CVE-2018-25270Patch(thinkphp / thinkphp)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch thinkphp thinkphp systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter. Attackers can craft requests to the index.php endpoint with malicious function parameters to execute system commands with application privileges.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • thinkphp

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
thinkphp

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-22: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-2204-23
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-221
Patch1
2026-04-231
Disclosure1
Full discourse2 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical authorisation bypass vulnerability in #ThinkPHP. CVE-2018-25270 CVSS: 9.8. Successful exploitation allows an unauthenticated attacker to perform remote code execution. #RCE! #Patch #Patch #Patch

    Post summary

    The tweet announces a critical authorization-bypass flaw (CVE-2018-25270) in ThinkPHP that allows remote code execution with high severity, but it does not provide exploit details or patches.

    01000180
    7.2K followersView on X
  • 0day Signal@0dayPublishing
    Patch

    🚨 CVE-2018-25270: ThinkPHP 5.0.23 Remote Code Exec... Unauthenticated RCE through function invocation makes every ThinkPHP 5.x instance a one-click shell - patch immediately... https://zerodaysignal.com/vulnerability/CVE-2018-25270 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A newly disclosed unauthenticated RCE in ThinkPHP 5.0.23 is highlighted with an urgent patch notice and a link to further details.

    0000072
    218 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appthinkphpthinkphp---
Appthinkphpthinkphp5.1.31--

Explore more