Skip to main content

CWE archive

CWE-98 CVEs

Programmatic archive

1,269 CVEs tagged with CWE-9865 Critical, 1,147 High, 55 Medium, 2 Low, 0 Unrated.

CVE-2025-26592

Published Jun 9, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Lab lab allows PHP Local File Inclusion.This i…

CVSS 8.1 · High

CVE-2025-24770

Published Jun 9, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme CraftXtore bw-craftxtore allows PHP Local File In…

CVSS 8.1 · High

CVE-2025-24768

Published Jun 9, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Nitan snsnitan allows PHP Local File Inclusion.Th…

CVSS 8.1 · High

CVE-2023-26005

Published Jun 9, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme Fitrush allows PHP Local File Inclusion. This iss…

CVSS 8.1 · High

CVE-2023-25999

Published Jun 9, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme BodyCenter - Gym, Fitness WooCommerce WordPress T…

CVSS 8.1 · High

CVE-2025-49313

Published Jun 6, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme BRW ova-brw allows PHP Local File Inclusion.This…

CVSS 7.5 · High

CVE-2025-49308

Published Jun 6, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows…

CVSS 7.5 · High

CVE-2025-49307

Published Jun 6, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magazine3 WP Multilang wp-multilang allows PHP Local File…

CVSS 7.5 · High

CVE-2025-30999

Published Jun 6, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fahad Mahmood External Store for Shopify wp-shopify allows…

CVSS 7.5 · High

CVE-2023-25995

Published Jun 6, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in choicehomemortgage AI Mortgage Calculator allows PHP Local…

CVSS 7.5 · High

CVE-2025-47586

Published Jun 6, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors - Events stm-motors-events allows PH…

CVSS 9.0 · Critical

CVE-2025-48292

Published May 23, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GoodLayers Tourmaster tourmaster allows PHP Local File Inc…

CVSS 8.1 · High

CVE-2025-47672

Published May 23, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange miniOrange Discord Integration miniorange-disco…

CVSS 8.1 · High

CVE-2025-47670

Published May 23, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-…

CVSS 8.1 · High

CVE-2025-47453

Published May 23, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Xylus Themes WP Smart Import wp-smart-import allows PHP Lo…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-47438

Published May 23, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local F…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46474

Published May 23, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SEUR OFICIAL SEUR Oficial seur allows PHP Local File Inclu…

CVSS 8.1 · High

CVE-2025-46468

Published May 23, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPFable Fable Extra fable-extra allows PHP Local File Incl…

CVSS 9.8 · Critical

CVE-2025-46454

Published May 23, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in svil4ok Meta Keywords & Description wp-meta-keywords-meta-…

CVSS 7.5 · High

CVE-2025-46444

Published May 23, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in scripteo Ads Pro ap-plugin-scripteo allows PHP Local File…

CVSS 8.1 · High

CVE-2025-39506

Published May 23, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Nasa Core nasa-core allows PHP Local File Inclus…

CVSS 8.1 · High

CVE-2025-39494

Published May 23, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wilmër wilmer allows PHP Local File Inclusio…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-39490

Published May 23, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows PH…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32309

Published May 23, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Healsoul healsoul allows PHP Local File Inclusio…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 951-975 of 1,269 CVEsPage 39 of 51