CVE-2019-7580: Thinkcmf

High severity, CVSS 8.8. EPSS: 9.9% chance of exploitation in the next 30 days.

ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection.

Affected products

  • Thinkcmf Thinkcmf: version 5.0.190111 only

Published 2019-02-07. Last modified 2026-06-17.