Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Thinksaas

First CVE: Aug 7, 2018Active for: 8 yearsTotal CVEs: 12
19.9
VTI Score
Low

Thinksaas develops a web-based business-management platform that is among the more prominent targets in its segment, with a vulnerability profile concentrated in a single core product and skewing toward serious outcomes. The recurring exposure centers on application-layer input-handling and state-management weaknesses, particularly cross-site scripting, SQL injection, and cross-site request forgery, which are characteristic of web applications handling user input and session control. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Thinksaas over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 7, 2018
7 years ago
Most Recent CVE
Jul 21, 2024
734 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-35337CRITICAL
ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows remote attackers to execute arbitrary SQ
Mar 24, 20219.829NONO
CVE-2024-40456CRITICAL
ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.
Jul 16, 20249.826NONO
CVE-2019-16665MEDIUM
An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1 URI, as demonstrated by a crafted SVG document in the SRC a
Sep 21, 20196.121NONO
CVE-2018-15129MEDIUM
ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter.
Aug 7, 20185.421NONO
CVE-2018-15130MEDIUM
ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.
Aug 7, 20185.420NONO
CVE-2019-16664MEDIUM
An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter.
Sep 21, 20194.819NONO
CVE-2024-33101MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payl
Apr 30, 20246.118NONO
CVE-2024-6942MEDIUM
A vulnerability, which was classified as problematic, was found in ThinkSAAS 3.7.0. Affected is an unknown function of the file app/system/action/anti.php of the component Admin Pa
Jul 21, 20245.417NONO
CVE-2024-6941MEDIUM
A vulnerability, which was classified as problematic, has been found in ThinkSAAS 3.7.0. This issue affects some unknown processing of the file app/system/action/do.php. The manipu
Jul 21, 20245.417NONO
CVE-2024-33102MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted pay
Apr 30, 20245.417NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
8%
75%
17%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (33.3%)
Unknown0 (0.0%)
Required8 (66.7%)
Privileges Required
Low4 (33.3%)
High2 (16.7%)
None6 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Thinksaas.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Thinksaas — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Thinksaas's Products

View all 2 CNAs →

Top CWEs