CVE-2025-63889: ThinkPHP

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary files via crafted file path in a template value.

Affected products

Published 2025-11-20. Last modified 2026-06-17.