Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
HIGH 8.1 CVE-2025-67981 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP… Mitigation only Fix from $1,9502026-02-20 HIGH 8.1 CVE-2025-67982 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna urna allows PHP… Mitigation only Fix from $1,9502026-02-20 HIGH 8.1 CVE-2025-67988 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean CozyStay cozystay … Mitigation only Fix from $1,9502026-02-20 HIGH 8.1 CVE-2025-60087 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nenad Obradovic Extensive VC… Mitigation only Fix from $1,9502026-02-20 HIGH 7.5 CVE-2026-27343 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VanKarWai Airtifact airtifac… Mitigation only Fix from $1,9502026-02-19 HIGH 7.5 CVE-2026-27052 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in villatheme Sales Countdown T… Mitigation only Fix from $1,9502026-02-19 HIGH 7.5 CVE-2026-25326 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Conten… Mitigation only Fix from $1,9502026-02-19 CRITICAL 9.8 CVE-2026-0926EPSS 9% The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'parameters[templ… Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.1 CVE-2026-25548 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerabil… Invoiceplane 1.7.1+ Fix from $2,3002026-02-18 HIGH 7.5 CVE-2026-1988 The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.… Mitigation only Fix from $1,9502026-02-14 HIGH 8.8 CVE-2025-15368 The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name… Mitigation only Fix from $1,9502026-02-04 HIGH 7.5 CVE-2026-25027 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp al… Mitigation only Fix from $1,9502026-02-03 HIGH 7.5 CVE-2024-54263 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Talemy Spirit Framework allo… Mitigation only Fix from $1,9502026-02-02 CRITICAL 9.8 CVE-2021-47900 Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system comm… Mitigation only Fix from $2,3002026-01-27 HIGH 7.5 CVE-2026-1257 The Administrative Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.3.4 via the 'slug' a… Mitigation only Fix from $1,9502026-01-24 HIGH 7.5 CVE-2026-24635 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DevsBlink EduBlink Core edub… Mitigation only Fix from $1,9502026-01-23 HIGH 7.5 CVE-2026-24608 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent Core l… Mitigation only Fix from $1,9502026-01-23 HIGH 7.5 CVE-2026-24609 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent lauren… Mitigation only Fix from $1,9502026-01-23 HIGH 7.5 CVE-2026-24531 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Prowess prowes… Mitigation only Fix from $1,9502026-01-23 HIGH 7.5 CVE-2026-24538 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in omnipressteam Omnipress omni… Mitigation only Fix from $1,9502026-01-23 HIGH 7.5 CVE-2026-24390 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QantumThemes Kentha Elemento… Mitigation only Fix from $1,9502026-01-22 HIGH 7.5 CVE-2026-23975 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo golo allows PHP L… Mitigation only Fix from $1,9502026-01-22 HIGH 7.5 CVE-2026-23978 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Softwebmedia Gyan Elements g… Mitigation only Fix from $1,9502026-01-22 HIGH 7.5 CVE-2026-22464 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wphocus My auctions allegro … Mitigation only Fix from $1,9502026-01-22 HIGH 7.5 CVE-2026-22401 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pavothemes Freshio freshio a… Mitigation only Fix from $1,9502026-01-22 HIGH 7.5 CVE-2026-22402 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pavothemes Triply triply all… Mitigation only Fix from $1,9502026-01-22 HIGH 8.1 CVE-2025-69314 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes Werkstatt werksta… Mitigation only Fix from $1,9502026-01-22 HIGH 8.1 CVE-2025-69078 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Malta malta all… Mitigation only Fix from $1,9502026-01-22 HIGH 8.1 CVE-2025-69100 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes North north-wp al… Mitigation only Fix from $1,9502026-01-22 HIGH 8.1 CVE-2025-69071 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes TanTum tantum a… Mitigation only Fix from $1,9502026-01-22