Loading
A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.
Use Thinkphp vendor hub and Thinkphp product page to widen CVE-2021-44892 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-63888, CVE-2025-50707 and CVE-2025-50706 for nearby disclosures in the same product family.