Skip to main content

CWE archive

CWE-98 CVEs

Programmatic archive

1,269 CVEs tagged with CWE-9865 Critical, 1,147 High, 55 Medium, 2 Low, 0 Unrated.

CVE-2025-69397

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Tint tint allows PHP Local File Inclusion.This is…

CVSS 8.1 · High

CVE-2025-69396

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Splendour splendour allows PHP Local File Inclusi…

CVSS 8.1 · High

CVE-2025-69395

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Gable gable allows PHP Local File Inclusion.This…

CVSS 8.1 · High

CVE-2025-69387

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in whatwouldjessedo Simple Retail Menus simple-retail-menus a…

CVSS 7.5 · High

CVE-2025-69383

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows PHP L…

CVSS 7.5 · High

CVE-2025-69375

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SolverWp Portfolio Builder swp-portfolio allows PHP Local…

CVSS 8.1 · High

CVE-2025-69374

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SolverWp Eleblog – Elementor Blog And Magazine Addons ele-…

CVSS 8.1 · High

CVE-2025-69373

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 VidoRev vidorev allows PHP Local File Inclusion…

CVSS 7.5 · High

CVE-2025-69322

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes PeakShops peakshops allows PHP Local File Inclu…

CVSS 8.1 · High

CVE-2025-68841

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themepul TopperPack – Complete Elementor Addons, Theme & C…

CVSS 7.5 · High

CVE-2025-68552

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace WooCommerce Coming Soon Product with Countd…

CVSS 7.5 · High

CVE-2025-68545

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika nika allows PHP Local File Inclusion.This iss…

CVSS 8.1 · High

CVE-2025-68543

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Diza diza allows PHP Local File Inclusion.This iss…

CVSS 8.1 · High

CVE-2025-68539

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local File Inclusion.This iss…

CVSS 8.1 · High

CVE-2025-68536

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local File Inclusion.This iss…

CVSS 8.1 · High

CVE-2025-67992

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean PatioTime patiotime allows PHP Local File Inclus…

CVSS 8.1 · High

CVE-2025-67988

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean CozyStay cozystay allows PHP Local File Inclusio…

CVSS 8.1 · High

CVE-2025-67982

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna urna allows PHP Local File Inclusion.This iss…

CVSS 8.1 · High

CVE-2025-67981

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP Local File Inclusion.This iss…

CVSS 8.1 · High

CVE-2025-67980

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Hara hara allows PHP Local File Inclusion.This iss…

CVSS 8.1 · High

CVE-2025-60087

Published Feb 20, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nenad Obradovic Extensive VC Addons for WPBakery page buil…

CVSS 8.1 · High

CVE-2026-27343

Published Feb 19, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VanKarWai Airtifact airtifact allows PHP Local File Inclus…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-27052

Published Feb 19, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in villatheme Sales Countdown Timer for WooCommerce and WordP…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-25326

Published Feb 19, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-0926

Published Feb 19, 2026

The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'parameters[template_name]' parameter. This mak…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
26.0
Showing 426-450 of 1,269 CVEsPage 18 of 51