Skip to main content

CWE archive

CWE-98 CVEs

Programmatic archive

1,272 CVEs tagged with CWE-9865 Critical, 1,148 High, 57 Medium, 2 Low, 0 Unrated.

CVE-2025-62868

Published Oct 24, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Edge CPT allows PHP Local File Inclusion.This…

CVSS 8.1 · High

CVE-2025-11023

Published Oct 23, 2025

Inclusion of Functionality from Untrusted Control Sphere, Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2025-62054

Published Oct 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez Theme - Functionality houzez-theme-funct…

CVSS 7.5 · High

CVE-2025-62029

Published Oct 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themesion Grevo grevo.This issue affects Grevo: from n/a t…

CVSS 8.1 · High

CVE-2025-59564

Published Oct 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall allows PHP Local File Inclusion.…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59558

Published Oct 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.Th…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59555

Published Oct 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Medizin medizin allows PHP Local File Inclusion.…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59550

Published Oct 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Xcare xcare allows PHP Local File Inclusion.T…

CVSS 8.1 · High

CVE-2025-58967

Published Oct 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Businext businext allows PHP Local File Inclusio…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58958

Published Oct 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove SmilePure smilepure allows PHP Local File Inclus…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58955

Published Oct 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Karzo karzo allows PHP Local File Inclusion.T…

CVSS 8.1 · High

CVE-2025-49935

Published Oct 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in xtemos WoodMart woodmart allows PHP Local File Inclusion.T…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-49921

Published Oct 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetReviews jet-reviews allows PHP Local File In…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-48338

Published Oct 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-32657

Published Oct 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slider And Showcase Pro testimonia…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-11722

Published Oct 15, 2025

The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0 via the 'categoryaccordi…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4

CVE-2025-7634

Published Oct 9, 2025

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.6.7 via the…

CVSS 9.8 · Critical

CVE-2025-7721

Published Oct 3, 2025

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.7.3 via the t…

CVSS 9.8 · Critical

CVE-2025-9993

Published Sep 30, 2025

The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the 'task'. This makes it possible…

CVSS 8.1 · High

CVE-2025-9991

Published Sep 30, 2025

The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.3.34 via the 'language' parameter. This makes…

CVSS 8.1 · High

CVE-2025-60153

Published Sep 26, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpshuffle Subscribe To Unlock subscribe-to-unlock allows P…

CVSS 7.5 · High

CVE-2025-60150

Published Sep 26, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpshuffle Subscribe to Download subscribe-to-download allo…

CVSS 7.5 · High

CVE-2025-60126

Published Sep 26, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginOps Testimonial Slider testimonial-add allows PHP Lo…

CVSS 8.8 · High

CVE-2025-59588

Published Sep 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusio…

CVSS 7.5 · High

CVE-2025-58973

Published Sep 22, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hashthemes Easy Elementor Addons easy-elementor-addons all…

CVSS 7.5 · High
Showing 776-800 of 1,272 CVEsPage 32 of 51