CWE-98

High likelihood

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

1,270 vulnerabilities with CWE-98
CVE-2026-13080 MEDIUM
WPFunnels <= 3.12.7 - Authenticated (Administrator+) Local File Inclusion via 'logKey' Parameter
CVSS 6.6
CVE-2026-12194 LOW
PHPIPAM Authenticated LFI
CVE-2026-5137 MEDIUM
RTMKit <= 2.0.7 - Authenticated (Contributor+) Limited Local File Inclusion via 'template' Parameter
CVSS 4.3
CVE-2026-57749 HIGH
WordPress SportsPress Pro plugin <= 2.7.29 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-57748 HIGH
WordPress Shopify plugin <= 1.0.0 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-42382 HIGH
WordPress Audrey theme <= 1.5 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-27412 HIGH
WordPress Pearl - Corporate Business theme <= 3.4.10 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-12923 HIGH
Video Gallery <= 4.0.3 - Authenticated (Subscriber+) Arbitrary Function Call via 'path' Parameter
CVSS 7.5
CVE-2026-57647 HIGH
WordPress Panorama Viewer – 360 Degree Image + Video Viewer plugin <= 1.6.1 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-54845 HIGH
WordPress MDTF plugin <= 1.3.8 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-7515 CRITICAL
BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
CVSS 9.8
CVE-2026-48820 MEDIUM
CakePHP: View::element() is missing a path containment check
CVE-2026-54814 HIGH
WordPress Motors plugin <= 1.4.109 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-39590 HIGH
WordPress Atomlab theme <= 2.4.5 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-39559 HIGH
WordPress Uppercase theme < 1.2.2 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-39523 HIGH
WordPress Solene Core plugin <= 2.3.2 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-40731 HIGH
WordPress ChapterOne theme <= 1.7 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-40721 HIGH
WordPress Element Pack Pro plugin <= 9.0.6 - Local File Inclusion vulnerability
CVSS 7.5
CVE-2026-39582 HIGH
WordPress Hitek theme < 1.8.3 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-39568 HIGH
WordPress Mr. SEO theme <= 2.0 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-39558 HIGH
WordPress Malmö theme <= 2.2 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-39549 HIGH
WordPress Aperitif theme <= 1.5 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-39547 HIGH
WordPress Getaway theme < 1.8 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-39537 HIGH
WordPress Mikado Core plugin <= 1.6 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-39522 HIGH
WordPress Solene theme <= 3.4 - Local File Inclusion vulnerability
CVSS 8.1
Details
Vulnerabilities 1,270
Exploit Likelihood High