← Back

Thinkcmf

thinkcmf

Vendor: Thinkcmf • 14 CVEs

CVEs (14)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Thinkcmf
1Thinkcmf
Apr 16, 2025
Apr 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.
1Thinkcmf
1Thinkcmf
Nov 21, 2024
Aug 11, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in UserController.php in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via crafted user_login.
1Thinkcmf
1Thinkcmf
Apr 24, 2025
Dec 1, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute ar...Show more
ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute arbitrary JavaScript code on the client side, e.g., to steal the administrator's PHP session token (PHPSESSID).Show less
1Thinkcmf
1Thinkcmf
Apr 24, 2025
Dec 1, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into administrative users.
1Thinkcmf
1Thinkcmf
Nov 21, 2024
Jun 14, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the backg...Show more
thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group authority is required.Show less
1Thinkcmf
1Thinkcmf
Nov 21, 2024
Dec 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
1Thinkcmf
1Thinkcmf
Nov 21, 2024
Jul 14, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account.
1Thinkcmf
1Thinkcmf
Nov 21, 2024
Feb 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injectio...Show more
ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection.Show less
1Thinkcmf
1Thinkcmf
Nov 21, 2024
Jan 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php...Show more
app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated by a file_put_contents call.Show less
1Thinkcmf
1Thinkcmf
Nov 21, 2024
Dec 6, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
ThinkCMF X2.2.2 has SQL Injection via the method edit_post in ArticleController.class.php and is exploitable by normal authenticated users via the post[id][1] parameter in an article edit_post action.
1Thinkcmf
1Thinkcmf
Nov 21, 2024
Dec 6, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
ThinkCMF X2.2.2 has SQL Injection via the function _listorders() in AdminbaseController.class.php and is exploitable with the manager privilege via the listorders[key][1] parameter in a Link listorders action.
1Thinkcmf
1Thinkcmf
Nov 21, 2024
Dec 6, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
ThinkCMF X2.2.2 has SQL Injection via the function delete() in SlideController.class.php and is exploitable with the manager privilege via the ids[] parameter in a slide action.
1Thinkcmf
1Thinkcmf
Nov 21, 2024
Dec 6, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
ThinkCMF X2.2.2 has SQL Injection via the function edit_post() in NavController.class.php and is exploitable with the manager privilege via the parentid parameter in a nav action.
1Thinkcmf
1Thinkcmf
Nov 21, 2024
Dec 6, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
ThinkCMF X2.2.2 has SQL Injection via the functions check() and delete() in CommentadminController.class.php and is exploitable with the manager privilege via the ids[] parameter in a commentadmin action.