Skip to main content

CWE archive

CWE-98 CVEs

Programmatic archive

1,279 CVEs tagged with CWE-9865 Critical, 1,155 High, 57 Medium, 2 Low, 0 Unrated.

CVE-2025-69050

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Overworld overworld allows PHP Local File Incl…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69049

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Töbel tobel allows PHP Local File Inclusion.…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69047

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech MaxShop sw_maxshop allows PHP Local File Inclusi…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69046

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebGeniusLab iRecco Core irecco-core allows PHP Local File…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69044

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Vango vango allows PHP Local File Inclusion.Thi…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69043

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Rashy rashy allows PHP Local File Inclusion.Thi…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69042

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Lindo lindo allows PHP Local File Inclusion.Thi…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69041

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Dekoro dekoro allows PHP Local File Inclusion.T…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69040

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Bfres bfres allows PHP Local File Inclusion.Thi…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69039

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Bailly bailly allows PHP Local File Inclusion.T…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69038

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Hyori hyori allows PHP Local File Inclusion.Thi…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69037

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Pippo pippo allows PHP Local File Inclusion.Thi…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69005

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Search & Go search-and-go allows PHP Local F…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-69004

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in XpeedStudio Bajaar - Highly Customizable WooCommerce WordP…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-68913

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zozothemes Miion miion allows PHP Local File Inclusion.Thi…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-68908

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in temash Barberry barberry allows PHP Local File Inclusion.T…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-68905

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jegtheme JNews - Pay Writer jnews-pay-writer allows PHP Lo…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-68510

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeGoods Photography photography allows PHP Local File I…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-67957

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TangibleWP Listivo Core listivo-core allows PHP Local File…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-67955

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TangibleWP MyHome Core myhome-core allows PHP Local File I…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-67946

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in scriptsbundle AdForest adforest allows PHP Local File Incl…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-67941

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes The Aisle theaisle allows PHP Local File Inc…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-67940

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Powerlift powerlift allows PHP Local File In…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-67938

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Biagiotti biagiotti allows PHP Local File In…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-67616

Published Jan 22, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme Mella mella allows PHP Local File Inclusion.This…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Showing 501-525 of 1,279 CVEsPage 21 of 52