References https://github.com/jas502n/ThinkCMF_getshell https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/ThinkCMF/ThinkCMF%20%E7%BC%93%E5%AD%98Getshell/ https://yaklang.com/Yaklab/wiki/DetectionPlug-in/ThinkCMF/ https://github.com/chaitin/xray/issues/833 http://www.0xby.com/2062.html https://cloud.tencent.com/developer/article/1533949 https://baizesec.github.io/bylibrary/%E6%BC%8F%E6%B4%9E%E5%BA%93/01-CMS%E6%BC%8F%E6%B4%9E/ThinkCMS/ThinkCMF%E6%BC%8F%E6%B4%9E%E5%85%A8%E9%9B%86%E5%92%8C/ https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/ThinkCMF/THINKCMFX_2.2.3%E6%BC%8F%E6%B4%9E%E5%90%88%E9%9B%86/ https://mochazz.github.io/2019/07/25/ThinkCMFX%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90%E5%90%88%E9%9B%86/ https://qkl.seebug.org/vuldb/ssvid-98223 https://www.cnblogs.com/mark-zh/p/11737823.html https://blog.csdn.net/cbaln0/article/details/102912478
Related VulnerabilitiesPoCCVE-2026-73034: DB-GPT <= 0.8.1 - Arbitrary File WritePoCCVE-2026-54917: SeaweedFS <= 4.29 - Path Traversal File WritePoCCVE-2026-12898: All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File WritePoCCVE-2026-25895: FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File WritePoCCVE-2026-49049: JoomShaper Helix3 <=3.1.0 - Unauthenticated Arbitrary JSON File WritePoCCVE-2026-50160: Hoppscotch <= 2026.4.1 - Mass Assignment JWT_SECRET OverwritePoCCVE-2026-64638: WordPress Core < 7.0.3 - Preauth Reflected XSS (XSS2Shell)PoCCVE-2026-1890: LeadConnector < 3.0.22 - Unauthenticated Arbitrary Data WritePoCCVE-2026-48282: Adobe ColdFusion - RDS Arbitrary File WriteNGINX ngx_http_rewrite_module 堆缓冲区溢出漏洞PoCCVE-2026-38360: dash-uploader 0.1.0 - 0.7.0a2 - Unauthenticated Arbitrary File Write via Path TraversalPoCCVE-2025-59342: esm.sh <= v136 - Arbitrary File Write via Path TraversalPoCCVE-2025-67303: ComfyUI-Manager < 3.38 - Configuration Overwrite