VYPR

CWE-98

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

VariantDraftLikelihood: High

Description

The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.

In certain versions and configurations of PHP, this can allow an attacker to specify a URL to a remote location from which the product will obtain the code to execute. In other cases in association with path traversal, the attacker can specify a local file that may contain executable statements that can be parsed by PHP.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-193

CVEs mapped to this weakness (1,304)

page 64 of 66
  • CVE-2026-57793HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Flow flow allows PHP Local File Inclusion.This issue affects Flow: from n/a through <= 1.8.

  • CVE-2026-57792HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through <= 2.4.1.

  • CVE-2026-57791HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This issue affects Brook: from n/a through <= 2.9.0.

  • CVE-2026-57790HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.This issue affects Billey: from n/a through <= 2.1.8.

  • CVE-2026-57789HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PHP Local File Inclusion.This issue affects Aqua: from n/a through <= 5.1.2.

  • CVE-2026-57788HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Aalto aalto allows PHP Local File Inclusion.This issue affects Aalto: from n/a through <= 1.8.

  • CVE-2026-57743HigJul 13, 2026
    risk 0.00cvss 8.1epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP Local File Inclusion.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

  • CVE-2026-15540MedJul 13, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename…

  • CVE-2026-15338HigJul 11, 2026
    risk 0.00cvss 7.5epss 0.01

    The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to…

  • CVE-2025-11977MedJul 10, 2026
    risk 0.00cvss 6.6epss 0.01

    The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.26.12 via the happyforms_get_form_partial() function. This makes it…

  • CVE-2026-13080MedJul 9, 2026
    risk 0.00cvss 6.6epss 0.01

    The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.12.7 via the 'logKey' parameter parameter. This makes it possible for authenticated attackers,…

  • CVE-2026-12194LowJul 4, 2026
    risk 0.00cvss —epss 0.00

    PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations.

  • CVE-2026-5137MedJul 3, 2026
    risk 0.00cvss 4.3epss 0.00

    The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.7 This is due to insufficient path validation on the 'template' parameter in the render_templates AJAX endpoint, which is used directly in a…

  • CVE-2026-57749HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.

  • CVE-2026-57748HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    Contributor Local File Inclusion in Shopify <= 1.0.0 versions.

  • CVE-2026-42382HigJul 2, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.

  • CVE-2026-27412HigJul 2, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.

  • CVE-2025-69133HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.

  • CVE-2025-58902HigJul 2, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.

  • CVE-2026-12923HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.01

    The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3. This is due to insufficient validation of the 'path' parameter in the emd_delete_file() AJAX handler in includes/common-functions.php. The user-supplied…