Thinkadmin is a narrowly scoped administrative software product that has surfaced vulnerabilities skewing toward serious outcomes, frequently acquiring public exploit code. The exposure recurs through characteristic web-application weakness classes including unrestricted file uploads, untrusted deserialization, improper authentication, path traversal, and cross-site scripting, reflecting the input-handling and access-control demands of administrative interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thinkadmin over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25540HIGH ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on a remote server via GET request encode parameter. | Sep 14, 2020 | 7.5 | 82 | NO | YES |
CVE-2020-23653CRITICAL An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/controller/api/Push.php, which may | Jan 13, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-11018CRITICAL application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials after a password change. | Apr 8, 2019 | 9.8 | 30 | NO | NO |
CVE-2023-48965HIGH An issue in the component /admin/api.plugs/script of ThinkAdmin v6.1.53 allows attackers to getshell via providing a crafted URL to download a malicious PHP file. | Dec 4, 2023 | 8.8 | 23 | NO | NO |
CVE-2020-35296HIGH ThinkAdmin v6 has default administrator credentials, which allows attackers to gain unrestricted administratior dashboard access. | Mar 3, 2021 | 7.5 | 23 | NO | NO |
CVE-2024-10749HIGH A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script of the file /app/admin/controller/api/Plugs.php. The manipu | Nov 4, 2024 | 8.1 | 22 | NO | NO |
CVE-2023-48966HIGH An arbitrary file upload vulnerability in the component /admin/api.upload/file of ThinkAdmin v6.1.53 allows attackers to execute arbitrary code via a crafted Zip file. | Dec 4, 2023 | 8.8 | 22 | NO | NO |
CVE-2020-29315MEDIUM ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML. | Dec 1, 2020 | 5.4 | 19 | NO | NO |
CVE-2023-34833MEDIUM An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arbitrary code via a crafted file. | Jun 15, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thinkadmin.
Media articles that mention a CVE ID that affects a product developed by Thinkadmin — matched by CVE ID, not by vendor name.