Skip to main content

CWE archive

CWE-98 CVEs

Programmatic archive

1,267 CVEs tagged with CWE-9865 Critical, 1,145 High, 55 Medium, 2 Low, 0 Unrated.

CVE-2026-9662

Published Jun 9, 2026

The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to insufficient validation and s…

CVSS 8.1 · High
evidence mentions
8
Buzz score
37.0

CVE-2026-39553

Published Jun 2, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes WaveRide allows PHP Local File Inclusion. T…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39552

Published Jun 2, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion.…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69369

Published Jun 2, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows PHP Local File Inclusion. This…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-68886

Published Jun 2, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion. Th…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-58897

Published Jun 2, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows PHP Local File Inclusion. Th…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-58707

Published Jun 2, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion. This is…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-58705

Published Jun 2, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Crafti allows PHP Local File Inclusion. This…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-58024

Published Jun 2, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnboundStudio Accordion FAQ allows PHP Local File Inclusio…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-53440

Published Jun 2, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Confidant allows PHP Local File Inclusion. Th…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-44239

Published May 29, 2026

FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitiza…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9559

Published May 29, 2026

A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-37266

Published May 28, 2026

An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component

CVSS 8.0 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-48972

Published May 27, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SeedProd LLC SeedProd Pro allows PHP Local File Inclusion.…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-9200

Published May 27, 2026

The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2.1 via the shortcode function. This makes it possible for a…

CVSS 7.5 · High
evidence mentions
5
Buzz score
32.9

CVE-2026-48133

Published May 26, 2026

When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-39661

Published May 26, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP Local File Inclusion. This i…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-8134

Published May 21, 2026

Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An a…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-39850

Published May 20, 2026

Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local File Inclusion. Th…

CVSS 7.4 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-7522

Published May 20, 2026

The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.0 via the 'template' parameter. This makes…

CVSS 8.8 · High
evidence mentions
3
Buzz score
25.4

CVE-2018-25329

Published May 17, 2026

WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting file paths into the u…

CVSS 8.7 · High

CVE-2018-25324

Published May 17, 2026

Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by injecting null byte…

CVSS 6.9 · Medium

CVE-2021-47978

Published May 16, 2026

ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper path traversal validation. At…

CVSS 6.9 · Medium

CVE-2020-37246

Published May 16, 2026

Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path par…

CVSS 6.9 · Medium

CVE-2020-37169

Published May 13, 2026

WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parame…

CVSS 6.8 · Medium
Showing 126-150 of 1,267 CVEsPage 6 of 51