CVE-2020-19705: ThinkPHP-Zcms Project ThinkPHP-Zcms

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.

Affected products

Published 2021-08-26. Last modified 2026-06-17.