Vulnerability index

Browse CVEs

1,269 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
Unclassified HIGH 7.5
CVE-2026-39661

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP…

Mitigation only
Fix from $1,950 2026-05-26
Concrete Cms HIGH 7.2
CVE-2026-8134

Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page ty…

Fix: after 9.5.0
Fix from $1,950 2026-05-21
Unclassified HIGH 7.4
CVE-2026-39850

Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that lea…

Patch available
Fix from $1,950 2026-05-20
Unclassified HIGH 8.8
CVE-2026-7522

The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.0 via the 't…

Mitigation only
Fix from $1,950 2026-05-20
Unclassified HIGH 7.5
CVE-2018-25329

WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by i…

No fix yet
Fix from $1,950 2026-05-17
Unclassified MEDIUM 6.2
CVE-2018-25324

Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrar…

No fix yet
Fix from $1,600 2026-05-17
Unclassified MEDIUM 6.2
CVE-2021-47978

ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper…

No fix yet
Fix from $1,600 2026-05-16
Unclassified MEDIUM 6.2
CVE-2020-37246

Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by mani…

No fix yet
Fix from $1,600 2026-05-16
Unclassified MEDIUM 5.5
CVE-2020-37169

WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files b…

No fix yet
Fix from $1,600 2026-05-13
Unclassified HIGH 8.8
CVE-2026-3425

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path'…

Mitigation only
Fix from $1,950 2026-05-13
Unclassified MEDIUM 6.2
CVE-2022-50954

WordPress Plugin cab-fare-calculator 1.0.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary file…

No fix yet
Fix from $1,600 2026-05-10
Unclassified HIGH 8.9
CVE-2026-8208

Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and fo…

Mitigation only
Fix from $1,950 2026-05-09
Froxlor CRITICAL 9.9
CVE-2026-41228

Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does…

Fix: 2.3.6+
Fix from $2,300 2026-04-23
Unclassified HIGH 8.8
CVE-2026-1620

The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.0. This is due t…

Mitigation only
Fix from $1,950 2026-04-16
Boidcms HIGH 7.2
CVE-2026-39387

BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vu…

Fix: 2.1.3+
Fix from $1,950 2026-04-14
Unclassified MEDIUM 6.5
CVE-2026-30480

A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to in…

Mitigation only
Fix from $1,600 2026-04-14
Unclassified HIGH 7.5
CVE-2025-5804

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Case Themes Case Theme User …

Mitigation only
Fix from $1,950 2026-04-10
Unclassified HIGH 8.1
CVE-2025-58913

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CactusThemes VideoPro videop…

Mitigation only
Fix from $1,950 2026-04-10
Unclassified HIGH 7.5
CVE-2026-39684

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnTheme OrganicFood organicf…

Mitigation only
Fix from $1,950 2026-04-08
Unclassified HIGH 7.5
CVE-2026-39677

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Emphires em…

Mitigation only
Fix from $1,950 2026-04-08
Unclassified HIGH 7.5
CVE-2026-39679

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Freeio freeio allo…

Mitigation only
Fix from $1,950 2026-04-08
Unclassified HIGH 7.5
CVE-2026-39681

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Homeo homeo allows…

Mitigation only
Fix from $1,950 2026-04-08
Unclassified HIGH 7.5
CVE-2026-39623

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Biolife biolife a…

Mitigation only
Fix from $1,950 2026-04-08
Unclassified HIGH 7.5
CVE-2026-39613

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Boutique kute-bou…

Mitigation only
Fix from $1,950 2026-04-08
Unclassified HIGH 7.5
CVE-2026-39611

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes KuteShop kuteshop…

Mitigation only
Fix from $1,950 2026-04-08
Unclassified HIGH 7.5
CVE-2026-39544

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeStek LabtechCO labtechc…

Mitigation only
Fix from $1,950 2026-04-08
Unclassified HIGH 7.5
CVE-2026-39538

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Mikado Core mi…

Mitigation only
Fix from $1,950 2026-04-08
Emlog MEDIUM 6.5
CVE-2026-34787

Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability exists in admin/plugin.php a…

Fix: after 2.6.2
Fix from $1,600 2026-04-03
Dolibarr Erp\/crm MEDIUM 6.5
CVE-2026-34036

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is…

Fix: after 22.0.4
Fix from $1,600 2026-03-31
Heidisql MEDIUM 5.5
CVE-2018-25231

HeidiSQL 9.5.0.5196 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long …

Fix: after 9.5.0.5196
Fix from $1,600 2026-03-30