CWE-98

High likelihood

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

1,270 vulnerabilities with CWE-98
CVE-2026-63302 MEDIUM
Local File Inclusion in Quick.CMS
CVE-2026-65481 HIGH
WordPress Vino theme <= 1.9 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-65477 HIGH
WordPress Tonda Core plugin <= 2.1.2 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-44177 HIGH
Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup
CVE-2026-46687 HIGH
Emlog Local File Inclusion (LFI)
CVE-2026-57805 HIGH
WordPress Tonda theme <= 2.5 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57804 HIGH
WordPress TheGem theme Elements (for Elementor) plugin <= 5.11.1 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57803 HIGH
WordPress Struktur Core plugin <= 2.5.1 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57802 HIGH
WordPress Struktur theme <= 2.5.1 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57801 HIGH
WordPress SetSail theme <= 2.1 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57800 HIGH
WordPress Overworld theme <= 1.5 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57799 HIGH
WordPress Nuss theme <= 1.3.6 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57798 HIGH
WordPress NewsPlus Shortcodes plugin <= 4.2.0 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57796 HIGH
WordPress Leedo theme <= 3.0.0 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57795 HIGH
WordPress Kitchor theme <= 1.4.3 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57794 HIGH
WordPress Golo Framework plugin <= 1.7.3 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57793 HIGH
WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57792 HIGH
WordPress Dør theme <= 2.4.1 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57791 HIGH
WordPress Brook theme <= 2.9.0 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57790 HIGH
WordPress Billey theme <= 2.1.8 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57789 HIGH
WordPress Aqua theme <= 5.1.2 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57788 HIGH
WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57743 HIGH
WordPress RT-Theme 18 | Extensions plugin <= 2.5 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-15540 MEDIUM
SourceCodester Online Book Store System Administrative index.php php file inclusion
CVSS 4.3
CVE-2026-15338 HIGH
LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting
CVSS 7.5
Details
Vulnerabilities 1,270
Exploit Likelihood High