Vulnerability index

Browse CVEs

1,269 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness PHP File Inclusion (RFI/LFI)CWE-98 × clear
HIGH 7.5 CVE-2026-39661 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP… Mitigation only Fix from $1,9502026-05-26 HIGH 7.2 CVE-2026-8134 Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page ty… Concrete Cms after 9.5.0 Fix from $1,9502026-05-21 HIGH 7.4 CVE-2026-39850 Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that lea… Patch available Fix from $1,9502026-05-20 HIGH 8.8 CVE-2026-7522 The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.0 via the 't… Mitigation only Fix from $1,9502026-05-20 HIGH 7.5 CVE-2018-25329 WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by i… No fix yet Fix from $1,9502026-05-17 MEDIUM 6.2 CVE-2018-25324 Simple Fields 0.2 through 0.3.5 WordPress Plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrar… No fix yet Fix from $1,6002026-05-17 MEDIUM 6.2 CVE-2021-47978 ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper… No fix yet Fix from $1,6002026-05-16 MEDIUM 6.2 CVE-2020-37246 Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by mani… No fix yet Fix from $1,6002026-05-16 MEDIUM 5.5 CVE-2020-37169 WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files b… No fix yet Fix from $1,6002026-05-13 HIGH 8.8 CVE-2026-3425 The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path'… Mitigation only Fix from $1,9502026-05-13 MEDIUM 6.2 CVE-2022-50954 WordPress Plugin cab-fare-calculator 1.0.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary file… No fix yet Fix from $1,6002026-05-10 HIGH 8.9 CVE-2026-8208 Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and fo… Mitigation only Fix from $1,9502026-05-09 CRITICAL 9.9 CVE-2026-41228 Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does… Froxlor 2.3.6+ Fix from $2,3002026-04-23 HIGH 8.8 CVE-2026-1620 The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.0. This is due t… Mitigation only Fix from $1,9502026-04-16 HIGH 7.2 CVE-2026-39387 BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vu… Boidcms 2.1.3+ Fix from $1,9502026-04-14 MEDIUM 6.5 CVE-2026-30480 A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to in… Mitigation only Fix from $1,6002026-04-14 HIGH 7.5 CVE-2025-5804 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Case Themes Case Theme User … Mitigation only Fix from $1,9502026-04-10 HIGH 8.1 CVE-2025-58913 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CactusThemes VideoPro videop… Mitigation only Fix from $1,9502026-04-10 HIGH 7.5 CVE-2026-39684 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnTheme OrganicFood organicf… Mitigation only Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-39677 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Emphires em… Mitigation only Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-39679 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Freeio freeio allo… Mitigation only Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-39681 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Homeo homeo allows… Mitigation only Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-39623 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Biolife biolife a… Mitigation only Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-39613 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Boutique kute-bou… Mitigation only Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-39611 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes KuteShop kuteshop… Mitigation only Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-39544 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themeStek LabtechCO labtechc… Mitigation only Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-39538 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Mikado Core mi… Mitigation only Fix from $1,9502026-04-08 MEDIUM 6.5 CVE-2026-34787 Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability exists in admin/plugin.php a… Emlog after 2.6.2 Fix from $1,6002026-04-03 MEDIUM 6.5 CVE-2026-34036 Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is… Dolibarr Erp\/crm after 22.0.4 Fix from $1,6002026-03-31 MEDIUM 5.5 CVE-2018-25231 HeidiSQL 9.5.0.5196 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long … Heidisql after 9.5.0.5196 Fix from $1,6002026-03-30