Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
Rezgo Online Booking HIGH 8.1
CVE-2024-53800

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in rezgo Rezgo rezgo allows PHP…

Fix: 4.17.1+
Fix from $1,950 2025-01-07
Unclassified HIGH 7.5
CVE-2025-22364

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Service Shogun Ach Invoice A…

Mitigation only
Fix from $1,950 2025-01-07
Unclassified MEDIUM 6.5
CVE-2025-22305

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Essential Plugin Hero Banner…

Mitigation only
Fix from $1,600 2025-01-07
Unclassified HIGH 7.5
CVE-2024-56281

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in codemstory 워드프레스 결제 …

Mitigation only
Fix from $1,950 2025-01-07
Unclassified HIGH 7.5
CVE-2024-56282

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elicus WPMozo Addons Lite fo…

Mitigation only
Fix from $1,950 2025-01-07
Build App Online CRITICAL 9.8
CVE-2024-49649

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hakeemnala Build App Online …

Fix: after 1.0.23
Fix from $2,300 2025-01-07
Builder MEDIUM 6.5
CVE-2024-56216

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Builder th…

Fix: after 7.6.3
Fix from $1,600 2024-12-31
Unclassified HIGH 7.5
CVE-2024-56230

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Maidul Dynamic Product Categ…

Mitigation only
Fix from $1,950 2024-12-31
Unclassified HIGH 8.8
CVE-2024-12272

The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for WordPress is vulnerable to Local Fi…

Mitigation only
Fix from $1,950 2024-12-25
Unclassified CRITICAL 9.8
CVE-2024-12571

The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in version 3.98.9 via the…

Mitigation only
Fix from $2,300 2024-12-20
Unclassified HIGH 8.1
CVE-2024-54270

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axeptio Axeptio axeptio-sdk-…

Mitigation only
Fix from $1,950 2024-12-18
Unclassified HIGH 7.5
CVE-2024-54376

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Spider Themes EazyDocs eazyd…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 8.8
CVE-2024-12040

The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc…

Mitigation only
Fix from $1,950 2024-12-12
Unclassified HIGH 7.5
CVE-2024-54225

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in codegearthemes Designer desi…

Mitigation only
Fix from $1,950 2024-12-09
Unclassified CRITICAL 9.8
CVE-2024-12209EPSS 23%

The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Mitigation only
Fix from $2,300 2024-12-08
Unclassified HIGH 7.5
CVE-2024-53824

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in all_bootstrap_blocks All Boo…

Mitigation only
Fix from $1,950 2024-12-06
Unclassified HIGH 8.1
CVE-2024-11289

The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via several functions like penci_ar…

Mitigation only
Fix from $1,950 2024-12-06
Aspect Ent 12 Firmware HIGH 7.5
CVE-2024-51541

Local File Inclusion vulnerabilities allow access to sensitive system information.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Ser…

Fix: 3.08.03+
Fix from $1,950 2024-12-05
Unclassified HIGH 8.8
CVE-2024-11429

The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress is vulnerable to Local File In…

Mitigation only
Fix from $1,950 2024-12-05
Cryptocurrency Widgets For Elementor CRITICAL 9.8
CVE-2024-53739

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cool Plugins Cryptocurrency …

Fix: 1.6.5+
Fix from $2,300 2024-11-30
Unclassified HIGH 7.5
CVE-2024-52501

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebbyTemplate Office Locator…

Mitigation only
Fix from $1,950 2024-11-28
Unclassified HIGH 7.5
CVE-2024-52497

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in quomodosoft Shopready shopre…

Mitigation only
Fix from $1,950 2024-11-28
Unclassified HIGH 7.5
CVE-2024-52499

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ibrahim Pricing table addon …

Mitigation only
Fix from $1,950 2024-11-28
Unclassified HIGH 7.5
CVE-2024-52496

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AbsolutePlugins Absolute Add…

Mitigation only
Fix from $1,950 2024-11-28
Element Kit For Elementor HIGH 8.8
CVE-2024-10873

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via th…

Fix: 1.4.3+
Fix from $1,950 2024-11-23
Contact Form 7 Email Add On HIGH 8.8
CVE-2024-10898

The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the cf7_emai…

Fix: after 1.9
Fix from $1,950 2024-11-21
Unclassified HIGH 7.5
CVE-2024-52450

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in officialprocoders nBlocks nb…

Mitigation only
Fix from $1,950 2024-11-20
Ads Booster By Ads Pro CRITICAL 9.8
CVE-2024-52428

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Peter Ads Booster by Ads Pro…

Fix: after 1.12
Fix from $2,300 2024-11-18
Unclassified MEDIUM 5.3
CVE-2024-52386

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Classified Listi…

Mitigation only
Fix from $1,600 2024-11-16
Unclassified HIGH 8.1
CVE-2024-52381

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Shoaib Rehmat ZIJ KART zij-k…

Mitigation only
Fix from $1,950 2024-11-14