CWE-98
1,295 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
CVEs (1,295)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated a...Show more |
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage. |
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage. |
The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, all...Show more |
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.3.7.4 via the em_options_save function. This makes it possibl...Show more |
Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions. |
Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions. |
Unauthenticated Local File Inclusion in Måne <= 1.7 versions. |
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions. |
Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions. |
Unauthenticated Local File Inclusion in Tonda < 2.6 versions. |
Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions. |
Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. |
Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. |
The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attack...Show more |
Unauthenticated Local File Inclusion in Resido <= 1.5 versions. |
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. |
Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. |
Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. |
Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. |