Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
Wpcafe HIGH 8.8
CVE-2024-5431

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclu…

Fix: 2.2.26+
Fix from $1,950 2024-06-25
The Plus Addons For Elementor HIGH 8.8
CVE-2024-5455

The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.5.4 via…

Fix: 5.6.0+
Fix from $1,950 2024-06-21
Wp Blog Post Layouts HIGH 8.8
CVE-2024-5503

The WP Blog Post Layouts plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.3. This makes it possib…

Fix: after 1.1.3
Fix from $1,950 2024-06-21
Unclassified HIGH 7.5
CVE-2024-5574

The WP Magazine Modules Lite plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.2 via the 'blockLay…

Mitigation only
Fix from $1,950 2024-06-19
Video Gallery CRITICAL 9.8
CVE-2024-4258

The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and…

Fix: 1.3.14+
Fix from $2,300 2024-06-15
Video Gallery HIGH 8.8
CVE-2024-4551

The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and…

Fix: 1.3.14+
Fix from $1,950 2024-06-15
Tagdiv Composer HIGH 8.8
CVE-2024-3813

The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' sho…

Fix: 4.9+
Fix from $1,950 2024-06-15
Unclassified CRITICAL 9.8
CVE-2024-5577

The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the WIW_HEADER parameter of the …

Mitigation only
Fix from $2,300 2024-06-14
Canto CRITICAL 9.8
CVE-2024-4936

The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This mak…

Fix: 3.0.9+
Fix from $2,300 2024-06-14
Suitecrm HIGH 8.8
CVE-2024-36415

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in upload…

Fix: 7.14.4 / 8.6.1+
Fix from $1,950 2024-06-10
Melapress Login Security HIGH 7.2
CVE-2024-35650

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Melapress MelaPress Login Se…

Fix: 1.3.1+
Fix from $1,950 2024-06-10
Qi Addons For Elementor HIGH 7.5
CVE-2024-4887

The Qi Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.2 via the 'behavior'…

Fix: 1.7.3+
Fix from $1,950 2024-06-07
Easy Digital Downloads CRITICAL 9.8
CVE-2024-35629

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Easy Digital Dow…

Fix: after 1.0.2
Fix from $2,300 2024-06-04
Gas Agency Management System HIGH 8.1
CVE-2024-36569

Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php.

No fix yet
Fix from $1,950 2024-06-03
Unclassified HIGH 8.8
CVE-2024-5348

The Elements For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.1 via the 'beforeafter_…

Mitigation only
Fix from $1,950 2024-06-01
Content Blocks HIGH 8.8
CVE-2024-3564

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via th…

Fix: 3.3.1+
Fix from $1,950 2024-06-01
Unclassified HIGH 8.8
CVE-2024-5345

The Responsive Owl Carousel for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.0 via …

Mitigation only
Fix from $1,950 2024-05-31
Unclassified HIGH 7.5
CVE-2024-3812

The Salient Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.7 via the 'nectar_icon' shortco…

Mitigation only
Fix from $1,950 2024-05-18
Unclassified HIGH 8.8
CVE-2024-3810

The Salient Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.5.3 via the 'icon' shortcod…

Mitigation only
Fix from $1,950 2024-05-18
Unclassified HIGH 8.1
CVE-2024-32523

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in EverPress Mailster mailster.…

Mitigation only
Fix from $1,950 2024-05-17
Unclassified HIGH 8.3
CVE-2024-27971

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Permalin…

Mitigation only
Fix from $1,950 2024-05-17
Unclassified CRITICAL 9.8
CVE-2024-3551

The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.0 via the 'data'…

Mitigation only
Fix from $2,300 2024-05-17
Unclassified HIGH 8.8
CVE-2024-4670

The All-in-One Video Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.5 via the aiovg_sea…

Mitigation only
Fix from $1,950 2024-05-15
Linqi CRITICAL 9.8
CVE-2024-33863

An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion.

Fix: 1.4.0.1+
Fix from $2,300 2024-05-14
Unclassified HIGH 8.1
CVE-2024-4441

The XML Sitemap & Google News plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.8 via the 'feed' p…

Mitigation only
Fix from $1,950 2024-05-14
Unclassified HIGH 8.8
CVE-2024-3809

The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.9 via the 'slide…

Mitigation only
Fix from $1,950 2024-05-14
Unclassified CRITICAL 9.8
CVE-2024-3806

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the 'porto_ajax_posts' function. …

Mitigation only
Fix from $2,300 2024-05-14
Unclassified HIGH 8.8
CVE-2024-3807

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'porto_page_header_shortcode_type…

Mitigation only
Fix from $1,950 2024-05-14
Unclassified HIGH 8.8
CVE-2024-3808

The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the 'porto…

Mitigation only
Fix from $1,950 2024-05-14
Fedora HIGH 7.2
CVE-2024-31459

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.…

Fix: 1.2.27+
Fix from $1,950 2024-05-14