Skip to content
Noroxi

CWE-98 · 1,293 records

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

CVEs in this class

1,293 records

  • A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper

    HighCVSS 8.8KEVWeaponizedEPSS 49%

    synacor · zimbra collaboration suiteDec 22, 2025

  • CVE-2026-87902
    69This week

    An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the

    HighCVSS 8.1KEVWeaponizedEPSS 22%

    wordpress · wordpressSep 22, 2026

  • Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion

    CriticalCVSS 9.8Proof of conceptEPSS 57%

    getshieldsecurity · shield securityFeb 5, 2024

  • Local File Inclusion (RCE) in Cacti

    HighCVSS 8.8WeaponizedEPSS 64%

    cacti · cactiDec 21, 2023

  • Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability

    HighCVSS 8.1No exploitEPSS 72%

    zen-cart · zen cartAug 21, 2024

  • wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contents

    HighCVSS 8.8No exploitEPSS 61%

    gvectors · wpforo forumJun 9, 2023

  • Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusion

    CriticalCVSS 9.8Proof of conceptEPSS 43%

    scripteo · ads proJul 2, 2025

  • PHP Remote File Inclusion in flatpressblog/flatpress

    CriticalCVSS 9.8No exploitEPSS 35%

    flatpress · flatpressDec 18, 2022

  • Local File Inclusion in parisneo/lollms-webui

    CriticalCVSS 9.3No exploitEPSS 33%

    lollms · lollms web uiApr 10, 2024

  • WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion

    CriticalCVSS 9.8Proof of conceptEPSS 23%

    wphealth · wp umbrella: update backup restore & monitoringDec 8, 2024

  • Prodigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name]

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    prodigycommerce · prodigy commerceFeb 19, 2026

  • Canto <= 3.0.4 - Unauthenticated Remote File Inclusion

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    canto · cantoAug 11, 2023

  • MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    stylemixthemes · masterstudy lmsApr 9, 2024

  • WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion

    CriticalCVSS 10.0WeaponizedEPSS 2%

    advanced custom fields · wordpress pluginAug 5, 2025

  • Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    ays-pro · chartifyNov 14, 2024

  • News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusion

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    infornweb · news \& blog designer packNov 22, 2023

  • A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).

    CriticalCVSS 9.8No exploitEPSS 4%

    advantech · r-seenetJul 16, 2021

  • A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x bef

    CriticalCVSS 9.8No exploitEPSS 4%

    honeywell · experion process knowledge systemApr 8, 2019

  • WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    whmpress · whmcsFeb 28, 2025

  • Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    p-themes · portoMay 14, 2024

  • A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file

    CriticalCVSS 9.8No exploitEPSS 3%

    simple college website project · simple college websiteSep 22, 2022

  • WordPress BeeTeam368 Extensions Plugin <= 1.9.4 - Local File Inclusion Vulnerability

    CriticalCVSS 10.0No exploitEPSS 1%

    beeteam368 · beeteam368 extensionsAug 14, 2025

  • CVE-2024-2411
    39Monitor

    MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal

    CriticalCVSS 9.8No exploitEPSS 2%

    stylemixthemes · masterstudy lmsMar 29, 2024

  • News and Blog Designer Bundle <= 1.1 - Unauthenticated Local File Inclusion

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    vaghasia3 · news and blog designer bundleJan 14, 2026

  • CVE-2022-4446
    39Monitor

    PHP Remote File Inclusion in tsolucio/corebos

    CriticalCVSS 9.8No exploitEPSS 1%

    corebos · corebosDec 13, 2022

All vulnerability classes