Vulnerability index

Browse CVEs

1,270 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
HIGH 7.5 CVE-2025-26890 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RealMag777 HUSKY woocommerce… Mitigation only Fix from $1,9502025-03-27 CRITICAL 9.8 CVE-2025-26909 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost… Hide My Wp Ghost 5.4.02+ Fix from $2,3002025-03-27 HIGH 8.8 CVE-2025-30891 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpTravelly to… Mitigation only Fix from $1,9502025-03-27 HIGH 7.5 CVE-2025-30890 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SuitePlugins Login Widget fo… Mitigation only Fix from $1,9502025-03-27 HIGH 7.5 CVE-2025-30868 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Maidul Team Manager wp-team-… Mitigation only Fix from $1,9502025-03-27 HIGH 7.5 CVE-2025-30871 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel E… Wp Travel Engine 6.3.6+ Fix from $1,9502025-03-27 HIGH 7.5 CVE-2025-30845 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in webangon The Pack Elementor … Mitigation only Fix from $1,9502025-03-27 HIGH 8.8 CVE-2025-30846 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jetmonsters Restaurant Menu … Mitigation only Fix from $1,9502025-03-27 HIGH 7.5 CVE-2025-30829 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics WPCafe wp-cafe all… Mitigation only Fix from $1,9502025-03-27 HIGH 7.5 CVE-2025-30831 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Event Post… Mitigation only Fix from $1,9502025-03-27 HIGH 7.5 CVE-2025-30820 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins WishSuite wishsui… Mitigation only Fix from $1,9502025-03-27 HIGH 7.5 CVE-2025-30814 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme The Post Grid th… Mitigation only Fix from $1,9502025-03-27 HIGH 7.5 CVE-2025-30785 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Down… Mitigation only Fix from $1,9502025-03-27 CRITICAL 9.8 CVE-2025-28916 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rashid Docpro docpro allows … Mitigation only Fix from $2,3002025-03-26 HIGH 8.1 CVE-2025-26986 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Pearl - Corpo… Mitigation only Fix from $1,9502025-03-26 HIGH 7.5 CVE-2025-27015 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designingmedia Hostiko hosti… Mitigation only Fix from $1,9502025-03-26 HIGH 8.1 CVE-2025-24690 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality for… Mitigation only Fix from $1,9502025-03-26 HIGH 8.1 CVE-2025-23937 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alex Furr LinkedIn Lite link… Mitigation only Fix from $1,9502025-03-26 HIGH 8.1 CVE-2025-23952 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ntm custom-field-list-widget… Mitigation only Fix from $1,9502025-03-26 CRITICAL 9.8 CVE-2024-13790 The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and in… Mitigation only Fix from $2,3002025-03-19 HIGH 8.8 CVE-2024-12563 The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214 via the 'template' attribute… Mitigation only Fix from $1,9502025-03-18 HIGH 7.5 CVE-2025-26137 Systemic Risk Value <=2.8.0 is vulnerable to Local File Inclusion via /GetFile.aspx?ReportUrl=. An unauthenticated attacker can exploit this issue to… Risk Value after 2.8.0 Fix from $1,9502025-03-18 CRITICAL 9.8 CVE-2025-1771 The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_load_more_pos… Traveler 3.1.9+ Fix from $2,3002025-03-15 HIGH 8.8 CVE-2025-1707 The Review Schema plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.4 via post meta. This makes it… Mitigation only Fix from $1,9502025-03-11 HIGH 7.3 CVE-2024-51319 A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Ex… Ad Hoc Infinity No fix yet Fix from $1,9502025-03-11 CRITICAL 9.0 CVE-2025-26916 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Pixflow Massive Dynamic mass… Mitigation only Fix from $2,3002025-03-10 HIGH 7.5 CVE-2025-26933 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nitin Prakash WC Place Order… Mitigation only Fix from $1,9502025-03-10 MEDIUM 5.1 CVE-2023-49031 Directory Traversal (Local File Inclusion) vulnerability in Tikit (now Advanced) eMarketing platform 6.8.3.0 allows a remote attacker to read arbitra… Tikit Emarketing No fix yet Fix from $1,6002025-03-03 HIGH 7.5 CVE-2025-27264 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creativeitem Doctor Appointm… Mitigation only Fix from $1,9502025-03-03 HIGH 8.1 CVE-2025-25109 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky WP Vehicle Manager j… Mitigation only Fix from $1,9502025-03-03