CWE-98
High likelihoodImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
1,228 vulnerabilities with CWE-98
CVE-2024-21687
HIGH
Atlassian Bamboo 9.0.0-9.6.0 - Authenticated Local File Inclusion and Remote Code Execution
CVSS 8.1
CVE-2024-38735
HIGH
N.O.U.S. Open Useful and Simple Event post <5.9.5 - Path Traversal
CVSS 7.5
CVE-2024-37520
MEDIUM
RadiusTheme ShopBuilder < 2.1.12 - Local File Inclusion
CVSS 6.5
CVE-2024-37410
MEDIUM
PowerPack Lite for Beaver Builder <= 1.3.0.3 - Local File Inclusion
CVSS 4.9
CVE-2024-37479
HIGH
LA-Studio Element Kit for Elementor <= 1.3.8.1 - Local File Inclusion via Progress Bar Widget Progress Type Attribute
CVSS 8.5
CVE-2024-5431
HIGH
WPCafe < 2.2.25 - Authenticated Local File Inclusion via reservation_extra_field Shortcode Parameter
CVSS 8.8
CVE-2024-5455
HIGH
Plus Addons for Elementor Page Builder <5.5.4 - Code Injection
CVSS 8.8
CVE-2024-5503
HIGH
WP Blog Post Layouts <1.1.3 - Code Injection
CVSS 8.8
CVE-2024-5574
HIGH
WP Magazine Modules Lite - Local File Inclusion
CVSS 7.5
CVE-2024-4551
MEDIUM
YotuWP <1.3.13 - Local File Inclusion
CVSS 6.4
CVE-2024-4258
CRITICAL
YotuWP <1.3.13 - Local File Inclusion
CVSS 9.8
CVE-2024-3813
HIGH
tagDiv Composer < 4.8 - Authenticated Local File Inclusion via block_template_id Attribute
CVSS 8.8
CVE-2024-5577
CRITICAL
Where I Was, Where I Will Be <1.1.1 - RCE
CVSS 9.8
CVE-2024-4936
CRITICAL
Canto < 3.0.9 - Unauthenticated Remote File Inclusion via abspath Parameter
CVSS 9.8
CVE-2024-36415
CRITICAL
SuiteCRM < 7.14.4 - Remote Code Execution via Unrestricted File Upload
CVSS 9.1
CVE-2024-35650
MEDIUM
MelaPress Login Security <= 1.3.0 - Remote File Inclusion
CVSS 4.9
CVE-2024-4887
HIGH
Qi Addons For Elementor <1.7.2 - RCE
CVSS 7.5
CVE-2024-35629
CRITICAL
Wow-Company Easy Digital Downloads - Recent Purchases <1.0.2 - Code...
CVSS 9.6
CVE-2024-36569
HIGH
Sourcecodester Gas Agency Management System v1.0 - RCE
CVSS 8.1
CVE-2024-5348
HIGH
Elements For Elementor <2.1 - Local File Inclusion
CVSS 8.8
CVE-2024-3564
HIGH
Content Blocks (Custom Post Widget) <3.3.0 - Code Injection
CVSS 8.8
CVE-2024-5345
HIGH
Responsive Owl Carousel for Elementor <1.2.0 - Code Injection
CVSS 8.8
CVE-2024-3812
HIGH
Salient Core <2.0.7 - Local File Inclusion
CVSS 7.5
CVE-2024-3810
HIGH
Salient Shortcodes <1.5.3 - Code Injection
CVSS 8.8
CVE-2024-32523
HIGH
EverPress Mailster <4.0.6 - Path Traversal
CVSS 8.1
Details
Vulnerabilities
1,228
Exploit Likelihood
High