Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
Unclassified CRITICAL 9.8
CVE-2025-11023

Inclusion of Functionality from Untrusted Control Sphere, Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File…

Mitigation only
Fix from $2,300 2025-10-23
Unclassified HIGH 8.1
CVE-2025-62029

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themesion Grevo grevo.This i…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 7.5
CVE-2025-62054

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez Theme - Fu…

Mitigation only
Fix from $1,950 2025-10-22
Billey HIGH 8.1
CVE-2025-59558

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allo…

Fix: 2.1.6+
Fix from $1,950 2025-10-22
Edumall HIGH 8.1
CVE-2025-59564

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall al…

Fix: 4.4.5+
Fix from $1,950 2025-10-22
Businext HIGH 8.1
CVE-2025-58967

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Businext businext …

Fix: 2.4.4+
Fix from $1,950 2025-10-22
Unclassified HIGH 8.1
CVE-2025-59550

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Xcare xcare all…

Mitigation only
Fix from $1,950 2025-10-22
Medizin HIGH 8.1
CVE-2025-59555

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Medizin medizin al…

Fix: 1.9.7+
Fix from $1,950 2025-10-22
Unclassified HIGH 8.1
CVE-2025-58955

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Karzo karzo all…

Mitigation only
Fix from $1,950 2025-10-22
Smilepure HIGH 8.1
CVE-2025-58958

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove SmilePure smilepur…

Fix: 1.8.5+
Fix from $1,950 2025-10-22
Unclassified HIGH 7.5
CVE-2025-49935

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in xtemos WoodMart woodmart all…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 7.5
CVE-2025-49921

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetReviews jet-re…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 7.5
CVE-2025-48338

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kevon Adonis WP Abstracts wp…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 7.5
CVE-2025-32657

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slid…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 7.5
CVE-2025-11722

The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including…

Mitigation only
Fix from $1,950 2025-10-15
Unclassified CRITICAL 9.8
CVE-2025-7634

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,…

Mitigation only
Fix from $2,300 2025-10-09
Unclassified CRITICAL 9.8
CVE-2025-7721

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, …

Mitigation only
Fix from $2,300 2025-10-03
Unclassified HIGH 8.1
CVE-2025-9991

The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.3.34 via the 'la…

Mitigation only
Fix from $1,950 2025-09-30
Unclassified HIGH 8.1
CVE-2025-9993

The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the …

Mitigation only
Fix from $1,950 2025-09-30
Unclassified HIGH 7.5
CVE-2025-60150

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpshuffle Subscribe to Downl…

Mitigation only
Fix from $1,950 2025-09-26
Unclassified HIGH 7.5
CVE-2025-60153

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpshuffle Subscribe To Unloc…

Mitigation only
Fix from $1,950 2025-09-26
Unclassified HIGH 8.8
CVE-2025-60126

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginOps Testimonial Slider…

Mitigation only
Fix from $1,950 2025-09-26
Unclassified HIGH 7.5
CVE-2025-59588

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad …

Mitigation only
Fix from $1,950 2025-09-22
Unclassified HIGH 7.5
CVE-2025-58973

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hashthemes Easy Elementor Ad…

Mitigation only
Fix from $1,950 2025-09-22
Unclassified HIGH 7.5
CVE-2025-57925

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in immonex immonex Kickstart Te…

Mitigation only
Fix from $1,950 2025-09-22
Unclassified HIGH 7.5
CVE-2025-53450

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Pluginwale Easy Pricing Tabl…

Mitigation only
Fix from $1,950 2025-09-22
Unclassified HIGH 7.5
CVE-2025-10143

The Catch Dark Mode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0 via the 'catch_dark_mode' sh…

Mitigation only
Fix from $1,950 2025-09-17
Unclassified HIGH 7.5
CVE-2025-10269

The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.13. This makes it possible …

Mitigation only
Fix from $1,950 2025-09-12
Unclassified HIGH 7.5
CVE-2025-9874

The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6 via the 'uclwp_…

Mitigation only
Fix from $1,950 2025-09-11
Unclassified HIGH 8.1
CVE-2025-58215

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Ziston ziston allows …

Mitigation only
Fix from $1,950 2025-09-09