CVE-2018-19894: Thinkcmf
High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.
ThinkCMF X2.2.2 has SQL Injection via the functions check() and delete() in CommentadminController.class.php and is exploitable with the manager privilege via the ids[] parameter in a commentadmin action.
Affected products
- Thinkcmf Thinkcmf: version x2.2.2 only
Published 2018-12-06. Last modified 2026-06-17.