Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
Unclassified HIGH 8.1
CVE-2025-67981

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 8.1
CVE-2025-67982

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna urna allows PHP…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 8.1
CVE-2025-67988

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean CozyStay cozystay …

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 8.1
CVE-2025-60087

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nenad Obradovic Extensive VC…

Mitigation only
Fix from $1,950 2026-02-20
Unclassified HIGH 7.5
CVE-2026-27343

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VanKarWai Airtifact airtifac…

Mitigation only
Fix from $1,950 2026-02-19
Unclassified HIGH 7.5
CVE-2026-27052

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in villatheme Sales Countdown T…

Mitigation only
Fix from $1,950 2026-02-19
Unclassified HIGH 7.5
CVE-2026-25326

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Conten…

Mitigation only
Fix from $1,950 2026-02-19
Unclassified CRITICAL 9.8
CVE-2026-0926EPSS 9%

The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'parameters[templ…

Mitigation only
Fix from $2,300 2026-02-19
Invoiceplane CRITICAL 9.1
CVE-2026-25548

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerabil…

Fix: 1.7.1+
Fix from $2,300 2026-02-18
Unclassified HIGH 7.5
CVE-2026-1988

The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.…

Mitigation only
Fix from $1,950 2026-02-14
Unclassified HIGH 8.8
CVE-2025-15368

The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name…

Mitigation only
Fix from $1,950 2026-02-04
Unclassified HIGH 7.5
CVE-2026-25027

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp al…

Mitigation only
Fix from $1,950 2026-02-03
Unclassified HIGH 7.5
CVE-2024-54263

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Talemy Spirit Framework allo…

Mitigation only
Fix from $1,950 2026-02-02
Unclassified CRITICAL 9.8
CVE-2021-47900

Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system comm…

Mitigation only
Fix from $2,300 2026-01-27
Unclassified HIGH 7.5
CVE-2026-1257

The Administrative Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.3.4 via the 'slug' a…

Mitigation only
Fix from $1,950 2026-01-24
Unclassified HIGH 7.5
CVE-2026-24635

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DevsBlink EduBlink Core edub…

Mitigation only
Fix from $1,950 2026-01-23
Unclassified HIGH 7.5
CVE-2026-24608

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent Core l…

Mitigation only
Fix from $1,950 2026-01-23
Unclassified HIGH 7.5
CVE-2026-24609

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent lauren…

Mitigation only
Fix from $1,950 2026-01-23
Unclassified HIGH 7.5
CVE-2026-24531

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Prowess prowes…

Mitigation only
Fix from $1,950 2026-01-23
Unclassified HIGH 7.5
CVE-2026-24538

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in omnipressteam Omnipress omni…

Mitigation only
Fix from $1,950 2026-01-23
Unclassified HIGH 7.5
CVE-2026-24390

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QantumThemes Kentha Elemento…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 7.5
CVE-2026-23975

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo golo allows PHP L…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 7.5
CVE-2026-23978

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Softwebmedia Gyan Elements g…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 7.5
CVE-2026-22464

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wphocus My auctions allegro …

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 7.5
CVE-2026-22401

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pavothemes Freshio freshio a…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 7.5
CVE-2026-22402

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pavothemes Triply triply all…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.1
CVE-2025-69314

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes Werkstatt werksta…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.1
CVE-2025-69078

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Malta malta all…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.1
CVE-2025-69100

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North north-wp al…

Mitigation only
Fix from $1,950 2026-01-22
Unclassified HIGH 8.1
CVE-2025-69071

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes TanTum tantum a…

Mitigation only
Fix from $1,950 2026-01-22