Vulnerability index

Browse CVEs

1,269 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
Unclassified HIGH 8.1
CVE-2025-69110

Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2025-60085

Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 7.5
CVE-2025-49403

Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2025-58924

Unauthenticated Local File Inclusion in Geya <= 1.15 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2025-58952

Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2025-58953

Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 8.1
CVE-2025-58954

Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions.

Mitigation only
Fix from $1,950 2026-06-17
Unclassified HIGH 7.2
CVE-2026-49954

Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated administrators to execute arbi…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified MEDIUM 6.2
CVE-2016-20077

WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by ex…

No fix yet
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.2
CVE-2016-20078

WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by ma…

No fix yet
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.2
CVE-2016-20079

WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary …

No fix yet
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.2
CVE-2016-20080

WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attack…

No fix yet
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.2
CVE-2016-20082

WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulatin…

No fix yet
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.2
CVE-2016-20064

WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescap…

No fix yet
Fix from $1,600 2026-06-09
Unclassified HIGH 8.1
CVE-2026-9662

The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to…

Mitigation only
Fix from $1,950 2026-06-09
Unclassified HIGH 8.1
CVE-2026-39552

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint al…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 8.1
CVE-2026-39553

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes WaveRide allow…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 8.1
CVE-2025-68886

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 8.1
CVE-2025-69369

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows P…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 8.1
CVE-2025-58707

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP …

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 8.1
CVE-2025-58897

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 8.1
CVE-2025-53440

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Confidant allows…

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 7.5
CVE-2025-58024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnboundStudio Accordion FAQ …

Mitigation only
Fix from $1,950 2026-06-02
Unclassified HIGH 8.1
CVE-2025-58705

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Crafti allows PH…

Mitigation only
Fix from $1,950 2026-06-02
Freepbx HIGH 8.8
CVE-2026-44239

FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-suppli…

Fix: 16.0.22 / 17.0.5+
Fix from $1,950 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-9559

A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw …

Mitigation only
Fix from $2,300 2026-05-29
Unclassified HIGH 8.0
CVE-2026-37266

An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.p…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 7.5
CVE-2026-48972

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SeedProd LLC SeedProd Pro al…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-9200

The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2.1 via the shortcode function…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-48133

When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on…

Mitigation only
Fix from $1,950 2026-05-26