Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
Unclassified HIGH 7.5
CVE-2025-3703

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wipeoutmedia CSS & JavaScrip…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified HIGH 7.5
CVE-2025-32288

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensi…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified HIGH 8.1
CVE-2025-30635

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeAtelier IDonatePro idon…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified CRITICAL 10.0
CVE-2025-25174

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 BeeTeam368 Extens…

Mitigation only
Fix from $2,300 2025-08-14
Wp Pipes CRITICAL 9.8
CVE-2025-28979

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress WP Pipes allows PH…

Fix: after 1.4.3
Fix from $2,300 2025-08-14
Unclassified HIGH 8.1
CVE-2025-25172

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 VidMov vidmov all…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified HIGH 7.5
CVE-2025-24766

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wproyal News Magazine X news…

Mitigation only
Fix from $1,950 2025-08-14
Organization Portal System CRITICAL 9.8
CVE-2025-8913

Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arb…

Mitigation only
Fix from $2,300 2025-08-13
Vedo Suite MEDIUM 6.5
CVE-2025-51057

A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by …

No fix yet
Fix from $1,600 2025-08-06
Unclassified CRITICAL 10.0
CVE-2012-10025

The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export…

Mitigation only
Fix from $2,300 2025-08-05
Unclassified HIGH 7.5
CVE-2025-6991

The kallyas theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.21.0 via the 'TH_LatestPosts4` widget. …

Mitigation only
Fix from $1,950 2025-07-26
Librenms HIGH 7.5
CVE-2025-54138

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating sys…

Fix: 25.7.0+
Fix from $1,950 2025-07-22
Wavesuite Noc CRITICAL 9.0
CVE-2025-24937

File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full …

Mitigation only
Fix from $2,300 2025-07-21
Subscribe To Comments HIGH 7.2
CVE-2015-10133

The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the Path to header value. T…

Fix: after 2.1.2
Fix from $1,950 2025-07-19
Unclassified MEDIUM 6.6
CVE-2025-54015

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins HT Contact Form 7…

Mitigation only
Fix from $1,600 2025-07-16
Woodmart HIGH 8.8
CVE-2025-6746

The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This …

Fix: 8.2.4+
Fix from $1,950 2025-07-08
Widget For Google Reviews HIGH 8.8
CVE-2025-7327

The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.15 via the layout p…

Fix: 1.0.16+
Fix from $1,950 2025-07-08
Unclassified HIGH 8.1
CVE-2025-52807

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Kossy - Minimalist eC…

Mitigation only
Fix from $1,950 2025-07-04
Unclassified HIGH 8.1
CVE-2025-4414

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Conten…

Mitigation only
Fix from $1,950 2025-07-04
Unclassified HIGH 7.5
CVE-2025-49070

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Elessi elessi-them…

Mitigation only
Fix from $1,950 2025-07-04
Unclassified HIGH 7.5
CVE-2025-47627

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LCweb PrivateContent - Mail …

Mitigation only
Fix from $1,950 2025-07-04
Ads Pro CRITICAL 9.8
CVE-2025-4689

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion which leads to Remote Cod…

Fix: after 4.89
Fix from $2,300 2025-07-02
Ads Pro CRITICAL 9.8
CVE-2025-4380EPSS 40%

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an…

Fix: after 4.89
Fix from $2,300 2025-07-02
Unclassified HIGH 7.5
CVE-2025-53339

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in devnex Devnex Addons For Ele…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.5
CVE-2025-53281

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPBean WPB Category Slider f…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.5
CVE-2025-53257

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Serhii Pasyuk Gmedia Photo G…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.5
CVE-2025-53259

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking nd-boo…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 8.1
CVE-2025-52812

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Domnoo domnoo allows …

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 8.1
CVE-2025-52814

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme BRW ova-brw allows …

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 8.1
CVE-2025-52815

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CityGov citygov…

Mitigation only
Fix from $1,950 2025-06-27