CVE-2024-48112: ThinkPHP

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

Affected products

  • ThinkPHP ThinkPHP: from 6.1.3, up to and including 8.0.4

Published 2024-10-30. Last modified 2026-06-17.