Vulnerability index

Browse CVEs

1,269 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
Unclassified HIGH 7.5
CVE-2026-57789

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows P…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 8.1
CVE-2026-57743

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensi…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 7.5
CVE-2026-15338

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via th…

No fix yet
Fix from $1,950 2026-07-11
Unclassified MEDIUM 6.6
CVE-2025-11977

The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.6
CVE-2026-13080

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all ver…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 7.5
CVE-2026-57748

Contributor Local File Inclusion in Shopify <= 1.0.0 versions.

No fix yet
Fix from $1,950 2026-07-02
Unclassified HIGH 7.5
CVE-2026-57749

Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 8.1
CVE-2026-42382

Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 8.1
CVE-2026-27412

Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.5
CVE-2025-69133

Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 8.1
CVE-2025-58902

Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.5
CVE-2026-12923

The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3. This is due to insufficient…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 7.5
CVE-2026-57647

Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2025-68063

Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2025-68064

Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.1
CVE-2026-54845

Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified MEDIUM 6.2
CVE-2019-25760

Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supp…

No fix yet
Fix from $1,600 2026-06-19
Unclassified CRITICAL 9.8
CVE-2026-7515

The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. …

Mitigation only
Fix from $2,300 2026-06-19
Unclassified MEDIUM 6.3
CVE-2026-48820

CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and…

Mitigation only
Fix from $1,600 2026-06-17
Unclassified HIGH 8.1
CVE-2026-54814

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows…

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-39559

Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-39590

Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2026-39523

Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2025-69166

Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2025-69170

Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2025-69174

Unauthenticated Local File Inclusion in Etude <= 1.6 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2025-69175

Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2025-69144

Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2025-69157

Unauthenticated Local File Inclusion in Gamic <= 1.15 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2025-69158

Unauthenticated Local File Inclusion in Granola <= 1.13 versions.

Mitigation only
Fix from $1,950 2026-06-17