Skip to main content

CWE archive

CWE-98 CVEs

Programmatic archive

1,269 CVEs tagged with CWE-9865 Critical, 1,147 High, 55 Medium, 2 Low, 0 Unrated.

CVE-2025-7650

Published Aug 15, 2025

The BizCalendar Web plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.0.53 via the 'bizcalv' shortcode. This makes it possible f…

CVSS 7.5 · High

CVE-2025-54701

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp allows PHP Local File Inclusion.…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54700

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Makeaholic makeaholic allows PHP Local File Incl…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54690

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeStek Xinterio xinterio allows PHP Local File Inclusio…

CVSS 8.1 · High

CVE-2025-54689

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna urna allows PHP Local File Inclusion.This iss…

CVSS 8.1 · High

CVE-2025-52806

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in eyecix JobSearch wp-jobsearch allows PHP Local File Inclus…

CVSS 7.5 · High

CVE-2025-52732

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 GMap Targeting gmap-targeting allows PHP Local…

CVSS 8.8 · High

CVE-2025-52728

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-po…

CVSS 7.5 · High

CVE-2025-52716

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Acato WP REST Cache wp-rest-cache allows PHP Local File In…

CVSS 7.5 · High

CVE-2025-49271

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GravityWP GravityWP - Merge Tags gravitywp-merge-tags allo…

CVSS 7.5 · High

CVE-2025-49264

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cloud Infrastructure Services Cloud SAML SSO - Single Sign…

CVSS 7.5 · High

CVE-2025-49036

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in octagonwebstudio Premium Addons for KingComposer premium-a…

CVSS 8.1 · High

CVE-2025-48332

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress Gutenberg Blocks advanced-gutenberg allows PH…

CVSS 7.5 · High

CVE-2025-48293

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dylan Kuhn Geo Mashup geo-mashup allows PHP Local File In…

CVSS 9.8 · Critical

CVE-2025-3703

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wipeoutmedia CSS & JavaScript Toolbox css-javascript-toolb…

CVSS 7.5 · High

CVE-2025-32288

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP…

CVSS 7.5 · High

CVE-2025-30635

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeAtelier IDonatePro idonate-pro allows PHP Local File…

CVSS 8.1 · High

CVE-2025-28979

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress WP Pipes allows PHP Local File Inclusion. This i…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-25174

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 BeeTeam368 Extensions beeteam368-extensions all…

CVSS 10.0 · Critical

CVE-2025-25172

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 VidMov vidmov allows PHP Local File Inclusion.T…

CVSS 8.1 · High

CVE-2025-24766

Published Aug 14, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wproyal News Magazine X news-magazine-x allows PHP Local F…

CVSS 7.5 · High

CVE-2025-8913

Published Aug 13, 2025

Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-51057

Published Aug 6, 2025

A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'rea…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-10025

Published Aug 5, 2025

The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export.php. When the PHP configurati…

CVSS 10.0 · Critical

CVE-2025-6991

Published Jul 26, 2025

The kallyas theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.21.0 via the 'TH_LatestPosts4` widget. This makes it possible for aut…

CVSS 7.5 · High
Showing 851-875 of 1,269 CVEsPage 35 of 51