Thinkcmf

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 15
    Known Exploited: 0
    3
    Critical Level Threats
    7
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-31615

    ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.

    Last Modified: Apr 16, 2025
    Published: Apr 25, 2024

    CVE-2020-25915

    Cross Site Scripting (XSS) vulnerability in UserController.php in ThinkCMF version 5.1.5, allows attackers to execute arbitrary code via crafted user_login.

    Last Modified: Nov 21, 2024
    Published: Aug 11, 2023

    CVE-2022-40849

    ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute arbitrary JavaScript code on the client side, e.g., to steal the administrator's PHP session token (PHPSESSID).

    Last Modified: Apr 24, 2025
    Published: Dec 01, 2022

    CVE-2022-40489

    ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into administrative users.

    Last Modified: Apr 24, 2025
    Published: Dec 01, 2022

    CVE-2021-40616

    thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group authority is required.

    Last Modified: Nov 21, 2024
    Published: Jun 14, 2022
    Items Per Page
    Thinkcmf Vulnerabilities & Security CVEs | CVE-DB