CWE-98

High likelihood

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

1,228 vulnerabilities with CWE-98
CVE-2025-39463 HIGH
Select-Themes Dessau <1.9 - Code Injection
CVSS 7.5
CVE-2025-12497 HIGH
Phlox theme plugin <2.3.10 - Local File Inclusion
CVSS 8.1
CVE-2025-11704 HIGH
Elegance Menu <1.9 - Local File Inclusion
CVSS 7.5
CVE-2025-11920 HIGH
WPCOM Member <1.7.14 - Code Injection
CVSS 8.8
CVE-2025-64364 HIGH
StylemixThemes Masterstudy < 4.8.126 - Code Injection
CVSS 7.5
CVE-2025-64363 HIGH
SeventhQueen Kleo <5.5.0 - Code Injection
CVSS 7.5
CVE-2025-64360 HIGH
StylemixThemes Consulting Elementor Widgets <1.4.2 - Code Injection
CVSS 7.5
CVE-2025-64359 HIGH
StylemixThemes Consulting < 6.7.5 - Code Injection
CVSS 7.5
CVE-2025-64284 HIGH
Majestic Support <1.1.1 - Code Injection
CVSS 7.5
CVE-2025-64216 HIGH
ThemeSphere SmartMag <10.3.0 - Code Injection
CVSS 7.5
CVE-2025-64195 HIGH
ThimPress Eduma <5.7.6 - Code Injection
CVSS 7.5
CVE-2025-62868 HIGH
Edge CPT < 1.4 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-11023 CRITICAL
AcBakImzala <5.1.4 - Code Injection
CVSS 9.8
CVE-2025-62054 HIGH
Houzez Theme - Functionality <4.1.8 - Code Injection
CVSS 7.5
CVE-2025-62029 HIGH
themesion Grevo <2.4 - Code Injection
CVSS 8.1
CVE-2025-59564 HIGH
ThemeMove EduMall < 4.4.5 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-59558 HIGH
ThemeMove Billey < 2.1.6 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-59555 HIGH
ThemeMove Medizin < 1.9.7 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-59550 HIGH
designervily Xcare <6.5 - Code Injection
CVSS 8.1
CVE-2025-58967 HIGH
ThemeMove Businext <2.4.4 - Code Injection
CVSS 8.1
CVE-2025-58958 HIGH
ThemeMove SmilePure <1.8.5 - Code Injection
CVSS 8.1
CVE-2025-58955 HIGH
designervily Karzo < 2.6 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-49935 HIGH
xtemos WoodMart <8.3.2 - Code Injection
CVSS 7.5
CVE-2025-49921 HIGH
CrocoBlock JetReviews <=3.0.0 - Code Injection
CVSS 7.5
CVE-2025-48338 HIGH
Kevon Adonis WP Abstracts <= 2.7.4 - Code Injection
CVSS 7.5
Details
Vulnerabilities 1,228
Exploit Likelihood High