Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
Chartify CRITICAL 9.8
CVE-2024-10571

The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the …

Fix: 2.9.6+
Fix from $2,300 2024-11-14
Unclassified CRITICAL 9.8
CVE-2024-10871

The Category Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.2 via the 'params[caf-p…

Mitigation only
Fix from $2,300 2024-11-09
Unclassified HIGH 8.8
CVE-2024-10436

The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.1 via the…

Mitigation only
Fix from $1,950 2024-10-29
Clean Retina HIGH 8.8
CVE-2024-50436

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehorse Clean Retina clea…

Fix: 3.0.7+
Fix from $1,950 2024-10-28
Qode Essential Addons HIGH 8.8
CVE-2024-50457

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qode Essential Addons q…

Fix: 1.6.4+
Fix from $1,950 2024-10-28
Newscard HIGH 8.8
CVE-2024-50434

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehorse NewsCard newscard…

Fix: 1.4+
Fix from $1,950 2024-10-28
Meta News HIGH 8.8
CVE-2024-50435

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehorse Meta News meta-ne…

Fix: 1.1.8+
Fix from $1,950 2024-10-28
Advanced Online Ordering And Delivery Platform CRITICAL 9.8
CVE-2024-50497

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wdesco Advanced Online Order…

Fix: after 2.0.0
Fix from $2,300 2024-10-28
Unclassified HIGH 7.2
CVE-2024-8392

The WordPress Post Grid Layouts with Pagination – Sogrid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ…

Mitigation only
Fix from $1,950 2024-10-26
Mags HIGH 8.8
CVE-2024-49701

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehorse Mags mags.This is…

Fix: 1.1.7+
Fix from $1,950 2024-10-23
Qi Blocks HIGH 8.8
CVE-2024-49690

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qi Blocks qi-blocks.Thi…

Fix: 1.3.3+
Fix from $1,950 2024-10-23
Dynamic Elementor Addons HIGH 8.8
CVE-2024-49243

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ramjon27 Dynamic Elementor A…

Fix: after 1.0.0
Fix from $1,950 2024-10-18
Unclassified HIGH 7.5
CVE-2024-49317

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ZIPANG Point Maker point-mak…

Mitigation only
Fix from $1,950 2024-10-17
Unclassified HIGH 7.5
CVE-2024-49251

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Acnoo Maan Addons For Elemen…

Mitigation only
Fix from $1,950 2024-10-16
Unclassified HIGH 7.5
CVE-2024-48029

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hung Trang Si SB Random Post…

Mitigation only
Fix from $1,950 2024-10-16
Ee Class HIGH 8.8
CVE-2024-9981

The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regular privileges to upload a mal…

Fix: 2024-03-26+
Fix from $1,950 2024-10-15
Unclassified HIGH 8.1
CVE-2024-47323

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ex-Themes WP Timeline – Vert…

Mitigation only
Fix from $1,950 2024-10-05
Unclassified HIGH 8.1
CVE-2024-44023

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in abcapp ABCApp Creator abcapp…

Mitigation only
Fix from $1,950 2024-10-05
Unclassified CRITICAL 9.8
CVE-2024-41925

The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly validate user input, allowing an attacker to travers…

Mitigation only
Fix from $2,300 2024-10-03
Unclassified MEDIUM 6.5
CVE-2024-44048

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Product Carousel Slide…

Mitigation only
Fix from $1,600 2024-09-23
Clean Login HIGH 8.8
CVE-2024-8252

The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute …

Fix: 1.14.6+
Fix from $1,950 2024-08-30
Zen Cart HIGH 8.1
CVE-2024-5762EPSS 72%

Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Mitigation only
Fix from $1,950 2024-08-21
Unclassified CRITICAL 9.6
CVE-2024-43261

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hamed Naderfar Compute Links…

Mitigation only
Fix from $2,300 2024-08-19
Element Pack MEDIUM 6.5
CVE-2024-4359

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to arb…

Fix: 5.7.3+
Fix from $1,600 2024-08-12
Learnpress HIGH 8.8
CVE-2024-6589

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.6.8.2 via …

Fix: after 4.2.6.8.2
Fix from $1,950 2024-07-25
Bamboo HIGH 8.1
CVE-2024-21687

This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center a…

Fix: 9.2.16 / 9.6.4+
Fix from $1,950 2024-07-16
Unclassified HIGH 7.5
CVE-2024-38735

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Bastien Ho Event post event-…

Mitigation only
Fix from $1,950 2024-07-12
Shopbuilder HIGH 8.8
CVE-2024-37520

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme ShopBuilder – El…

Fix: 2.1.13+
Fix from $1,950 2024-07-09
Powerpack For Beaver Builder HIGH 7.2
CVE-2024-37410

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in IdeaBox Creations PowerPack …

Fix: 1.3.0.4+
Fix from $1,950 2024-07-09
Element Kit For Elementor HIGH 8.8
CVE-2024-37479

Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widget in New Post, specifically i…

Fix: 1.3.9+
Fix from $1,950 2024-07-02