Vulnerability index

Browse CVEs

1,274 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
Unclassified CRITICAL 9.8
CVE-2024-3806

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the 'porto_ajax_posts' function. …

Mitigation only
Fix from $2,300 2024-05-14
Unclassified HIGH 8.8
CVE-2024-3807

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'porto_page_header_shortcode_type…

Mitigation only
Fix from $1,950 2024-05-14
Unclassified HIGH 8.8
CVE-2024-3808

The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the 'porto…

Mitigation only
Fix from $1,950 2024-05-14
Fedora HIGH 7.2
CVE-2024-31459

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.…

Fix: 1.2.27+
Fix from $1,950 2024-05-14
Unclassified HIGH 8.8
CVE-2024-3849

The Click to Chat – HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.35. This makes it p…

Mitigation only
Fix from $1,950 2024-05-02
Elementskit HIGH 8.8
CVE-2024-3500

The ElementsKit Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.0 via the Price Menu, Hotspo…

Fix: 3.6.1+
Fix from $1,950 2024-05-02
Elements Kit Elementor Addons HIGH 8.8
CVE-2024-3499

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the gener…

Fix: 3.1.1+
Fix from $1,950 2024-05-02
Lollms Web Ui CRITICAL 9.3
CVE-2024-1600EPSS 33%

A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attack…

Fix: 9.6+
Fix from $2,300 2024-04-10
Masterstudy Lms CRITICAL 9.8
CVE-2024-3136EPSS 5%

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' paramet…

Fix: 3.3.4+
Fix from $2,300 2024-04-09
Complete E Commerce Site CRITICAL 9.8
CVE-2024-30849

Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename p…

No fix yet
Fix from $2,300 2024-04-05
Elements Kit Elementor Addons HIGH 8.8
CVE-2024-2047

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.6 via the rende…

Fix: 3.0.7+
Fix from $1,950 2024-03-30
Husky Products Filter Professional For Woocommerce HIGH 7.2
CVE-2024-3061

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ…

Fix: 1.3.5.3+
Fix from $1,950 2024-03-29
Masterstudy Lms CRITICAL 9.8
CVE-2024-2411

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter.…

Fix: 3.3.1+
Fix from $2,300 2024-03-29
Restaurant Reservations HIGH 8.8
CVE-2024-1382

The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the nd_rst_layou…

Fix: 2.0+
Fix from $1,950 2024-03-07
Shield Security CRITICAL 9.8
CVE-2023-6989EPSS 57%

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions u…

Fix: 18.5.10+
Fix from $2,300 2024-02-05
Apex Central HIGH 7.5
CVE-2023-52325

A local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a remote attacker to execute arbitrary code on affected…

Mitigation only
Fix from $1,950 2024-01-23
Central Management HIGH 7.8
CVE-2024-0315

Remote file inclusion vulnerability in FireEye Central Management affecting version 9.1.1.956704. This vulnerability allows an attacker to upload a m…

Mitigation only
Fix from $1,950 2024-01-15
Import And Export Users And Customers HIGH 7.2
CVE-2023-6583

The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.24.2 via …

Fix: after 1.24.2
Fix from $1,950 2024-01-11
Cacti HIGH 8.8
CVE-2023-49084EPSS 64%

Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL …

No fix yet
Fix from $1,950 2023-12-21
News \& Blog Designer Pack CRITICAL 9.8
CVE-2023-5815

The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) p…

Fix: after 3.4.1
Fix from $2,300 2023-11-22
Html Filter And Csv File Search HIGH 8.8
CVE-2023-5099

The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 via the 'src' at…

Fix: 2.8+
Fix from $1,950 2023-10-31
Php To Page HIGH 8.8
CVE-2023-5199

The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-t…

Fix: after 0.3
Fix from $1,950 2023-10-30
Grid Plus HIGH 8.8
CVE-2023-5250

The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3 via a shortcode attribute. This allo…

Fix: after 1.3.2
Fix from $1,950 2023-10-30
Dropbox Folder Share CRITICAL 9.8
CVE-2023-4488

The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. Th…

Fix: after 1.9.7
Fix from $2,300 2023-10-20
Fuxa HIGH 7.5
CVE-2023-31718

FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.

Fix: after 1.1.12
Fix from $1,950 2023-09-22
Fuxa HIGH 7.5
CVE-2023-31716

FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log

Fix: after 1.1.12
Fix from $1,950 2023-09-22
Canto CRITICAL 9.8
CVE-2023-3452EPSS 7%

The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This al…

Fix: after 3.0.4
Fix from $2,300 2023-08-12
Cockpit HIGH 8.8
CVE-2023-4195

PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

Fix: 2.6.3+
Fix from $1,950 2023-08-06
Wpforo Forum HIGH 8.8
CVE-2023-2249EPSS 61%

The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, a…

Fix: after 2.1.7
Fix from $1,950 2023-06-09
Bumsys HIGH 8.8
CVE-2023-2551

PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.

Fix: 2.1.1+
Fix from $1,950 2023-05-05