Skip to content
COOEY

FAIL › dossier

thinkphp

VENDOR

· dossier confidence 50%

ThinkPHP is a PHP framework with a concerning history of critical remote code execution vulnerabilities, highlighting a need for rigorous security assessments and remediation efforts. The repeated nature of these vulnerabilities suggests systemic issues in their development practices. This poses a significant risk to systems utilizing ThinkPHP.

PROFILE
CategorySoftware DevelopmentWhat they doThinkPHP is a free and open-source PHP framework. It is designed to simplify web application development and provide a robust foundation for building complex systems.
SECURITY POSTURE

ThinkPHP has a history of critical remote code execution vulnerabilities, indicating a significant risk profile. Repeated vulnerabilities suggest potential weaknesses in the development lifecycle and security practices.

Notable failures
  • CVE-2018-20062 RCE
  • CVE-2019-9082 RCE
  • CVE-2024-44902 RCE
  • CVE-2024-44902 RCE
Patterns: Recurring RCE vulnerabilities; Unpatched vulnerabilities; Deserialization vulnerabilities
FAILURE HISTORY · 5
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2018-20062 high ThinkPHP's noneCms framework suffered a remote code execution flaw via the filter parameter that was actively exploited in the wild.
2021-11-03 CVE-2019-9082 high ThinkPHP framework suffered a remote code execution vulnerability that was actively exploited in the wild.
2021-11-03 CVE-2019-9082 high ThinkPHP framework suffered a remote code execution vulnerability that was actively exploited in the wild.
2024-09-09 CVE-2024-44902 critical A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
2024-09-09 CVE-2024-44902 critical A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
ThinkPHP's CVE-2018-20062 RCE vulnerability in noneCms was widely recognized as a critical flaw allowing remote code execution via filter parameter abuse, resulting in severe fallout for the vendor an
synthesissevere-fallout-0.60
ThinkPHP's RCE vulnerability was widely recognized as critical and exploited, leading to severe fallout for the vendor.
github.com ↗severe-fallout+0.00
GitHub advisory database entry is unrelated to CVE-2018-20062 and ThinkPHP.
www.cvefind.com ↗severe-fallout+0.00
CVEFind is a vulnerability database and does not comment on ThinkPHP's CVE-2018-20062.
NVD ↗severe-fallout+0.00
NVD page for CVE-2026-77647 is unrelated to CVE-2018-20062 and ThinkPHP.
app.opencve.io ↗severe-fallout+0.00
OpenCVE database entry is unrelated to CVE-2018-20062 and ThinkPHP.
cvefeed.io ↗severe-fallout+0.00
CVEFeed.io mirrors CISA KEV but does not comment on CVE-2018-20062.
www.youtube.com ↗severe-fallout+0.00
YouTube video is unrelated to CVE-2018-20062 and ThinkPHP.
NVD ↗severe-fallout+0.00
Irrelevant NVD page unrelated to CVE-2019-9082.
cooey ↗severe-fallout-0.80
NVD confirms critical RCE vulnerability in ThinkPHP, indicating severe security failure.
"ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command."
www.cvefind.com ↗severe-fallout+0.00
Neutral CVE database listing without specific sentiment toward ThinkPHP.
cvefeed.io ↗severe-fallout-0.50
CISA KEV catalog inclusion signals active exploitation, amplifying vendor fallout.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
app.opencve.io ↗severe-fallout+0.00
Neutral CVE database listing without specific sentiment toward ThinkPHP.
www.youtube.com ↗severe-fallout+0.00
Irrelevant YouTube content unrelated to CVE-2019-9082.
www.looperman.com ↗severe-fallout+0.00
Irrelevant audio samples unrelated to CVE-2019-9082.
cooey ↗severe-fallout-0.80
NVD confirms the RCE vulnerability in ThinkPHP noneCms, indicating a severe security failure.
"ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter."
Open questions: What is the current ownership structure? · What is the current employee count? · What is the current website URL?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-29 04:20:16.183705+00:00