← Back
CWE-98

1,269 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

JSON object

Loading...

CVEs (1,269)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in Deliciosa <= 1.10.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in Corbesier <= 1.15.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in CopyPress <= 1.4.5 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in Ingenioso <= 1.14.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in Iona <= 1.0.8 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in MaxiNet <= 1.2.10 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in Nexio <= 1.10.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in Planty <= 1.14.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in Raider Spirit <= 1.1.2 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in Rosaleen <= 2.8 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in Modernee <= 1.6.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Unauthenticated Local File Inclusion in Geya <= 1.15 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions.
-
-
Jun 17, 2026
Jun 15, 2026
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated administrators to execute arbitrary code by importing a specially crafted plugin configuration contai...Show more
Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated administrators to execute arbitrary code by importing a specially crafted plugin configuration containing path traversal sequences in the directory attribute. Attackers can trigger an exception during plugin installation to bypass sanitization routines, causing malicious paths to be stored unsanitized and subsequently passed to include(), which combined with file upload functionality escalates to arbitrary code execution in the context of the web server user.Show less
-
-
Jun 15, 2026
Jun 15, 2026
6.9 MEDIUM· v4
6.2 MEDIUM· v3
N/A· v2
WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the action parameter. Attackers can send GET requests to abtest_admin...Show more
WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the action parameter. Attackers can send GET requests to abtest_admin.php with malicious action values to include files from the admin directory and execute arbitrary code.Show less