CWE-98

High likelihood

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

1,149 vulnerabilities with CWE-98
CVE-2025-69339 HIGH
Molla <=1.5.16 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-69090 HIGH
Remons <=1.3.4 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-53335 HIGH
ThemeREX Berger <=1.1.1 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-69410 HIGH
Belletrist <=1.2 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-69409 HIGH
PJ Life & Business Coaching <=3.0.0 - PHP RFI
CVSS 8.1
CVE-2025-69408 HIGH
Mikado-Themes HealthFirst <=1.0.1 - PHP RFI
CVSS 8.1
CVE-2025-69407 HIGH
Struktur <=2.5.1 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-69406 HIGH
ThemeREX FreightCo <=1.1.7 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-69402 HIGH
ThemeREX R&F rf <=1.5 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-69400 HIGH
ThemeREX Yokoo <=1.1.11 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-69399 HIGH
ThemeREX Cobble <=1.7 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-69398 HIGH
ThemeREX Plank <=1.7 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-69397 HIGH
ThemeREX Tint <=1.7 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-69396 HIGH
ThemeREX Splendour <=1.23 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-69395 HIGH
ThemeREX Gable <=1.5 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-69387 HIGH
Simple Retail Menus <=4.2.1 - PHP RFI
CVSS 7.5
CVE-2025-69383 HIGH
WP shop <=2.6.1 - PHP Local File Inclusion
CVSS 7.5
CVE-2025-69375 HIGH
SolverWp Portfolio Builder <=1.2.5 - PHP LFI
CVSS 8.1
CVE-2025-69374 HIGH
Eleblog - Elementor Blog And Magazine Addons <=2.0.3 - PHP Local Fi...
CVSS 8.1
CVE-2025-69373 HIGH
VidoRev <=2.9.9.9.9.9.7 - PHP Local File Inclusion
CVSS 7.5
CVE-2025-69322 HIGH
PeakShops <1.5.9 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-68841 HIGH
TopperPack <=1.2.1 - PHP Local File Inclusion
CVSS 7.5
CVE-2025-68552 HIGH
WooCommerce Coming Soon Product <=5.0 - PHP LFI
CVSS 7.5
CVE-2025-68545 HIGH
thembay Nika <=1.2.14 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-68543 HIGH
Thembay Diza <=1.3.15 - PHP Local File Inclusion
CVSS 8.1
Details
Vulnerabilities 1,149
Exploit Likelihood High