CVE-2018-16385: ThinkPHP

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.

Affected products

  • ThinkPHP ThinkPHP: before 5.1.23 (fixed in 5.1.23)

Published 2018-09-03. Last modified 2026-06-17.