Skip to main content

CWE archive

CWE-98 CVEs

Programmatic archive

1,269 CVEs tagged with CWE-9865 Critical, 1,147 High, 55 Medium, 2 Low, 0 Unrated.

CVE-2026-25548

Published Feb 18, 2026

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-1988

Published Feb 14, 2026

The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.5 via the `flexipsg_carousel…

CVSS 7.5 · High
evidence mentions
5
Buzz score
29.4

CVE-2025-15368

Published Feb 4, 2026

The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This makes it pos…

CVSS 8.8 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-25027

Published Feb 3, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp allows PHP Local File Inclusion.…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-54263

Published Feb 2, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Talemy Spirit Framework allows PHP Local File Inclusion.Th…

CVSS 7.5 · High

CVE-2021-47900

Published Jan 27, 2026

Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP…

CVSS 9.3 · Critical

CVE-2026-1257

Published Jan 24, 2026

The Administrative Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.3.4 via the 'slug' attribute of the 'get_template'…

CVSS 7.5 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-24635

Published Jan 23, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DevsBlink EduBlink Core edublink-core allows PHP Local Fil…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24609

Published Jan 23, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent laurent allows PHP Local File Inclus…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24608

Published Jan 23, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent Core laurent-core allows PHP Local F…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24538

Published Jan 23, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in omnipressteam Omnipress omnipress allows PHP Local File In…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24531

Published Jan 23, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Prowess prowess allows PHP Local File Inclus…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24390

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QantumThemes Kentha Elementor Widgets kentha-elementor all…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-23978

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Softwebmedia Gyan Elements gyan-elements allows PHP Local…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-23975

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo golo allows PHP Local File Inclusion.This issue…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-22464

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-editi…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-22402

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pavothemes Triply triply allows PHP Local File Inclusion.T…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-22401

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pavothemes Freshio freshio allows PHP Local File Inclusion…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69314

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes Werkstatt werkstatt allows PHP Local File Inclu…

CVSS 8.1 · High

CVE-2025-69100

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North north-wp allows PHP Local File Inclusion.…

CVSS 8.1 · High

CVE-2025-69078

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Malta malta allows PHP Local File Inclusion.T…

CVSS 8.1 · High

CVE-2025-69077

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Hobo hobo allows PHP Local File Inclusion.Thi…

CVSS 8.1 · High

CVE-2025-69076

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Modern Housewife modernhousewife allows PHP L…

CVSS 8.1 · High

CVE-2025-69075

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Yolox yolox allows PHP Local File Inclusion.T…

CVSS 8.1 · High

CVE-2025-69074

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Pearson Specter pearsonspecter allows PHP Loc…

CVSS 8.1 · High
Showing 451-475 of 1,269 CVEsPage 19 of 51