CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Description
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-193
CVEs mapped to this weakness (1,304)
page 66 of 66| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-69106 | Hig | 0.00 | 8.1 | 0.00 | Jun 17, 2026 | Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions. | ||
| CVE-2026-25548 | Cri | 0.00 | 9.1 | 0.01 | Feb 18, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7.0 through a chained Local File Inclusion (LFI) and Log Poisoning attack. An authenticated… | ||
| CVE-2023-2551 | Hig | 0.00 | 8.8 | 0.02 | May 5, 2023 | PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1. | ||
| CVE-2022-4446 | Cri | 0.00 | 9.8 | 0.01 | Dec 13, 2022 | PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0. |
- risk 0.00cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.
- risk 0.00cvss 9.1epss 0.01
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7.0 through a chained Local File Inclusion (LFI) and Log Poisoning attack. An authenticated…
- risk 0.00cvss 8.8epss 0.02
PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.
- risk 0.00cvss 9.8epss 0.01
PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.