CVE-2024-44902: ThinkPHP

Critical severity, CVSS 9.8. EPSS: 4.2% chance of exploitation in the next 30 days.

A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

Affected products

  • ThinkPHP ThinkPHP: from 6.1.3, up to and including 8.0.4

Published 2024-09-09. Last modified 2026-07-05.