Vulnerabilities (CVE)

Filtered by CWE-98
Total 1299 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-27556 2026-09-16 N/A 8.8 HIGH
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.
CVE-2026-27555 2026-09-16 N/A 8.8 HIGH
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.
CVE-2026-85200 2026-09-14 N/A 7.5 HIGH
The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. In environments where PEAR is installed with register_argc_argv enabled, this file inclusion can be leveraged to write and execute arbitrary PHP code, achieving full remote code execution.
CVE-2026-15406 2026-09-11 N/A 7.5 HIGH
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
CVE-2026-87927 2026-09-09 N/A 8.2 HIGH
MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.
CVE-2026-15667 2026-09-09 N/A 7.5 HIGH
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The etn_manage_event capability is assigned to Contributors by default, meaning any Contributor-level user can set the malicious event_layout value via the REST API without any additional configuration.
CVE-2026-11613 2026-09-07 N/A 9.8 CRITICAL
The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. This vulnerability is only exploitable when the loop_templates parameter is set to 'custom-template'.
CVE-2026-14280 2026-08-26 N/A 6.6 MEDIUM
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.3.7.4 via the em_options_save function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal key is subsequently executed via an include_once() call that fires on every admin_init invocation — including unauthenticated admin-ajax.php requests — meaning once the malicious key is stored by an administrator, the inclusion is triggered without any further authentication or capability check.
CVE-2026-78478 2026-08-26 N/A 8.1 HIGH
The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
CVE-2026-32560 2026-08-26 N/A 8.8 HIGH
Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.
CVE-2026-66670 2026-08-24 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Måne <= 1.7 versions.
CVE-2026-28152 2026-08-24 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
CVE-2026-66671 2026-08-24 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.
CVE-2026-66587 2026-08-24 N/A 9.8 CRITICAL
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
CVE-2026-28151 2026-08-24 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Tonda < 2.6 versions.
CVE-2019-25760 1 Joomtech 1 Easy Shop 2026-08-21 N/A 6.2 MEDIUM
Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task set to ajax.loadImage, and a base64-encoded file path in the file parameter to retrieve sensitive files like configuration.php and system files.
CVE-2026-28150 2026-08-20 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.
CVE-2026-75963 2026-08-20 N/A 7.5 HIGH
The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, meaning post-submission execution does not require additional attacker interaction.
CVE-2026-66586 2026-08-20 N/A 6.6 MEDIUM
Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
CVE-2025-15637 2026-08-20 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.