ThinkPHP is a widely adopted open-source PHP web application framework that, despite its narrow product scope, holds a prominent position in the vulnerability landscape due to its extensive deployment across web applications globally. Vulnerabilities affecting the framework skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting both the framework's central role in request handling and the appeal of web-application flaws for broad-scale exploitation. The exposure recurs through dangerous weakness classes including untrusted deserialization, SQL injection, code injection, authorization-bypass patterns, and resource-exposure issues that are characteristic of application-framework codebases handling user input and access control at scale. Defenders should treat ThinkPHP advisories with high priority, inventory affected deployments, and apply patches promptly given the framework's role in directly processing web requests. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thinkphp over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9082HIGH ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_ | Feb 24, 2019 | 8.8 | 99 | YES | YES |
CVE-2022-47945CRITICAL ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote a | Dec 23, 2022 | 9.8 | 52 | NO | YES |
CVE-2022-33107CRITICAL ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerabilit | Jun 29, 2022 | 9.8 | 42 | NO | NO |
CVE-2022-38352CRITICAL ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerability allows attackers to execu | Sep 15, 2022 | 9.8 | 40 | NO | NO |
CVE-2022-25481HIGH ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: t | Mar 21, 2022 | 7.5 | 37 | NO | YES |
CVE-2024-44902CRITICAL A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code. | Sep 9, 2024 | 9.8 | 34 | NO | NO |
CVE-2018-25270CRITICAL ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing paramet | Apr 22, 2026 | 9.8 | 32 | NO | NO |
CVE-2021-36567CRITICAL ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache. | Dec 6, 2021 | 9.8 | 32 | NO | NO |
CVE-2025-63888CRITICAL The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability. | Nov 20, 2025 | 9.8 | 31 | NO | NO |
CVE-2022-45982CRITICAL thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload. | Feb 8, 2023 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thinkphp.
Media articles that mention a CVE ID that affects a product developed by Thinkphp — matched by CVE ID, not by vendor name.