Skip to main content

CWE archive

CWE-98 CVEs

Programmatic archive

1,269 CVEs tagged with CWE-9865 Critical, 1,147 High, 55 Medium, 2 Low, 0 Unrated.

CVE-2025-54138

Published Jul 22, 2025

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. LibreNMS versions 25.6.0…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24937

Published Jul 21, 2025

File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web applicat…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-10133

Published Jul 19, 2025

The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the Path to header value. This allows authenticated attac…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54015

Published Jul 16, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows PHP Loc…

CVSS 6.6 · Medium

CVE-2025-6746

Published Jul 8, 2025

The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This makes it possible for authenti…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-7327

Published Jul 8, 2025

The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.15 via the layout parameter. This makes it possib…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52807

Published Jul 4, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Kossy - Minimalist eCommerce WordPress Theme kossy…

CVSS 8.1 · High

CVE-2025-4414

Published Jul 4, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-…

CVSS 8.1 · High

CVE-2025-49070

Published Jul 4, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Elessi elessi-theme allows PHP Local File Inclus…

CVSS 7.5 · High

CVE-2025-47627

Published Jul 4, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LCweb PrivateContent - Mail Actions allows PHP Local File…

CVSS 7.5 · High

CVE-2025-4689

Published Jul 2, 2025

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion which leads to Remote Code Execution in all versions up…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-4380

Published Jul 2, 2025

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.89 via the 'bsa…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-53339

Published Jun 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in devnex Devnex Addons For Elementor devnex-addons-for-eleme…

CVSS 7.5 · High

CVE-2025-53281

Published Jun 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPBean WPB Category Slider for WooCommerce wpb-woocommerce…

CVSS 7.5 · High

CVE-2025-53259

Published Jun 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking nd-booking allows PHP Local File Inc…

CVSS 7.5 · High

CVE-2025-53257

Published Jun 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Serhii Pasyuk Gmedia Photo Gallery grand-media allows PHP…

CVSS 7.5 · High

CVE-2025-52816

Published Jun 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehunk Zita zita allows PHP Local File Inclusion.This i…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52815

Published Jun 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CityGov citygov allows PHP Local File Inclusi…

CVSS 8.1 · High

CVE-2025-52814

Published Jun 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme BRW ova-brw allows PHP Local File Inclusion.This…

CVSS 8.1 · High

CVE-2025-52812

Published Jun 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Domnoo domnoo allows PHP Local File Inclusion.This…

CVSS 8.1 · High

CVE-2025-52809

Published Jun 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Russell National Weather Service Alerts national-weat…

CVSS 8.1 · High

CVE-2025-52808

Published Jun 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in real-web RealtyElite realtyelite allows PHP Local File Inc…

CVSS 8.1 · High

CVE-2025-52729

Published Jun 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Diza diza allows PHP Local File Inclusion.This iss…

CVSS 8.1 · High

CVE-2025-52723

Published Jun 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in codesupplyco Networker networker allows PHP Local File Inc…

CVSS 8.1 · High

CVE-2025-49886

Published Jun 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebGeniusLab Zikzag Core zikzag-core allows PHP Local File…

CVSS 8.1 · High
Showing 876-900 of 1,269 CVEsPage 36 of 51