CWE-98

High likelihood

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

1,270 vulnerabilities with CWE-98
CVE-2025-69133 HIGH
WordPress Tourmaster plugin <= 5.4.5 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2025-58902 HIGH
WordPress Lighthouse theme <= 1.2.12 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-68064 HIGH
WordPress Goya Core plugin < 1.0.9.4 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2025-68063 HIGH
WordPress Splash - Sport Club WordPress theme for Basketball, Football, Hockey theme <= 4.4.3 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2025-69175 HIGH
WordPress Line Agency theme <= 1.3.1 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69174 HIGH
WordPress Etude theme <= 1.6 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69170 HIGH
WordPress Eventicity theme <= 1.5 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69166 HIGH
WordPress Gunslinger theme <= 1.7 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69164 HIGH
WordPress Skyward theme <= 1.10 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69158 HIGH
WordPress Granola theme <= 1.13 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69157 HIGH
WordPress Gamic theme <= 1.15 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69144 HIGH
WordPress Preservation theme <= 1.10 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69126 HIGH
WordPress Fortius theme <= 2.3.0 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69123 HIGH
WordPress Snow Club theme <= 1.1 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69120 HIGH
WordPress Dazzle theme <= 1.0.0 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69115 HIGH
WordPress LuxMed | Medicine & Healthcare Doctor WordPress Theme theme <= 1.2.2 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69106 HIGH
WordPress Imba theme <= 1.5.0 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69178 HIGH
WordPress Truemag theme <= 4.3.14.2 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69177 HIGH
WordPress Roneous theme <= 2.1.5 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69176 HIGH
WordPress ITactics theme <= 1.0 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69173 HIGH
WordPress Tipsy theme <= 1.1 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69172 HIGH
WordPress Resurs theme <= 1.3 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69171 HIGH
WordPress Orpheus theme <= 1.3 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69168 HIGH
WordPress Spike theme <= 1.2 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2025-69167 HIGH
WordPress Eros theme <= 1.3 - Local File Inclusion vulnerability
CVSS 8.1
Details
Vulnerabilities 1,270
Exploit Likelihood High