CVE-2020-20601: Thinkcmf

Critical severity, CVSS 9.8. EPSS: 7.6% chance of exploitation in the next 30 days.

An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.

Affected products

  • Thinkcmf Thinkcmf: version x1.6.0 only; version x2.1.0 only; version x2.2.0 only; version x2.2.1 only; version x2.2.2 only

Published 2021-12-22. Last modified 2026-06-17.