CWE-98
High likelihoodImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
1,228 vulnerabilities with CWE-98
CVE-2025-39463
HIGH
Select-Themes Dessau <1.9 - Code Injection
CVSS 7.5
CVE-2025-12497
HIGH
Phlox theme plugin <2.3.10 - Local File Inclusion
CVSS 8.1
CVE-2025-11704
HIGH
Elegance Menu <1.9 - Local File Inclusion
CVSS 7.5
CVE-2025-11920
HIGH
WPCOM Member <1.7.14 - Code Injection
CVSS 8.8
CVE-2025-64364
HIGH
StylemixThemes Masterstudy < 4.8.126 - Code Injection
CVSS 7.5
CVE-2025-64363
HIGH
SeventhQueen Kleo <5.5.0 - Code Injection
CVSS 7.5
CVE-2025-64360
HIGH
StylemixThemes Consulting Elementor Widgets <1.4.2 - Code Injection
CVSS 7.5
CVE-2025-64359
HIGH
StylemixThemes Consulting < 6.7.5 - Code Injection
CVSS 7.5
CVE-2025-64284
HIGH
Majestic Support <1.1.1 - Code Injection
CVSS 7.5
CVE-2025-64216
HIGH
ThemeSphere SmartMag <10.3.0 - Code Injection
CVSS 7.5
CVE-2025-64195
HIGH
ThimPress Eduma <5.7.6 - Code Injection
CVSS 7.5
CVE-2025-62868
HIGH
Edge CPT < 1.4 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-11023
CRITICAL
AcBakImzala <5.1.4 - Code Injection
CVSS 9.8
CVE-2025-62054
HIGH
Houzez Theme - Functionality <4.1.8 - Code Injection
CVSS 7.5
CVE-2025-62029
HIGH
themesion Grevo <2.4 - Code Injection
CVSS 8.1
CVE-2025-59564
HIGH
ThemeMove EduMall < 4.4.5 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-59558
HIGH
ThemeMove Billey < 2.1.6 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-59555
HIGH
ThemeMove Medizin < 1.9.7 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-59550
HIGH
designervily Xcare <6.5 - Code Injection
CVSS 8.1
CVE-2025-58967
HIGH
ThemeMove Businext <2.4.4 - Code Injection
CVSS 8.1
CVE-2025-58958
HIGH
ThemeMove SmilePure <1.8.5 - Code Injection
CVSS 8.1
CVE-2025-58955
HIGH
designervily Karzo < 2.6 - PHP Local File Inclusion
CVSS 8.1
CVE-2025-49935
HIGH
xtemos WoodMart <8.3.2 - Code Injection
CVSS 7.5
CVE-2025-49921
HIGH
CrocoBlock JetReviews <=3.0.0 - Code Injection
CVSS 7.5
CVE-2025-48338
HIGH
Kevon Adonis WP Abstracts <= 2.7.4 - Code Injection
CVSS 7.5
Details
Vulnerabilities
1,228
Exploit Likelihood
High