CVE-2019-9082: ThinkPHP Remote Code Execution Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 97.4% chance of exploitation in the next 30 days.

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

Affected products

  • Opensourcebms Open Source Background Management System: version 1.1.1 only
  • ThinkPHP ThinkPHP: before 3.2.4 (fixed in 3.2.4)
  • Zzzcms Zzzphp: version 1.6.1 only

Published 2019-02-24. Last modified 2026-06-17.