CWE-98
High likelihoodImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
1,114 vulnerabilities with CWE-98
CVE-2026-28046
HIGH
ThemeREX Law Office <=3.3.0 - PHP RFI
CVSS 8.1
CVE-2026-28045
HIGH
ThemeREX N7 Golf Club <=2.16.0 - PHP RFI
CVSS 8.1
CVE-2026-28043
CRITICAL
ThemeREX Healer <=1.0.0 - PHP Local File Inclusion
CVSS 9.8
CVE-2026-28041
HIGH
AncoraThemes Grit <=1.0.1 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28039
HIGH
wpDataTables <=6.5.0.1 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-28035
HIGH
ThemeREX Printy <=1.8 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28034
HIGH
ThemeREX Progress <=1.2 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28033
HIGH
ThemeREX Edifice <=1.8 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28032
HIGH
ThemeREX Tuning <=1.3 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28031
HIGH
ThemeREX Invetex <=2.18 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28030
HIGH
ThemeREX Bonbon <=1.6 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28029
HIGH
ThemeREX EmojiNation <=1.0.12 - PHP RFI
CVSS 8.1
CVE-2026-28028
HIGH
ThemeREX MoneyFlow <=1.0 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28027
HIGH
ThemeREX Kayon <=1.3 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28026
HIGH
ThemeREX Motorix <=1.6 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28025
HIGH
ThemeREX Stargaze <=1.5 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28024
HIGH
Helion <=1.1.12 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28023
HIGH
ThemeREX Nuts <=1.10 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28022
HIGH
ThemeREX Foodie <=1.14 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28021
HIGH
ThemeREX Craftis <=1.2.8 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28020
HIGH
ThemeREX Chroma <=1.11 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28019
HIGH
ThemeREX Manoir <=1.11 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28018
HIGH
ThemeREX Global Logistics <=3.20 - PHP RFI
CVSS 8.1
CVE-2026-28017
HIGH
ThemeREX Green Thumb <=1.1.12 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28016
HIGH
ThemeREX Luxury Wine <=1.1.14 - PHP RFI
CVSS 8.1
Details
Vulnerabilities
1,114
Exploit Likelihood
High