Onethink's vulnerability profile concentrates in a single application product and skews strongly toward critical-severity outcomes across a modestly represented footprint. The recurring weakness classes—cross-site request forgery, code injection, SQL injection, and server-side request forgery—reflect characteristic input-handling and access-control gaps in web-facing applications that can enable broad system compromise. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Onethink over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14323CRITICAL SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information, attack intranet hosts, or pos | Apr 10, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-15198HIGH An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a user. | Aug 8, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-15197HIGH An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that can endow administrator privileges. | Aug 8, 2018 | 8.8 | 27 | NO | NO |
CVE-2024-33444CRITICAL SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to the ModelModel.class.php component. | Apr 29, 2024 | 9.8 | 26 | NO | NO |
CVE-2018-16449MEDIUM OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Article/update.html, and setting the audit state via admin.php?s | Sep 4, 2018 | 6.5 | 22 | NO | NO |
CVE-2024-33443HIGH An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php component. | Apr 29, 2024 | 7.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Onethink.
Media articles that mention a CVE ID that affects a product developed by Onethink — matched by CVE ID, not by vendor name.