Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
HIGH 7.5 CVE-2025-3703 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wipeoutmedia CSS & JavaScrip… Mitigation only Fix from $1,9502025-08-14 HIGH 7.5 CVE-2025-32288 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensi… Mitigation only Fix from $1,9502025-08-14 HIGH 8.1 CVE-2025-30635 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeAtelier IDonatePro idon… Mitigation only Fix from $1,9502025-08-14 CRITICAL 10.0 CVE-2025-25174 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 BeeTeam368 Extens… Mitigation only Fix from $2,3002025-08-14 CRITICAL 9.8 CVE-2025-28979 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress WP Pipes allows PH… Wp Pipes after 1.4.3 Fix from $2,3002025-08-14 HIGH 8.1 CVE-2025-25172 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 VidMov vidmov all… Mitigation only Fix from $1,9502025-08-14 HIGH 7.5 CVE-2025-24766 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wproyal News Magazine X news… Mitigation only Fix from $1,9502025-08-14 CRITICAL 9.8 CVE-2025-8913 Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arb… Organization Portal System Mitigation only Fix from $2,3002025-08-13 MEDIUM 6.5 CVE-2025-51057 A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by … Vedo Suite No fix yet Fix from $1,6002025-08-06 CRITICAL 10.0 CVE-2012-10025 The WordPress plugin Advanced Custom Fields (ACF) version 3.5.1 and below contains a remote file inclusion (RFI) vulnerability in core/actions/export… Mitigation only Fix from $2,3002025-08-05 HIGH 7.5 CVE-2025-6991 The kallyas theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.21.0 via the 'TH_LatestPosts4` widget. … Mitigation only Fix from $1,9502025-07-26 HIGH 7.5 CVE-2025-54138 LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating sys… Librenms 25.7.0+ Fix from $1,9502025-07-22 CRITICAL 9.0 CVE-2025-24937 File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full … Wavesuite Noc Mitigation only Fix from $2,3002025-07-21 HIGH 7.2 CVE-2015-10133 The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the Path to header value. T… Subscribe To Comments after 2.1.2 Fix from $1,9502025-07-19 MEDIUM 6.6 CVE-2025-54015 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins HT Contact Form 7… Mitigation only Fix from $1,6002025-07-16 HIGH 8.8 CVE-2025-6746 The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via the 'layout' attribute. This … Woodmart 8.2.4+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-7327 The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.15 via the layout p… Widget For Google Reviews 1.0.16+ Fix from $1,9502025-07-08 HIGH 8.1 CVE-2025-52807 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Kossy - Minimalist eC… Mitigation only Fix from $1,9502025-07-04 HIGH 8.1 CVE-2025-4414 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Conten… Mitigation only Fix from $1,9502025-07-04 HIGH 7.5 CVE-2025-49070 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Elessi elessi-them… Mitigation only Fix from $1,9502025-07-04 HIGH 7.5 CVE-2025-47627 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LCweb PrivateContent - Mail … Mitigation only Fix from $1,9502025-07-04 CRITICAL 9.8 CVE-2025-4689 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion which leads to Remote Cod… Ads Pro after 4.89 Fix from $2,3002025-07-02 CRITICAL 9.8 CVE-2025-4380EPSS 40% The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an… Ads Pro after 4.89 Fix from $2,3002025-07-02 HIGH 7.5 CVE-2025-53339 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in devnex Devnex Addons For Ele… Mitigation only Fix from $1,9502025-06-27 HIGH 7.5 CVE-2025-53281 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPBean WPB Category Slider f… Mitigation only Fix from $1,9502025-06-27 HIGH 7.5 CVE-2025-53257 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Serhii Pasyuk Gmedia Photo G… Mitigation only Fix from $1,9502025-06-27 HIGH 7.5 CVE-2025-53259 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking nd-boo… Mitigation only Fix from $1,9502025-06-27 HIGH 8.1 CVE-2025-52812 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusWP Domnoo domnoo allows … Mitigation only Fix from $1,9502025-06-27 HIGH 8.1 CVE-2025-52814 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme BRW ova-brw allows … Mitigation only Fix from $1,9502025-06-27 HIGH 8.1 CVE-2025-52815 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CityGov citygov… Mitigation only Fix from $1,9502025-06-27