Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
Unclassified HIGH 7.5
CVE-2025-23945

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Webliup Popliup popliup allo…

Mitigation only
Fix from $1,950 2025-03-03
Whmcs CRITICAL 9.8
CVE-2024-9193

The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.…

Fix: 6.3+
Fix from $2,300 2025-02-28
Unclassified HIGH 8.8
CVE-2024-12811

The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.9 via shortcodes. This makes it poss…

Mitigation only
Fix from $1,950 2025-02-28
Unclassified HIGH 8.1
CVE-2025-26985

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Su…

Mitigation only
Fix from $1,950 2025-02-25
Unclassified HIGH 7.5
CVE-2025-26979

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Aman Funnel Builder by Funne…

Mitigation only
Fix from $1,950 2025-02-25
Unclassified HIGH 7.5
CVE-2025-26957

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Deetronix Affiliate Coupons …

Mitigation only
Fix from $1,950 2025-02-25
Eventin HIGH 8.8
CVE-2025-26964

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics Eventin wp-event-s…

Fix: 4.0.21+
Fix from $1,950 2025-02-25
Unclassified HIGH 7.5
CVE-2025-26932

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QuantumCloud ChatBot chatbot…

Mitigation only
Fix from $1,950 2025-02-25
Unclassified HIGH 7.5
CVE-2025-27272

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in vinagecko VG PostCarousel vg…

Mitigation only
Fix from $1,950 2025-02-24
Unclassified HIGH 7.5
CVE-2025-26757

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FULL SERVICES FULL Customer …

Mitigation only
Fix from $1,950 2025-02-22
Unclassified HIGH 7.5
CVE-2025-26760

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Calculator Build…

Mitigation only
Fix from $1,950 2025-02-22
Responsive Addons For Elementor HIGH 8.8
CVE-2024-13353

The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Local File Inclusion…

Fix: 1.6.5+
Fix from $1,950 2025-02-21
Team Builder For Wpbakery Page Builder HIGH 8.8
CVE-2024-13592

The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to…

Mitigation only
Fix from $1,950 2025-02-19
Unclassified HIGH 8.1
CVE-2025-22656

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Oscar Alvarez Cookie Monster…

Mitigation only
Fix from $1,950 2025-02-18
Unclassified HIGH 7.5
CVE-2025-25141

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in zankover Fami Sales Popup fa…

Mitigation only
Fix from $1,950 2025-02-07
Unclassified HIGH 8.8
CVE-2024-12859

The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8.0 via the 'boombox_…

Mitigation only
Fix from $1,950 2025-02-03
Jupiter X Core HIGH 8.8
CVE-2025-0366

The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 vi…

Fix: 4.8.8+
Fix from $1,950 2025-02-01
Post Grid\, Slider \& Carousel Ultimate HIGH 8.8
CVE-2025-24782

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Post Grid, Slider & Ca…

Fix: 1.7+
Fix from $1,950 2025-01-27
Addons HIGH 8.8
CVE-2025-0682

The ThemeREX Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.0 via the 'trx_sc_reviews' …

Fix: 2.34.0+
Fix from $1,950 2025-01-25
Post Grid Master MEDIUM 6.5
CVE-2025-24733

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Akhtarujjaman Shuvo Post Gri…

Fix: 3.4.13+
Fix from $1,600 2025-01-24
Maximo Asset Management MEDIUM 6.5
CVE-2024-45077

IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated low privileged user to upload…

Mitigation only
Fix from $1,600 2025-01-24
Post Grid HIGH 8.8
CVE-2024-13408

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclu…

Fix: 1.7+
Fix from $1,950 2025-01-24
Meeting Map HIGH 8.8
CVE-2024-13593

The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.0 via the 'bmlt_meeting_map…

Fix: 2.6.1+
Fix from $1,950 2025-01-23
Unclassified HIGH 8.1
CVE-2025-23948

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Webarea Background animation…

Mitigation only
Fix from $1,950 2025-01-22
Unclassified HIGH 8.1
CVE-2025-23949

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dzeriho Improved Sale Badges…

Mitigation only
Fix from $1,950 2025-01-22
Unclassified HIGH 7.5
CVE-2025-23938

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CRUDLab Image Gallery Box by…

Mitigation only
Fix from $1,950 2025-01-22
Unclassified HIGH 7.5
CVE-2025-22311

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DeluxeThemes Private Message…

Mitigation only
Fix from $1,950 2025-01-21
Unclassified HIGH 7.5
CVE-2025-23915

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in roninwp FAT Event Lite fat-e…

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 8.1
CVE-2025-22508

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in roninwp FAT Event Lite fat-e…

Mitigation only
Fix from $1,950 2025-01-09
Unclassified MEDIUM 6.3
CVE-2025-22145

Carbon is an international PHP extension for DateTime. Application passing unsanitized user input to Carbon::setLocale are at risk of arbitrary file …

Patch available
Fix from $1,600 2025-01-08