VYPR

CWE-98

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

VariantDraftLikelihood: High

Description

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

In certain versions and configurations of PHP, this can allow an attacker to specify a URL to a remote location from which the product will obtain the code to execute. In other cases in association with path traversal, the attacker can specify a local file that may contain executable statements that can be parsed by PHP.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-193

CVEs mapped to this weakness (1,304)

page 59 of 66
  • CVE-2023-31716HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log

  • CVE-2022-44786HigNov 21, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Appalti & Contratti 9.12.2. The target web applications allow Local File Inclusion in any page relying on the href parameter to specify the JSP page to be rendered. This affects ApriPagina.do POST and GET requests to each application.

  • CVE-2020-13175HigAug 11, 2020
    risk 0.49cvss 7.5epss 0.02

    The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 and earlier for Cloud Access Connector) contains a local file inclusion vulnerability which allows an unauthenticated remote attacker to…

  • CVE-2019-5479HigSep 3, 2019
    risk 0.49cvss 7.5epss 0.01

    An unintended require vulnerability in <v0.5.5 larvitbase-api may allow an attacker to load arbitrary non-production code (JavaScript file).

  • CVE-2016-6565HigJul 13, 2018
    risk 0.49cvss 7.5epss 0.03

    The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server…

  • CVE-2026-49954HigJun 15, 2026
    risk 0.47cvss 7.2epss 0.01

    Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated administrators to execute arbitrary code by importing a specially crafted plugin configuration containing path traversal sequences in the directory attribute.…

  • CVE-2026-32401HigMar 13, 2026
    risk 0.47cvss 7.2epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows PHP Local File Inclusion.This issue affects Client Invoicing by Sprout Invoices: from n/a…

  • CVE-2024-51319HigMar 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution by uploading a jsp web/reverse shell through /jsp/zimg_upload.jsp.

  • CVE-2024-3061HigMar 29, 2024
    risk 0.47cvss 7.2epss 0.01

    The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.5.2 via the 'type' parameter. This makes it possible for authenticated attackers, with administrator-level access and…

  • CVE-2021-22968HigNov 19, 2021
    risk 0.47cvss 7.2epss 0.03

    A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versions 8.5.6 and below.The external file upload feature stages files in the public directory even if they have disallowed file…

  • CVE-2025-12851HigDec 5, 2025
    risk 0.46cvss 8.1epss 0.01

    The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.32 via the 'controller' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the…

  • CVE-2025-12497HigNov 5, 2025
    risk 0.46cvss 8.1epss 0.01

    The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.3.10 via the 'args[extra_template_path]' parameter. This makes it possible for unauthenticated attackers to include and execute…

  • CVE-2024-58302MedDec 11, 2025
    risk 0.45cvss —epss 0.00

    FoF Pretty Mail 1.1.2 contains a local file inclusion vulnerability that allows administrative users to include arbitrary server files in email templates. Attackers can exploit the template settings by inserting file inclusion payloads to read sensitive system files like…

  • CVE-2026-88994MedSep 18, 2026
    risk 0.43cvss 6.6epss 0.00

    The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their…

  • CVE-2026-14280MedAug 25, 2026
    risk 0.43cvss 6.6epss 0.01

    The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.3.7.4 via the em_options_save function. This makes it possible for authenticated attackers, with administrator-level…

  • CVE-2026-66586MedAug 20, 2026
    risk 0.43cvss 6.6epss 0.00

    Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

  • CVE-2025-68974MedDec 30, 2025
    risk 0.43cvss 6.6epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register:…

  • CVE-2025-66115MedNov 21, 2025
    risk 0.43cvss 6.6epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MatrixAddons Easy Invoice easy-invoice allows PHP Local File Inclusion.This issue affects Easy Invoice: from n/a through <= 2.1.4.

  • CVE-2024-8393MedAug 16, 2025
    risk 0.43cvss 6.6epss 0.01

    The Woocommerce Blocks – Woolook plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.0 via the via the 'tab' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include…

  • CVE-2025-54015MedJul 16, 2025
    risk 0.43cvss 6.6epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows PHP Local File Inclusion.This issue affects HT Contact Form 7: from n/a through <= 2.0.0.