Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
Unclassified HIGH 7.5
CVE-2025-26890

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 HUSKY woocommerce…

Mitigation only
Fix from $1,950 2025-03-27
Hide My Wp Ghost CRITICAL 9.8
CVE-2025-26909

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost…

Fix: 5.4.02+
Fix from $2,300 2025-03-27
Unclassified HIGH 8.8
CVE-2025-30891

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpTravelly to…

Mitigation only
Fix from $1,950 2025-03-27
Unclassified HIGH 7.5
CVE-2025-30890

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SuitePlugins Login Widget fo…

Mitigation only
Fix from $1,950 2025-03-27
Unclassified HIGH 7.5
CVE-2025-30868

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Maidul Team Manager wp-team-…

Mitigation only
Fix from $1,950 2025-03-27
Wp Travel Engine HIGH 7.5
CVE-2025-30871

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel E…

Fix: 6.3.6+
Fix from $1,950 2025-03-27
Unclassified HIGH 7.5
CVE-2025-30845

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in webangon The Pack Elementor …

Mitigation only
Fix from $1,950 2025-03-27
Unclassified HIGH 8.8
CVE-2025-30846

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jetmonsters Restaurant Menu …

Mitigation only
Fix from $1,950 2025-03-27
Unclassified HIGH 7.5
CVE-2025-30829

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics WPCafe wp-cafe all…

Mitigation only
Fix from $1,950 2025-03-27
Unclassified HIGH 7.5
CVE-2025-30831

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Event Post…

Mitigation only
Fix from $1,950 2025-03-27
Unclassified HIGH 7.5
CVE-2025-30820

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins WishSuite wishsui…

Mitigation only
Fix from $1,950 2025-03-27
Unclassified HIGH 7.5
CVE-2025-30814

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme The Post Grid th…

Mitigation only
Fix from $1,950 2025-03-27
Unclassified HIGH 7.5
CVE-2025-30785

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Down…

Mitigation only
Fix from $1,950 2025-03-27
Unclassified CRITICAL 9.8
CVE-2025-28916

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rashid Docpro docpro allows …

Mitigation only
Fix from $2,300 2025-03-26
Unclassified HIGH 8.1
CVE-2025-26986

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Pearl - Corpo…

Mitigation only
Fix from $1,950 2025-03-26
Unclassified HIGH 7.5
CVE-2025-27015

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designingmedia Hostiko hosti…

Mitigation only
Fix from $1,950 2025-03-26
Unclassified HIGH 8.1
CVE-2025-24690

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality for…

Mitigation only
Fix from $1,950 2025-03-26
Unclassified HIGH 8.1
CVE-2025-23937

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alex Furr LinkedIn Lite link…

Mitigation only
Fix from $1,950 2025-03-26
Unclassified HIGH 8.1
CVE-2025-23952

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ntm custom-field-list-widget…

Mitigation only
Fix from $1,950 2025-03-26
Unclassified CRITICAL 9.8
CVE-2024-13790

The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and in…

Mitigation only
Fix from $2,300 2025-03-19
Unclassified HIGH 8.8
CVE-2024-12563

The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214 via the 'template' attribute…

Mitigation only
Fix from $1,950 2025-03-18
Risk Value HIGH 7.5
CVE-2025-26137

Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to…

Fix: after 2.8.0
Fix from $1,950 2025-03-18
Traveler CRITICAL 9.8
CVE-2025-1771

The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_load_more_pos…

Fix: 3.1.9+
Fix from $2,300 2025-03-15
Unclassified HIGH 8.8
CVE-2025-1707

The Review Schema plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.4 via post meta. This makes it…

Mitigation only
Fix from $1,950 2025-03-11
Ad Hoc Infinity HIGH 7.3
CVE-2024-51319

A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Ex…

No fix yet
Fix from $1,950 2025-03-11
Unclassified CRITICAL 9.0
CVE-2025-26916

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Pixflow Massive Dynamic mass…

Mitigation only
Fix from $2,300 2025-03-10
Unclassified HIGH 7.5
CVE-2025-26933

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nitin Prakash WC Place Order…

Mitigation only
Fix from $1,950 2025-03-10
Tikit Emarketing MEDIUM 5.1
CVE-2023-49031

Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a remote attacker to read arbitra…

No fix yet
Fix from $1,600 2025-03-03
Unclassified HIGH 7.5
CVE-2025-27264

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creativeitem Doctor Appointm…

Mitigation only
Fix from $1,950 2025-03-03
Unclassified HIGH 8.1
CVE-2025-25109

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky WP Vehicle Manager j…

Mitigation only
Fix from $1,950 2025-03-03