CWE-98

High likelihood

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

1,114 vulnerabilities with CWE-98
CVE-2026-27077 HIGH
WordPress MultiOffice theme <= 1.2 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-27076 HIGH
WordPress LuxeDrive theme <= 1.0 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-27075 HIGH
WordPress Belfort theme <= 1.0 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-27048 HIGH
WordPress The Aisle Core plugin <= 2.0.5 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-27047 HIGH
WordPress Curly Core plugin <= 2.1.6 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-25464 HIGH
WordPress Jannah theme <= 7.6.3 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-25458 HIGH
WordPress Moments theme <= 2.2 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-25457 HIGH
WordPress Mixtape theme <= 2.1 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-25382 HIGH
WordPress IdealAuto theme < 3.8.6 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-25381 HIGH
WordPress LoveDate theme < 3.8.6 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-25380 HIGH
WordPress Feedy theme < 2.1.5 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-25379 HIGH
WordPress StreamVid theme < 6.8.6 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-25017 HIGH
WordPress NaturaLife Extensions plugin <= 2.1 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22516 HIGH
WordPress Wizor's theme <= 2.12 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22515 HIGH
WordPress VegaDays theme <= 1.2.0 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22514 HIGH
WordPress Unica theme <= 1.4.1 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22513 HIGH
WordPress Triompher theme <= 1.1.0 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22512 HIGH
WordPress Roisin theme <= 1.2.1 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22511 HIGH
WordPress NeoBeat theme <= 1.2 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22509 HIGH
WordPress Gioia theme <= 1.4 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22508 HIGH
WordPress Dentalux theme <= 3.3 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22506 HIGH
WordPress Amoli theme <= 1.0 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22504 HIGH
WordPress ProLingua theme <= 1.1.12 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22503 HIGH
WordPress Nelson theme <= 1.2.0 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22502 HIGH
WordPress Mr. Cobbler theme <= 1.1.9 - Local File Inclusion vulnerability
CVSS 8.1
Details
Vulnerabilities 1,114
Exploit Likelihood High