Vulnerability index

Browse CVEs

1,269 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
HIGH 8.1 CVE-2025-69110 Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2025-60085 Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 7.5 CVE-2025-49403 Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2025-58924 Unauthenticated Local File Inclusion in Geya <= 1.15 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2025-58952 Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2025-58953 Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.1 CVE-2025-58954 Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 7.2 CVE-2026-49954 Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated administrators to execute arbi… Mitigation only Fix from $1,9502026-06-15 MEDIUM 6.2 CVE-2016-20077 WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by ex… No fix yet Fix from $1,6002026-06-15 MEDIUM 6.2 CVE-2016-20078 WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by ma… No fix yet Fix from $1,6002026-06-15 MEDIUM 6.2 CVE-2016-20079 WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary … No fix yet Fix from $1,6002026-06-15 MEDIUM 6.2 CVE-2016-20080 WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attack… No fix yet Fix from $1,6002026-06-15 MEDIUM 6.2 CVE-2016-20082 WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulatin… No fix yet Fix from $1,6002026-06-15 MEDIUM 6.2 CVE-2016-20064 WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescap… No fix yet Fix from $1,6002026-06-09 HIGH 8.1 CVE-2026-9662 The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to… Mitigation only Fix from $1,9502026-06-09 HIGH 8.1 CVE-2026-39552 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint al… Mitigation only Fix from $1,9502026-06-02 HIGH 8.1 CVE-2026-39553 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes WaveRide allow… Mitigation only Fix from $1,9502026-06-02 HIGH 8.1 CVE-2025-68886 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows… Mitigation only Fix from $1,9502026-06-02 HIGH 8.1 CVE-2025-69369 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows P… Mitigation only Fix from $1,9502026-06-02 HIGH 8.1 CVE-2025-58707 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP … Mitigation only Fix from $1,9502026-06-02 HIGH 8.1 CVE-2025-58897 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows… Mitigation only Fix from $1,9502026-06-02 HIGH 8.1 CVE-2025-53440 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Confidant allows… Mitigation only Fix from $1,9502026-06-02 HIGH 7.5 CVE-2025-58024 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnboundStudio Accordion FAQ … Mitigation only Fix from $1,9502026-06-02 HIGH 8.1 CVE-2025-58705 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Crafti allows PH… Mitigation only Fix from $1,9502026-06-02 HIGH 8.8 CVE-2026-44239 FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-suppli… Freepbx 16.0.22 / 17.0.5+ Fix from $1,9502026-05-29 CRITICAL 9.9 CVE-2026-9559 A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw … Mitigation only Fix from $2,3002026-05-29 HIGH 8.0 CVE-2026-37266 An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.p… Mitigation only Fix from $1,9502026-05-28 HIGH 7.5 CVE-2026-48972 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SeedProd LLC SeedProd Pro al… Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-9200 The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2.1 via the shortcode function… Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-48133 When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on… Mitigation only Fix from $1,9502026-05-26