CWE-98
High likelihoodImproper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
1,270 vulnerabilities with CWE-98
CVE-2026-22498
HIGH
WordPress Laurent theme <= 3.1 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22496
HIGH
WordPress Hypnotherapy theme <= 1.2.10 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22495
HIGH
WordPress Greenville theme <= 1.3.2 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22494
HIGH
WordPress Good Homes theme <= 1.3.13 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-22493
HIGH
WordPress Gaspard theme <= 1.3 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-33513
HIGH
AVideo <=26.0 API locale - Unauthenticated Local File Inclusion
CVSS 8.6
CVE-2026-33130
MEDIUM
Uptime Kuma: SSTI in Notification Templates Allows Arbitrary File Read (Incomplete Fix for GHSA-vffh-c9pq-4crh)
CVSS 6.5
CVE-2026-22324
HIGH
WordPress Melania theme <= 2.5.0 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-27065
CRITICAL
WordPress BuilderPress plugin <= 2.0.1 - Local File Inclusion vulnerability
CVSS 9.8
CVE-2026-27093
HIGH
WordPress Tripgo theme < 1.5.6 - Local File Inclusion vulnerability
CVSS 8.1
CVE-2026-29858
HIGH
aaPanel 7.57.0 - Local File Inclusion via Path Validation Bypass
CVSS 7.5
CVE-2026-1463
HIGH
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery <= 4.0.4 - Authenticated (Author+) Local File Inclusion
CVSS 8.8
CVE-2026-27894
HIGH
LAM has Authenticated Local File Inclusion (LFI) in PDF export
CVSS 8.8
CVE-2026-32426
HIGH
Medilazar Core <1.4.7 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-32401
HIGH
Sprout Invoices Client Invoicing <=20.8.9 - PHP RFI
CVSS 7.2
CVE-2026-32400
HIGH
Boldman <=7.7 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-32393
HIGH
Greenly Theme Addons <8.2 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-32392
HIGH
Creatives_Planet Greenly <=8.1 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-32384
HIGH
WpBookingly <=1.2.9 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-32369
HIGH
RadiusTheme Medilink-Core <2.0.7 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-32364
HIGH
Turbo Manager <4.0.8 - PHP Local File Inclusion
CVSS 7.5
CVE-2026-3826
CRITICAL
WellChoose organization_portal_system < iftop_p4_181 - Unauthenticated Local File Inclusion
CVSS 9.8
CVE-2026-28129
HIGH
Little Birdies <=1.3.16 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28128
HIGH
ThemeREX Verse <=1.7.0 - PHP Local File Inclusion
CVSS 8.1
CVE-2026-28125
HIGH
Midi <=1.14 - PHP Local File Inclusion
CVSS 8.1
Details
Vulnerabilities
1,270
Exploit Likelihood
High