{"id":"CVE-2018-16385","aliases":["GHSA-vcm7-88jx-3r39"],"url":"https://o3.security/vulnerability/CVE-2018-16385","summary":"ThinkPHP SQL Injection vulnerability","details":"ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.","published":"2018-09-03T02:29:00.487Z","modified":"2026-07-08T17:18:10.171406Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"topthink/framework","fixedVersion":"5.1.23"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/149288"},{"type":"EVIDENCE","url":"https://github.com/top-think/framework/issues/1375"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T17:18:10.171406Z"}}