Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
CRITICAL 9.8 CVE-2025-11023 Inclusion of Functionality from Untrusted Control Sphere, Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File… Mitigation only Fix from $2,3002025-10-23 HIGH 8.1 CVE-2025-62029 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themesion Grevo grevo.This i… Mitigation only Fix from $1,9502025-10-22 HIGH 7.5 CVE-2025-62054 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in favethemes Houzez Theme - Fu… Mitigation only Fix from $1,9502025-10-22 HIGH 8.1 CVE-2025-59558 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allo… Billey 2.1.6+ Fix from $1,9502025-10-22 HIGH 8.1 CVE-2025-59564 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall al… Edumall 4.4.5+ Fix from $1,9502025-10-22 HIGH 8.1 CVE-2025-58967 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Businext businext … Businext 2.4.4+ Fix from $1,9502025-10-22 HIGH 8.1 CVE-2025-59550 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Xcare xcare all… Mitigation only Fix from $1,9502025-10-22 HIGH 8.1 CVE-2025-59555 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Medizin medizin al… Medizin 1.9.7+ Fix from $1,9502025-10-22 HIGH 8.1 CVE-2025-58955 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designervily Karzo karzo all… Mitigation only Fix from $1,9502025-10-22 HIGH 8.1 CVE-2025-58958 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove SmilePure smilepur… Smilepure 1.8.5+ Fix from $1,9502025-10-22 HIGH 7.5 CVE-2025-49935 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in xtemos WoodMart woodmart all… Mitigation only Fix from $1,9502025-10-22 HIGH 7.5 CVE-2025-49921 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetReviews jet-re… Mitigation only Fix from $1,9502025-10-22 HIGH 7.5 CVE-2025-48338 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kevon Adonis WP Abstracts wp… Mitigation only Fix from $1,9502025-10-22 HIGH 7.5 CVE-2025-32657 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slid… Mitigation only Fix from $1,9502025-10-22 HIGH 7.5 CVE-2025-11722 The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including… Mitigation only Fix from $1,9502025-10-15 CRITICAL 9.8 CVE-2025-7634 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,… Mitigation only Fix from $2,3002025-10-09 CRITICAL 9.8 CVE-2025-7721 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, … Mitigation only Fix from $2,3002025-10-03 HIGH 8.1 CVE-2025-9991 The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.3.34 via the 'la… Mitigation only Fix from $1,9502025-09-30 HIGH 8.1 CVE-2025-9993 The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the … Mitigation only Fix from $1,9502025-09-30 HIGH 7.5 CVE-2025-60150 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpshuffle Subscribe to Downl… Mitigation only Fix from $1,9502025-09-26 HIGH 7.5 CVE-2025-60153 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpshuffle Subscribe To Unloc… Mitigation only Fix from $1,9502025-09-26 HIGH 8.8 CVE-2025-60126 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginOps Testimonial Slider… Mitigation only Fix from $1,9502025-09-26 HIGH 7.5 CVE-2025-59588 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad … Mitigation only Fix from $1,9502025-09-22 HIGH 7.5 CVE-2025-58973 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hashthemes Easy Elementor Ad… Mitigation only Fix from $1,9502025-09-22 HIGH 7.5 CVE-2025-57925 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in immonex immonex Kickstart Te… Mitigation only Fix from $1,9502025-09-22 HIGH 7.5 CVE-2025-53450 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Pluginwale Easy Pricing Tabl… Mitigation only Fix from $1,9502025-09-22 HIGH 7.5 CVE-2025-10143 The Catch Dark Mode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0 via the 'catch_dark_mode' sh… Mitigation only Fix from $1,9502025-09-17 HIGH 7.5 CVE-2025-10269 The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.13. This makes it possible … Mitigation only Fix from $1,9502025-09-12 HIGH 7.5 CVE-2025-9874 The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6 via the 'uclwp_… Mitigation only Fix from $1,9502025-09-11 HIGH 8.1 CVE-2025-58215 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Ziston ziston allows … Mitigation only Fix from $1,9502025-09-09