← Back
CWE-98

1,269 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

JSON object

Loading...

CVEs (1,269)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cacti
1Cacti
Jun 17, 2026
Dec 21, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is p...Show more
Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is possible to execute arbitrary code on the server. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the `link.php`. Impact of the vulnerability execution of arbitrary code on the server.Show less
1Infornweb
1News & Blog Designer Pack
Jun 17, 2026
Nov 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerable to Remote Code Execution via Local Fi...Show more
The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerable to Remote Code Execution via Local File Inclusion in all versions up to, and including, 3.4.1 via the bdp_get_more_post function hooked via a nopriv AJAX. This is due to function utilizing an unsafe extract() method to extract values from the POST variable and passing that input to the include() function. This makes it possible for unauthenticated attackers to include arbitrary PHP files and achieve remote code execution. On vulnerable Docker configurations it may be possible for an attacker to create a PHP file and then subsequently include it to achieve RCE.Show less
1Jonashjalmarsson
1Html Filter And Csv File Search
Jun 17, 2026
Oct 31, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 via the 'src' attribute of the 'csvsearch' shortcode. This allows authenticated attacke...Show more
The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 via the 'src' attribute of the 'csvsearch' shortcode. This allows authenticated attackers, with contributor-level permissions and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.Show less
1G5theme
1Grid Plus
Jun 17, 2026
Oct 30, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3 via a shortcode attribute. This allows subscriber-level, and above, attackers to include and execute arbitr...Show more
The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3 via a shortcode attribute. This allows subscriber-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files with arbitrary content can be uploaded and included.Show less
1Php To Page Project
1Php To Page
Jun 17, 2026
Oct 30, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-...Show more
The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to include local file and potentially execute code on the server. While subscribers may need to poison log files or otherwise get a file installed in order to achieve remote code execution, author and above users can upload files by default and achieve remote code execution easily.Show less
1Hynotech
1Dropbox Folder Share
Jun 17, 2026
Oct 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. This allows unauthenticated attackers to include and execute arbitrary fi...Show more
The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.Show less
1Frangoteam
1Fuxa
Jun 17, 2026
Sep 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
1Frangoteam
1Fuxa
Jun 17, 2026
Sep 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log
1Geomatika
1Isigeo Web
Jun 17, 2026
Aug 22, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to retrieve PHP files from the server via Local File Inclusion.
1Canto
1Canto
Jun 17, 2026
Aug 12, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote...Show more
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote code on the server, provided that allow_url_include is enabled. Local File Inclusion is also possible, albeit less useful because it requires that the attacker be able to upload a malicious php file via FTP or some other means into a directory readable by the web server.Show less
1Agentejo
1Cockpit
Jun 17, 2026
Aug 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
1Gvectors
1Wpforo Forum
Jun 17, 2026
Jun 9, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_conten...Show more
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to retrieve the contents of files like wp-config.php hosted on the system, perform a deserialization attack and possibly achieve remote code execution, and make requests to internal services.Show less
1Bumsys Project
1Bumsys
Jun 17, 2026
May 5, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.
1Agilebio
1Electronic Lab Notebook
Jun 17, 2026
Mar 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.
1Flatpress
1Flatpress
Jun 17, 2026
Dec 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.
1Corebos
1Corebos
Jun 17, 2026
Dec 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.
1Maggioli
1Appalti & Contratti
Jun 17, 2026
Nov 21, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications allow Local File Inclusion in any page relying on the href parameter to specify the JSP page to be rendered. This affects ApriPagina.do P...Show more
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications allow Local File Inclusion in any page relying on the href parameter to specify the JSP page to be rendered. This affects ApriPagina.do POST and GET requests to each application.Show less
1Opensecurity
1Mobile Security Framework
Jun 17, 2026
Oct 18, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script. This vulnerability allows attackers to read arbitrary files v...Show more
Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script. This vulnerability allows attackers to read arbitrary files via a crafted HTTP request.Show less
1Simple College Website Project
1Simple College Website
Jun 17, 2026
Sep 22, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set...Show more
A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.Show less
1Esri
1Arcgis Server
Jun 17, 2026
Dec 7, 2021
N/A· v4
4.7 MEDIUM· v3
4.3 MEDIUM· v2
A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attacker to inject attacker supplied html into a page.