CVE-2025-63889: ThinkPHP
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary files via crafted file path in a template value.
Affected products
- ThinkPHP ThinkPHP: version 5.0.24 only
Published 2025-11-20. Last modified 2026-06-17.