CWE-98

High likelihood

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

1,149 vulnerabilities with CWE-98
CVE-2026-22424 HIGH
AncoraThemes Shaha <=1.1.2 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22423 HIGH
Select-Themes SetSail <=1.8 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22421 HIGH
AncoraThemes Quantum <=1.0 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22420 HIGH
AncoraThemes Horizon <=1.1 - PHP RFI
CVSS 8.1
CVE-2026-22419 HIGH
AncoraThemes Honor <=2.3 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22418 HIGH
AncoraThemes Great Lotus <=1.3.1 - PHP RFI
CVSS 8.1
CVE-2026-22416 HIGH
FixTeam <=1.4 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22415 HIGH
The Mounty <=1.1 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22414 HIGH
Mikado-Themes Marra <=1.2 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22413 HIGH
Malgré <=1.0.3 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22412 HIGH
Mikado-Themes Eona <= 1.3 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22410 HIGH
Mikado-Themes Dolcino <=1.6 - PHP RFI
CVSS 8.1
CVE-2026-22408 HIGH
Justicia <=1.2 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22405 HIGH
Mikado-Themes Overton <=1.3 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22403 HIGH
Mikado-Themes Innovio <=1.7 - PHP RFI
CVSS 8.1
CVE-2026-22399 HIGH
Mikado-Themes Holmes <=1.7 - PHP RFI
CVSS 8.1
CVE-2026-22397 HIGH
Mikado-Themes Fleur <=2.0 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22395 HIGH
Mikado-Themes Fiorello <=1.0 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22394 HIGH
Mikado-Themes Evently <=1.7 - PHP RFI
CVSS 8.1
CVE-2026-22392 HIGH
Mikado-Themes Cortex <=1.5 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22389 HIGH
Mikado-Themes Cocco <=1.5.1 - PHP RFI
CVSS 8.1
CVE-2026-22387 HIGH
Mikado-Themes Aviana <=2.1 - PHP RFI
CVSS 8.1
CVE-2026-22385 HIGH
Wolmart <=1.9.6 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22381 HIGH
PawFriends <=1.3 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22380 HIGH
AncoraThemes UnlimHost <=1.2.3 - PHP RFI
CVSS 8.1
Details
Vulnerabilities 1,149
Exploit Likelihood High