Thinksaas develops a web-based business-management platform that is among the more prominent targets in its segment, with a vulnerability profile concentrated in a single core product and skewing toward serious outcomes. The recurring exposure centers on application-layer input-handling and state-management weaknesses, particularly cross-site scripting, SQL injection, and cross-site request forgery, which are characteristic of web applications handling user input and session control. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thinksaas over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35337CRITICAL ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows remote attackers to execute arbitrary SQ | Mar 24, 2021 | 9.8 | 29 | NO | NO |
CVE-2024-40456CRITICAL ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php. | Jul 16, 2024 | 9.8 | 26 | NO | NO |
CVE-2019-16665MEDIUM An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1 URI, as demonstrated by a crafted SVG document in the SRC a | Sep 21, 2019 | 6.1 | 21 | NO | NO |
CVE-2018-15129MEDIUM ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter. | Aug 7, 2018 | 5.4 | 21 | NO | NO |
CVE-2018-15130MEDIUM ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter. | Aug 7, 2018 | 5.4 | 20 | NO | NO |
CVE-2019-16664MEDIUM An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter. | Sep 21, 2019 | 4.8 | 19 | NO | NO |
CVE-2024-33101MEDIUM A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payl | Apr 30, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-6942MEDIUM A vulnerability, which was classified as problematic, was found in ThinkSAAS 3.7.0. Affected is an unknown function of the file app/system/action/anti.php of the component Admin Pa | Jul 21, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-6941MEDIUM A vulnerability, which was classified as problematic, has been found in ThinkSAAS 3.7.0. This issue affects some unknown processing of the file app/system/action/do.php. The manipu | Jul 21, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-33102MEDIUM A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted pay | Apr 30, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thinksaas.
Media articles that mention a CVE ID that affects a product developed by Thinksaas — matched by CVE ID, not by vendor name.