CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Description
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-193
CVEs mapped to this weakness (1,304)
page 10 of 66| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-69118 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in CopyPress <= 1.4.5 versions. | ||
| CVE-2025-69117 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Ingenioso <= 1.14.0 versions. | ||
| CVE-2025-69116 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Iona <= 1.0.8 versions. | ||
| CVE-2025-69114 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in MaxiNet <= 1.2.10 versions. | ||
| CVE-2025-69113 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Nexio <= 1.10.0 versions. | ||
| CVE-2025-69112 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Planty <= 1.14.0 versions. | ||
| CVE-2025-69110 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions. | ||
| CVE-2025-69109 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Raider Spirit <= 1.1.2 versions. | ||
| CVE-2025-69107 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Rosaleen <= 2.8 versions. | ||
| CVE-2025-69105 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Modernee <= 1.6.0 versions. | ||
| CVE-2025-60085 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions. | ||
| CVE-2025-58954 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions. | ||
| CVE-2025-58953 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions. | ||
| CVE-2025-58952 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions. | ||
| CVE-2025-58924 | Hig | 0.53 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Geya <= 1.15 versions. | ||
| CVE-2026-9662 | Hig | 0.53 | 8.1 | 0.01 | Jun 9, 2026 | The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to insufficient validation and sanitization of the user-controlled `tpf` POST parameter before it is used in an `include()` path in… | ||
| CVE-2026-39553 | Hig | 0.53 | 8.1 | 0.00 | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes WaveRide allows PHP Local File Inclusion. This issue affects WaveRide: from n/a through 1.4. | ||
| CVE-2026-39552 | Hig | 0.53 | 8.1 | 0.00 | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion. This issue affects Blueprint: from n/a before 1.1.5. | ||
| CVE-2025-69369 | Hig | 0.53 | 8.1 | 0.00 | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows PHP Local File Inclusion. This issue affects Racquet: from n/a through 1.12.0. | ||
| CVE-2025-68886 | Hig | 0.53 | 8.1 | 0.00 | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion. This issue affects Cookiteer: from n/a through 1.4.8. |
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in CopyPress <= 1.4.5 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Ingenioso <= 1.14.0 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Iona <= 1.0.8 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in MaxiNet <= 1.2.10 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Nexio <= 1.10.0 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Planty <= 1.14.0 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Raider Spirit <= 1.1.2 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Rosaleen <= 2.8 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Modernee <= 1.6.0 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Geya <= 1.15 versions.
- risk 0.53cvss 8.1epss 0.01
The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to insufficient validation and sanitization of the user-controlled `tpf` POST parameter before it is used in an `include()` path in…
- risk 0.53cvss 8.1epss 0.00
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes WaveRide allows PHP Local File Inclusion. This issue affects WaveRide: from n/a through 1.4.
- risk 0.53cvss 8.1epss 0.00
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion. This issue affects Blueprint: from n/a before 1.1.5.
- risk 0.53cvss 8.1epss 0.00
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows PHP Local File Inclusion. This issue affects Racquet: from n/a through 1.12.0.
- risk 0.53cvss 8.1epss 0.00
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion. This issue affects Cookiteer: from n/a through 1.4.8.