LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2018-25270

CVE-2018-25270 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: April 22, 2026

ThinkPHP - Remote Code Execution

Published: April 22, 2026Updated: April 22, 2026Remote Exploitable

Overview

ThinkPHP 5.0.23 contains a remote code execution caused by invoking functions through the routing parameter, letting unauthenticated attackers execute arbitrary PHP code with application privileges, exploit requires crafted requests to index.php.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 17.8%(Probability of exploitation in next 30 days)

Impact

Unauthenticated attackers can execute arbitrary PHP code, potentially leading to full system compromise.

Mitigation

Update to the latest version.

Social Media Activity(1 post)

Yazoul - Cybersecurity Alerts
Yazoul - Cybersecurity Alerts
@Matchbook3469
Apr 23, 2026

⛔ New security advisory: CVE-2018-25270 affects multiple systems. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems • Mitigation: Patch immediately or isolate affected systems Full breakdown: https://www.yazoul.net/advisory/cve/cve-2018-25270-thinkphp-5-0-23-unauthenticated-remote-code-execution #Cybersecurity #VulnerabilityManagement #CyberSec

View original post

Details

CVE ID
CVE-2018-25270
Severity
Critical
CVSS Score
9.8
Type
command_injection
Status
unconfirmed
EPSS
17.8%
Social Posts
1

CWE

  • CWE-639

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

17.8%Probability of exploitation in the next 30 days