CWE-98
High likelihoodImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
1,270 vulnerabilities with CWE-98
CVE-2026-22362
HIGH
Photolia <=1.0.3 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22361
HIGH
A-Mart <=1.0.2 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-22356
HIGH
Jetpack CRM <=6.7.0 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-22344
HIGH
Mikado-Themes FiveStar <=1.7 - PHP RFI
CVSS 8.1
CVE-2026-27343
HIGH
Airtifact <=1.2.91 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-27052
HIGH
Sales Countdown Timer <=1.1.8.1 - PHP RFI
CVSS 7.5
CVE-2026-25326
HIGH
CMSMasters Content Composer <=1.4.5 - PHP LFI
CVSS 7.5
CVE-2026-0926
CRITICAL
Prodigy Commerce WordPress Plugin <3.2.9 - LFI
CVSS 9.8
CVE-2026-25548
CRITICAL
InvoicePlane 1.7.0 - RCE via LFI & Log Poisoning
CVSS 9.1
CVE-2026-1988
HIGH
Flexi Product Slider & Grid - Local File Inclusion
CVSS 7.5
CVE-2026-25027
HIGH
ThemeMove Unicamp <2.7.1 - Code Injection
CVSS 7.5
CVE-2026-1257
HIGH
WordPress <0.3.4 - Local File Inclusion
CVSS 7.5
CVE-2026-24635
HIGH
DevsBlink EduBlink Core <2.0.8 - Code Injection
CVSS 7.5
CVE-2026-24609
HIGH
Laurent <= 3.1 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-24608
HIGH
Laurent Core <2.4.1 - Code Injection
CVSS 7.5
CVE-2026-24538
HIGH
Omnipress <= 1.6.7 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-24531
HIGH
Select-Themes Prowess <= 2.3 - Code Injection
CVSS 7.5
CVE-2026-24390
HIGH
QantumThemes Kentha Elementor Widgets < 3.1 - Code Injection
CVSS 7.5
CVE-2026-23978
HIGH
Softwebmedia Gyan Elements <= 2.2.1 - Code Injection
CVSS 7.5
CVE-2026-23975
HIGH
uxper Golo < 1.7.5 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-22464
HIGH
wphocus My auctions allegro <3.6.33 - Code Injection
CVSS 7.5
CVE-2026-22402
HIGH
pavothemes Triply <= 2.4.7 - Code Injection
CVSS 7.5
CVE-2026-22401
HIGH
pavothemes Freshio <2.4.2 - Code Injection
CVSS 7.5
CVE-2026-22521
HIGH
G5Theme Handmade Framework <3.9 - Code Injection
CVSS 7.5
CVE-2025-11977
MEDIUM
HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion
CVSS 6.6
Details
Vulnerabilities
1,270
Exploit Likelihood
High