Skip to main content

CWE archive

CWE-98 CVEs

Programmatic archive

1,270 CVEs tagged with CWE-9865 Critical, 1,147 High, 56 Medium, 2 Low, 0 Unrated.

CVE-2026-63302

Published Jul 28, 2026

Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files lo…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-65481

Published Jul 23, 2026

Contributor Local File Inclusion in Vino <= 1.9 versions.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65477

Published Jul 23, 2026

Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44177

Published Jul 16, 2026

Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user ID, resulting in a path trave…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-46687

Published Jul 16, 2026

Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-57805

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Tonda tonda allows PHP Local File Inclusion.…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57804

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-e…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57803

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur Core struktur-core allows PHP Local…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57802

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur struktur allows PHP Local File Incl…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57801

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes SetSail setsail allows PHP Local File Inclus…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57800

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Overworld overworld allows PHP Local File Incl…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57799

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Nuss nuss allows PHP Local File Inclusion.This issue…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57798

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortcodes newsplus-shortcodes allo…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57796

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VLThemes Leedo leedo allows PHP Local File Inclusion.This…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57795

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Kitchor kitchor allows PHP Local File Inclusion…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57794

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-framework allows PHP Local File…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57793

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Flow flow allows PHP Local File Inclusion.Th…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57792

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57791

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57790

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.Th…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57789

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PHP Local File Inclusion.This i…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57788

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Aalto aalto allows PHP Local File Inclusion.Th…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57743

Published Jul 13, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-15540

Published Jul 13, 2026

A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrati…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-15338

Published Jul 11, 2026

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function.…

CVSS 7.5 · High
evidence mentions
8
Buzz score
33.5
Showing 1-25 of 1,270 CVEsPage 1 of 51