Vulnerabilities (CVE)

Filtered by CWE-98
Total 1299 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-57647 2026-06-26 N/A 7.5 HIGH
Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions.
CVE-2025-68064 2026-06-26 N/A 7.5 HIGH
Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.
CVE-2026-54845 2026-06-26 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.
CVE-2026-48820 2026-06-23 N/A N/A
CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11.
CVE-2026-7515 2026-06-22 N/A 9.8 CRITICAL
The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
CVE-2026-40721 2026-06-17 N/A 7.5 HIGH
Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions.
CVE-2026-39590 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.
CVE-2026-39582 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions.
CVE-2026-22338 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in EcoBlue <= 1.15 versions.
CVE-2026-22330 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Right Way <= 4.0 versions.
CVE-2026-22326 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Reprizo <= 1.0.8 versions.
CVE-2025-69166 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.
CVE-2025-69161 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Snowy <= 1.13 versions.
CVE-2025-69158 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Granola <= 1.13 versions.
CVE-2025-69145 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Gat <= 1.16 versions.
CVE-2025-69117 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Ingenioso <= 1.14.0 versions.
CVE-2025-69115 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions.
CVE-2025-69106 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.
CVE-2025-58953 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions.
CVE-2026-54814 2026-06-17 N/A 8.1 HIGH
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.