CWE-98

High likelihood

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

1,270 vulnerabilities with CWE-98
CVE-2026-22362 HIGH
Photolia <=1.0.3 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22361 HIGH
A-Mart <=1.0.2 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22356 HIGH
Jetpack CRM <=6.7.0 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-22344 HIGH
Mikado-Themes FiveStar <=1.7 - PHP RFI
CVSS 8.1
CVE-2026-27343 HIGH
Airtifact <=1.2.91 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-27052 HIGH
Sales Countdown Timer <=1.1.8.1 - PHP RFI
CVSS 7.5
CVE-2026-25326 HIGH
CMSMasters Content Composer <=1.4.5 - PHP LFI
CVSS 7.5
CVE-2026-0926 CRITICAL
Prodigy Commerce WordPress Plugin <3.2.9 - LFI
CVSS 9.8
CVE-2026-25548 CRITICAL
InvoicePlane 1.7.0 - RCE via LFI & Log Poisoning
CVSS 9.1
CVE-2026-1988 HIGH
Flexi Product Slider & Grid - Local File Inclusion
CVSS 7.5
CVE-2026-25027 HIGH
ThemeMove Unicamp <2.7.1 - Code Injection
CVSS 7.5
CVE-2026-1257 HIGH
WordPress <0.3.4 - Local File Inclusion
CVSS 7.5
CVE-2026-24635 HIGH
DevsBlink EduBlink Core <2.0.8 - Code Injection
CVSS 7.5
CVE-2026-24609 HIGH
Laurent <= 3.1 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-24608 HIGH
Laurent Core <2.4.1 - Code Injection
CVSS 7.5
CVE-2026-24538 HIGH
Omnipress <= 1.6.7 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-24531 HIGH
Select-Themes Prowess <= 2.3 - Code Injection
CVSS 7.5
CVE-2026-24390 HIGH
QantumThemes Kentha Elementor Widgets < 3.1 - Code Injection
CVSS 7.5
CVE-2026-23978 HIGH
Softwebmedia Gyan Elements <= 2.2.1 - Code Injection
CVSS 7.5
CVE-2026-23975 HIGH
uxper Golo < 1.7.5 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-22464 HIGH
wphocus My auctions allegro <3.6.33 - Code Injection
CVSS 7.5
CVE-2026-22402 HIGH
pavothemes Triply <= 2.4.7 - Code Injection
CVSS 7.5
CVE-2026-22401 HIGH
pavothemes Freshio <2.4.2 - Code Injection
CVSS 7.5
CVE-2026-22521 HIGH
G5Theme Handmade Framework <3.9 - Code Injection
CVSS 7.5
CVE-2025-11977 MEDIUM
HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion
CVSS 6.6
Details
Vulnerabilities 1,270
Exploit Likelihood High