CWE-98
1,269 CVEs • Abstraction: Variant • Likelihood of Exploit: High
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
CVEs (1,269)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is p...Show more |
1Infornweb 1News & Blog Designer Pack Jun 17, 2026 Nov 22, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerable to Remote Code Execution via Local Fi...Show more |
1Jonashjalmarsson 1Html Filter And Csv File Search Jun 17, 2026 Oct 31, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 via the 'src' attribute of the 'csvsearch' shortcode. This allows authenticated attacke...Show more |
The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3 via a shortcode attribute. This allows subscriber-level, and above, attackers to include and execute arbitr...Show more |
The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-...Show more |
The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. This allows unauthenticated attackers to include and execute arbitrary fi...Show more |
FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download. |
FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log |
An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to retrieve PHP files from the server via Local File Inclusion. |
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote...Show more |
PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3. |
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_conten...Show more |
PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1. |
AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability. |
PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3. |
PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0. |
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications allow Local File Inclusion in any page relying on the href parameter to specify the JSP page to be rendered. This affects ApriPagina.do P...Show more |
1Opensecurity 1Mobile Security Framework Jun 17, 2026 Oct 18, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script. This vulnerability allows attackers to read arbitrary files v...Show more |
1Simple College Website Project 1Simple College Website Jun 17, 2026 Sep 22, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set...Show more |
A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attacker to inject attacker supplied html into a page. |