CVE-2020-21865: THINKPHP50-CMS Project THINKPHP50-CMS

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

ThinkPHP50-CMS v1.0 contains a remote code execution (RCE) vulnerability in the component /public/?s=captcha.

Affected products

Published 2021-10-07. Last modified 2026-06-17.