VYPR

CWE-98

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

VariantDraftLikelihood: High

Description

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

In certain versions and configurations of PHP, this can allow an attacker to specify a URL to a remote location from which the product will obtain the code to execute. In other cases in association with path traversal, the attacker can specify a local file that may contain executable statements that can be parsed by PHP.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-193

CVEs mapped to this weakness (1,274)

page 63 of 64
  • CVE-2026-13080MedJul 9, 2026
    risk 0.00cvss 6.6epss 0.01

    The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.12.7 via the 'logKey' parameter parameter. This makes it possible for authenticated attackers,…

  • CVE-2026-12194LowJul 4, 2026
    risk 0.00cvss epss 0.00

    PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations.

  • CVE-2026-5137MedJul 3, 2026
    risk 0.00cvss 4.3epss 0.00

    The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.7 This is due to insufficient path validation on the 'template' parameter in the render_templates AJAX endpoint, which is used directly in a…

  • CVE-2026-57749HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.

  • CVE-2026-57748HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    Contributor Local File Inclusion in Shopify <= 1.0.0 versions.

  • CVE-2026-42382HigJul 2, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.

  • CVE-2026-27412HigJul 2, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.

  • CVE-2025-69133HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.

  • CVE-2025-58902HigJul 2, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.

  • CVE-2026-12923HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.00

    The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3. This is due to insufficient validation of the 'path' parameter in the emd_delete_file() AJAX handler in includes/common-functions.php. The user-supplied…

  • CVE-2026-57647HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions.

  • CVE-2025-68064HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

  • CVE-2025-68063HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions.

  • CVE-2026-54845HigJun 25, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.

  • CVE-2026-54814HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.

  • CVE-2026-39590HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.

  • CVE-2026-39559HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.

  • CVE-2026-39523HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.

  • CVE-2025-69175HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.

  • CVE-2025-69174HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Etude <= 1.6 versions.