CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Description
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-193
CVEs mapped to this weakness (1,274)
page 63 of 64| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-13080 | Med | 0.00 | 6.6 | 0.01 | Jul 9, 2026 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.12.7 via the 'logKey' parameter parameter. This makes it possible for authenticated attackers,… | ||
| CVE-2026-12194 | Low | 0.00 | — | 0.00 | Jul 4, 2026 | PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations. | ||
| CVE-2026-5137 | Med | 0.00 | 4.3 | 0.00 | Jul 3, 2026 | The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.7 This is due to insufficient path validation on the 'template' parameter in the render_templates AJAX endpoint, which is used directly in a… | ||
| CVE-2026-57749 | Hig | 0.00 | 7.5 | 0.00 | Jul 2, 2026 | Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions. | ||
| CVE-2026-57748 | Hig | 0.00 | 7.5 | 0.00 | Jul 2, 2026 | Contributor Local File Inclusion in Shopify <= 1.0.0 versions. | ||
| CVE-2026-42382 | Hig | 0.00 | 8.1 | 0.00 | Jul 2, 2026 | Unauthenticated Local File Inclusion in Audrey <= 1.5 versions. | ||
| CVE-2026-27412 | Hig | 0.00 | 8.1 | 0.00 | Jul 2, 2026 | Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions. | ||
| CVE-2025-69133 | Hig | 0.00 | 7.5 | 0.00 | Jul 2, 2026 | Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions. | ||
| CVE-2025-58902 | Hig | 0.00 | 8.1 | 0.00 | Jul 2, 2026 | Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions. | ||
| CVE-2026-12923 | Hig | 0.00 | 7.5 | 0.00 | Jul 1, 2026 | The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3. This is due to insufficient validation of the 'path' parameter in the emd_delete_file() AJAX handler in includes/common-functions.php. The user-supplied… | ||
| CVE-2026-57647 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions. | ||
| CVE-2025-68064 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions. | ||
| CVE-2025-68063 | Hig | 0.00 | 7.5 | 0.00 | Jun 26, 2026 | Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions. | ||
| CVE-2026-54845 | Hig | 0.00 | 8.1 | 0.00 | Jun 25, 2026 | Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions. | ||
| CVE-2026-54814 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109. | ||
| CVE-2026-39590 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions. | ||
| CVE-2026-39559 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions. | ||
| CVE-2026-39523 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions. | ||
| CVE-2025-69175 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions. | ||
| CVE-2025-69174 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Etude <= 1.6 versions. |
- risk 0.00cvss 6.6epss 0.01
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.12.7 via the 'logKey' parameter parameter. This makes it possible for authenticated attackers,…
- risk 0.00cvss —epss 0.00
PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations.
- risk 0.00cvss 4.3epss 0.00
The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.7 This is due to insufficient path validation on the 'template' parameter in the render_templates AJAX endpoint, which is used directly in a…
- risk 0.00cvss 7.5epss 0.00
Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.
- risk 0.00cvss 7.5epss 0.00
Contributor Local File Inclusion in Shopify <= 1.0.0 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.
- risk 0.00cvss 7.5epss 0.00
Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.
- risk 0.00cvss 7.5epss 0.00
The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3. This is due to insufficient validation of the 'path' parameter in the emd_delete_file() AJAX handler in includes/common-functions.php. The user-supplied…
- risk 0.00cvss 7.5epss 0.00
Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions.
- risk 0.00cvss 7.5epss 0.00
Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.
- risk 0.00cvss 7.5epss 0.00
Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.
- risk 0.00cvss 8.1epss 0.00
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Etude <= 1.6 versions.