Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Thinkphp

First CVE: Apr 19, 2018Active for: 8 yearsTotal CVEs: 27
81.9
VTI Score
TOP TARGET

ThinkPHP is a widely adopted open-source PHP web application framework that, despite its narrow product scope, holds a prominent position in the vulnerability landscape due to its extensive deployment across web applications globally. Vulnerabilities affecting the framework skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting both the framework's central role in request handling and the appeal of web-application flaws for broad-scale exploitation. The exposure recurs through dangerous weakness classes including untrusted deserialization, SQL injection, code injection, authorization-bypass patterns, and resource-exposure issues that are characteristic of application-framework codebases handling user input and access control at scale. Defenders should treat ThinkPHP advisories with high priority, inventory affected deployments, and apply patches promptly given the framework's role in directly processing web requests. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
3.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
9.4
Avg CVSS Score
Higher Avg CVSS Score than 90% of tracked vendors
3.7%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Thinkphp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 19, 2018
8 years ago
Most Recent CVE
Apr 22, 2026
93 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-9082HIGH
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_
Feb 24, 20198.899YESYES
CVE-2022-47945CRITICAL
ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote a
Dec 23, 20229.852NOYES
CVE-2022-33107CRITICAL
ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerabilit
Jun 29, 20229.842NONO
CVE-2022-38352CRITICAL
ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerability allows attackers to execu
Sep 15, 20229.840NONO
CVE-2022-25481HIGH
ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: t
Mar 21, 20227.537NOYES
CVE-2024-44902CRITICAL
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
Sep 9, 20249.834NONO
CVE-2018-25270CRITICAL
ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing paramet
Apr 22, 20269.832NONO
CVE-2021-36567CRITICAL
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.
Dec 6, 20219.832NONO
CVE-2025-63888CRITICAL
The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.
Nov 20, 20259.831NONO
CVE-2022-45982CRITICAL
thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
Feb 8, 20239.831NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
19%
78%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None25 (92.6%)
Unknown0 (0.0%)
Required2 (7.4%)
Privileges Required
Low2 (7.4%)
High0 (0.0%)
None25 (92.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
1 CVE
3.7% of CVEs· 99th percentile
Metasploit
1 CVE
3.7% of CVEs· 98th percentile
Nuclei
3 CVEs
11.1% of CVEs· 96th percentile
ExploitDB
1 CVE
3.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Thinkphp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Thinkphp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Thinkphp's Products

View all 3 CNAs →

Top CWEs