ThinkjsCVEs & Vulnerabilities
2 CVEs affecting Thinkjs products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
think-helper 1thinkjs 1
CVE-2021-32736HIGH
think-helper defines a set of helper functions for ThinkJS. In versions of think-helper prior to 1.1.3, the software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype. The vulnerability is patched in version 1.1.3.
30 Jun 2021
7.5
CVSS
CVE-2020-21176CRITICAL
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.
1 Feb 2021
9.8
CVSS
← PrevPage 1 / 1Next →