t
thinkphp
Security Risk Profile
79
/100
highSecurity Risk Score
Comprehensive risk assessment based on 29 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 19, 2018 to present
29
Total CVEs
27
Critical+High
4
Exploited
22
Unpatched
Threat Assessment
Avg CVSS
9.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
22
Critical/High
Risk Level
79/100
high
⚠️ 4 Active Exploits⚡ 1 Zero-Days
Severity Distribution
Critical
22High
5Medium
1Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
SQL Injection
8
2
Code Injection
3
3
Path Traversal
2
4
XSS
1
5
Malicious File Upload
1
Most Affected Products
1. ThinkPHP ThinkPHP36
2. composer/topthink/framework16
3. ThinkPHP Framework2
4. ownCloud GraphAPI1
5. ownCloud solution1
Recent Vulnerabilities
See more →CVE-2018-25270
CVSS 9.3critical
ThinkPHP 5.0.23 Remote Code Execution via invokefunction
Apr 22, 2026🔧 No Patch
CVE-2025-63889
CVSS 7.5high
Nov 20, 2025🔧 No Patch
CVE-2025-63888
CVSS 9.8critical
Nov 20, 2025🔧 No Patch
CVE-2025-50706
CVSS 9.8critical
Aug 5, 2025🔧 No Patch
CVE-2025-50707
CVSS 9.8critical
Aug 5, 2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/surge-in-attacks-exploiting-old-thinkphp-and-owncloud-flaws/
unknown
Surge in attacks exploiting old ThinkPHP and ownCloud flaws
Feb 12, 2025⚠ Exploited⚡ Zero-Day🔧 No Patch
CVE-2024-48112
CVSS 9.8critical
Oct 30, 2024🔧 No Patch
CVE-2024-44902
CVSS 9.8critical
Sep 9, 2024🔧 No Patch
CVE-2024-34467
CVSS 6.1EPSS 0%medium
May 4, 2024
CVE-2022-45982
CVSS 9.8critical
Feb 8, 2023🔧 No Patch
Monitor thinkphp in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.