CVE-2025-63888: Critical severity ThinkPHP ThinkPHP vulnerability
Published Nov 20, 2025
·Updated
The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.
Affected Software
2 affected components
ThinkPHP ThinkPHP
ThinkPHP ThinkPHP=5.0.24
Event History
Nov 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63888?
CVE-2025-63888 is classified as a critical vulnerability due to its remote code execution capability.
2
How do I fix CVE-2025-63888?
To fix CVE-2025-63888, you should upgrade ThinkPHP to the latest version that addresses this vulnerability.
3
What are the potential impacts of CVE-2025-63888?
The potential impact of CVE-2025-63888 includes unauthorized remote access and control over the server hosting ThinkPHP.
4
Is any version of ThinkPHP affected by CVE-2025-63888?
Yes, ThinkPHP version 5.0.24 is specifically affected by CVE-2025-63888.
5
How can I determine if my application is vulnerable to CVE-2025-63888?
You can determine if your application is vulnerable to CVE-2025-63888 by checking the version of ThinkPHP your application is using.