, granting attackers high-level confidentiality, integrity, and availability compromise capabilities. With a FAUCET Risk Score of 55.0 out of 100, this represents a significant organizational risk. While the vulnerability is not currently tracked in CISA's Known Exploited Vulnerabilities catalog, it remains actively listed on public vulnerability databases and maintains community attention. The attack surface and public knowledge of this vulnerability suggest continued risk of exploitation, warranting immediate patching of affected ThinkPHP installations to versions beyond 5.0.23.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.0.0, < 5.0.23CPE matchmatch criteria
cpe:2.3:a:thinkphp:thinkphp:*:*:*:*:*:*:*:*
5.1.31CPE matchmatch criteria
cpe:2.3:a:thinkphp:thinkphp:5.1.31:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.89%
Probability of exploitation in next 30 days
EPSS Percentile
55.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0089 is in the 40th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / top-think/framework
Product
thinkphp.cn
Broken Link
exploit-db.com / exploits/45978
ExploitThird Party AdvisoryVDB Entry
vulncheck.com / advisories/thinkphp-remote-code-execution-via-invokefunction
Third Party Advisory