Skip to main content

Daily materialized evidence profile

CWE CWE-98

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
1,272
CVEs with mentions
889
Total mentions
1,099
CVEs with KEV
1
CVEs with PoC
2

Attack vector counts

Network
1,254
Adjacent network
1
Local
17
Physical
0

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2025-68645

Published Dec 22, 2025

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request param…

CVSS 8.8 · High
evidence mentions
3
Buzz score
45.4
KEV listed

CVE-2026-17605

Published Aug 1, 2026

The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the…

CVSS 6.6 · Medium
evidence mentions
11
Buzz score
41.4

CVE-2026-13080

Published Jul 9, 2026

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.…

CVSS 6.6 · Medium
evidence mentions
11
Buzz score
36.4

CVE-2025-0366

Published Feb 1, 2025

The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 via the get_svg() function. This…

CVSS 8.8 · High
evidence mentions
5
Buzz score
34.4

CVE-2026-15338

Published Jul 11, 2026

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function.…

CVSS 7.5 · High
evidence mentions
8
Buzz score
33.5