Skip to main content

CWE archive

CWE-98 CVEs

Programmatic archive

1,267 CVEs tagged with CWE-9865 Critical, 1,145 High, 55 Medium, 2 Low, 0 Unrated.

CVE-2024-11429

Published Dec 5, 2024

The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,…

CVSS 8.8 · High

CVE-2024-52501

Published Nov 28, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebbyTemplate Office Locator office-locator.This issue aff…

CVSS 7.5 · High

CVE-2024-52499

Published Nov 28, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ibrahim Pricing table addon for elementor pricing-table-ad…

CVSS 7.5 · High

CVE-2024-52497

Published Nov 28, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in quomodosoft Shopready shopready-elementor-addon allows PHP…

CVSS 7.5 · High

CVE-2024-52496

Published Nov 28, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AbsolutePlugins Absolute Addons For Elementor absolute-add…

CVSS 7.5 · High

CVE-2024-10873

Published Nov 23, 2024

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the _load_template function. Thi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10898

Published Nov 21, 2024

The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the cf7_email_add_on_add_admin_template()…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52450

Published Nov 20, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in officialprocoders nBlocks nblocks allows PHP Local File In…

CVSS 7.5 · High

CVE-2024-52428

Published Nov 18, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Peter Ads Booster by Ads Pro free-wp-booster-by-ads-pro al…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52386

Published Nov 16, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listing classified-listing allows P…

CVSS 5.3 · Medium

CVE-2024-52381

Published Nov 14, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Shoaib Rehmat ZIJ KART zij-kart allows PHP Local File Incl…

CVSS 8.1 · High

CVE-2024-10571

Published Nov 14, 2024

The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-10871

Published Nov 9, 2024

The Category Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.2 via the 'params[caf-post-layout]' parameter. This m…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2024-10436

Published Oct 29, 2024

The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.1 via the get_condition_value function.…

CVSS 8.8 · High

CVE-2024-50457

Published Oct 28, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qode Essential Addons qode-essential-addons.This issu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50436

Published Oct 28, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehorse Clean Retina clean-retina.This issue affects Cl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50435

Published Oct 28, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehorse Meta News meta-news.This issue affects Meta New…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50434

Published Oct 28, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehorse NewsCard newscard.This issue affects NewsCard:…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8392

Published Oct 26, 2024

The WordPress Post Grid Layouts with Pagination – Sogrid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.5.6 via the 'tab' param…

CVSS 7.2 · High

CVE-2024-49701

Published Oct 23, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehorse Mags mags.This issue affects Mags: from n/a thr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-49690

Published Oct 23, 2024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: fro…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,151-1,175 of 1,267 CVEsPage 47 of 51