CVE-2019-11018: Thinkadmin

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials after a password change.

Affected products

Published 2019-04-08. Last modified 2026-06-17.