Description


ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter. Attackers can craft requests to the index.php endpoint with malicious function parameters to execute system commands with application privileges.

Related CPE's


a

thinkphp

thinkphp

2

Weaknesses



CWE-639

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 · Critical

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-04-22T16:16:47.770Z

5 months ago

Last modified

2026-06-17T01:55:07.767Z

3 months ago