CVEs affecting projects tracked on Release Alert, from NVD & OSV.
thinkphp 3.1.3 has SQL Injection via the index.php s parameter.