CVE-2025-13284: Thinplus
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
Affected products
- Thinplus Thinplus
Published 2025-11-17. Last modified 2026-06-17.