CWE-98— PHP Remote File Inclusion
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.— MITRE CWE catalog
1,294 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-98page 26 of 26
- CVE-2026-57748HIGHCVSS 7.5EG 7.52026-07-02
Contributor Local File Inclusion in Shopify <= 1.0.0 versions.
- CVE-2026-57749HIGHCVSS 7.5EG 7.52026-07-02
Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.
- CVE-2026-57788HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Aalto aalto allows PHP Local File Inclusion.This issue affects Aalto: from n/a through <= 1.8.
- CVE-2026-57789HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PHP Local File Inclusion.This issue affects Aqua: from n/a through <= 5.1.2.
- CVE-2026-57790HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.This issue affects Billey: from n/a through <= 2.1.8.
- CVE-2026-57791HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This issue affects Brook: from n/a through <= 2.9.0.
- CVE-2026-57792HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through <= 2.4.1.
- CVE-2026-57793HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Flow flow allows PHP Local File Inclusion.This issue affects Flow: from n/a through <= 1.8.
- CVE-2026-57794HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-framework allows PHP Local File Inclusion.This issue affects Golo Framework: from n/a throug…
- CVE-2026-57795HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Kitchor kitchor allows PHP Local File Inclusion.This issue affects Kitchor: from n/a through <= 1.4.3.
- CVE-2026-57796HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VLThemes Leedo leedo allows PHP Local File Inclusion.This issue affects Leedo: from n/a through <= 3.0.0.
- CVE-2026-57798HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortcodes newsplus-shortcodes allows PHP Local File Inclusion.This issue affects NewsPlus Shor…
- CVE-2026-57799HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Nuss nuss allows PHP Local File Inclusion.This issue affects Nuss: from n/a through <= 1.3.6.
- CVE-2026-57800HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Overworld overworld allows PHP Local File Inclusion.This issue affects Overworld: from n/a through <= 1.5.
- CVE-2026-57801HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes SetSail setsail allows PHP Local File Inclusion.This issue affects SetSail: from n/a through <= 2.1.
- CVE-2026-57802HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur allows PHP Local File Inclusion. This issue affects Struktur: from n/a before 2.7.
- CVE-2026-57803HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur Core allows PHP Local File Inclusion. This issue affects Struktur Core: from n/a before 2.7.
- CVE-2026-57804HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows PHP Local File Inclusion. This issue affects TheGem Theme El…
- CVE-2026-57805HIGHCVSS 7.5EG 7.52026-07-13
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Tonda tonda allows PHP Local File Inclusion.This issue affects Tonda: from n/a through <= 2.5.
- CVE-2026-63302MEDIUMCVSS 5.1EG 5.12026-07-28
Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application's directory structure via a cra…
- CVE-2026-65477HIGHCVSS 7.5EG 7.52026-07-23
Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
- CVE-2026-65481HIGHCVSS 7.5EG 7.52026-07-23
Contributor Local File Inclusion in Vino <= 1.9 versions.
- CVE-2026-66450HIGHCVSS 8.1EG 8.12026-08-13
Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions.
- CVE-2026-66586MEDIUMCVSS 6.6EG 6.62026-08-20
Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
- CVE-2026-66587CRITICALCVSS 9.8EG 9.82026-08-24
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
- CVE-2026-66653HIGHCVSS 8.1EG 8.12026-08-13
Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.
- CVE-2026-66656HIGHCVSS 8.1EG 8.12026-08-13
Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.
- CVE-2026-66657HIGHCVSS 8.1EG 8.12026-08-13
Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.
- CVE-2026-66670HIGHCVSS 8.1EG 8.12026-08-24
Unauthenticated Local File Inclusion in Måne <= 1.7 versions.
- CVE-2026-66671HIGHCVSS 8.1EG 8.12026-08-24
Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.
- CVE-2026-66710HIGHCVSS 8.1EG 8.12026-08-06
Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
- CVE-2026-73387HIGHCVSS 8.1EG 8.12026-08-19
Unauthenticated Local File Inclusion in Resido <= 1.5 versions.
- CVE-2026-73400HIGHCVSS 8.1EG 8.12026-08-18
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
- CVE-2026-7515CRITICALCVSS 9.8EG 9.82026-06-19
The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php…
- CVE-2026-7522HIGHCVSS 8.8EG 8.82026-05-20
The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.0 via the 'template' parameter. This makes it possible for authenticated attackers, with Subscriber-…
- CVE-2026-75963HIGHCVSS 7.5EG 7.52026-08-20
The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contribut…
- CVE-2026-78478HIGHCVSS 8.1EG 8.12026-08-25
The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution…
- CVE-2026-78562HIGHCVSS 8.1EG 8.12026-08-25
The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the …
- CVE-2026-78566HIGHCVSS 8.1EG 8.12026-08-25
The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execut…
- CVE-2026-8134HIGHCVSS 7.2EG 7.22026-05-21
Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing …
- CVE-2026-8208HIGHCVSS 8.9EG 8.92026-05-09
Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user provided .zip as PHP. Successful exploitation requires Teac…
- CVE-2026-9200HIGHCVSS 7.5EG 7.52026-05-27
The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2.1 via the shortcode function. This makes it possible for authenticated attackers, with contributor-level access and ab…
- CVE-2026-9559CRITICALCVSS 9.9EG 9.92026-05-29
A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. An…
- CVE-2026-9662HIGHCVSS 8.1EG 8.12026-06-09
The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to insufficient validation and sanitization of the user-controlled `tpf` POST parameter befo…
Map vulnerabilities like CWE-98 to your infrastructure
EchelonGraph correlates every CVE — across CWE-98 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →