CWE-98 · 1,293 records
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVEs in this class
1,293 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
80Now | CVE-2025-68645Weaponized | A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper synacor · zimbra collaboration suite · CWE-98 | High8.8 | KEV | 48.9% | Dec 22, 2025 |
69This week | CVE-2026-87902Weaponized | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the wordpress · wordpress · CWE-98 | High8.1 | KEV | 22.5% | Sep 22, 2026 |
56Plan | CVE-2023-6989Proof of concept | Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusiongetshieldsecurity · shield security · CWE-98 | Critical9.8 | — | 56.6% | Feb 5, 2024 |
54Plan | CVE-2023-49084Weaponized | Local File Inclusion (RCE) in Cacticacti · cacti · CWE-98 | High8.8 | — | 64.4% | Dec 21, 2023 |
53Plan | CVE-2024-5762No exploit | Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerabilityzen-cart · zen cart · CWE-98 | High8.1 | — | 71.6% | Aug 21, 2024 |
53Plan | CVE-2023-2249No exploit | wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contentsgvectors · wpforo forum · CWE-98 | High8.8 | — | 60.8% | Jun 9, 2023 |
52Plan | CVE-2025-4380Proof of concept | Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusionscripteo · ads pro · CWE-98 | Critical9.8 | — | 42.8% | Jul 2, 2025 |
50Plan | CVE-2022-4606No exploit | PHP Remote File Inclusion in flatpressblog/flatpressflatpress · flatpress · CWE-98 | Critical9.8 | — | 35.4% | Dec 18, 2022 |
47Plan | CVE-2024-1600No exploit | Local File Inclusion in parisneo/lollms-webuilollms · lollms web ui · CWE-98 | Critical9.3 | — | 32.5% | Apr 10, 2024 |
46Plan | CVE-2024-12209Proof of concept | WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusionwphealth · wp umbrella: update backup restore & monitoring · CWE-98 | Critical9.8 | — | 23.2% | Dec 8, 2024 |
42Plan | CVE-2026-0926Proof of concept | Prodigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name]prodigycommerce · prodigy commerce · CWE-98 | Critical9.8 | — | 9.4% | Feb 19, 2026 |
41Plan | CVE-2023-3452Proof of concept | Canto <= 3.0.4 - Unauthenticated Remote File Inclusioncanto · canto · CWE-98 | Critical9.8 | — | 7.0% | Aug 11, 2023 |
41Plan | CVE-2024-3136Proof of concept | MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via templatestylemixthemes · masterstudy lms · CWE-98 | Critical9.8 | — | 5.0% | Apr 9, 2024 |
41Plan | CVE-2012-10025Weaponized | WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusionadvanced custom fields · wordpress plugin · CWE-98 | Critical10.0 | — | 1.8% | Aug 5, 2025 |
40Plan | CVE-2024-10571Proof of concept | Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via sourceays-pro · chartify · CWE-98 | Critical9.8 | — | 4.8% | Nov 14, 2024 |
40Plan | CVE-2023-5815Proof of concept | News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusioninfornweb · news \& blog designer pack · CWE-98 | Critical9.8 | — | 4.3% | Nov 22, 2023 |
40Plan | CVE-2021-21804No exploit | A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).advantech · r-seenet · CWE-98 | Critical9.8 | — | 3.7% | Jul 16, 2021 |
40Plan | CVE-2014-9186No exploit | A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x befhoneywell · experion process knowledge system · CWE-98 | Critical9.8 | — | 3.7% | Apr 8, 2019 |
40Plan | CVE-2024-9193Proof of concept | WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Updatewhmpress · whmcs · CWE-98 | Critical9.8 | — | 3.3% | Feb 28, 2025 |
40Plan | CVE-2024-3806Proof of concept | Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_postsp-themes · porto · CWE-98 | Critical9.8 | — | 2.7% | May 14, 2024 |
40Plan | CVE-2022-40089No exploit | A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP filesimple college website project · simple college website · CWE-98 | Critical9.8 | — | 2.7% | Sep 22, 2022 |
40Plan | CVE-2025-25174No exploit | WordPress BeeTeam368 Extensions Plugin <= 1.9.4 - Local File Inclusion Vulnerabilitybeeteam368 · beeteam368 extensions · CWE-98 | Critical10.0 | — | 0.5% | Aug 14, 2025 |
39Monitor | CVE-2024-2411No exploit | MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modalstylemixthemes · masterstudy lms · CWE-98 | Critical9.8 | — | 1.5% | Mar 29, 2024 |
39Monitor | CVE-2025-14502Proof of concept | News and Blog Designer Bundle <= 1.1 - Unauthenticated Local File Inclusionvaghasia3 · news and blog designer bundle · CWE-98 | Critical9.8 | — | 1.5% | Jan 14, 2026 |
39Monitor | CVE-2022-4446No exploit | PHP Remote File Inclusion in tsolucio/coreboscorebos · corebos · CWE-98 | Critical9.8 | — | 1.3% | Dec 13, 2022 |
- CVE-2025-6864580Now
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper
HighCVSS 8.8KEVWeaponizedEPSS 49%synacor · zimbra collaboration suiteDec 22, 2025
- CVE-2026-8790269This week
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the
HighCVSS 8.1KEVWeaponizedEPSS 22%wordpress · wordpressSep 22, 2026
- CVE-2023-698956Plan
Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion
CriticalCVSS 9.8Proof of conceptEPSS 57%getshieldsecurity · shield securityFeb 5, 2024
- CVE-2023-4908454Plan
Local File Inclusion (RCE) in Cacti
HighCVSS 8.8WeaponizedEPSS 64%cacti · cactiDec 21, 2023
- CVE-2024-576253Plan
Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability
HighCVSS 8.1No exploitEPSS 72%zen-cart · zen cartAug 21, 2024
- CVE-2023-224953Plan
wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contents
HighCVSS 8.8No exploitEPSS 61%gvectors · wpforo forumJun 9, 2023
- CVE-2025-438052Plan
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusion
CriticalCVSS 9.8Proof of conceptEPSS 43%scripteo · ads proJul 2, 2025
- CVE-2022-460650Plan
PHP Remote File Inclusion in flatpressblog/flatpress
CriticalCVSS 9.8No exploitEPSS 35%flatpress · flatpressDec 18, 2022
- CVE-2024-160047Plan
Local File Inclusion in parisneo/lollms-webui
CriticalCVSS 9.3No exploitEPSS 33%lollms · lollms web uiApr 10, 2024
- CVE-2024-1220946Plan
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
CriticalCVSS 9.8Proof of conceptEPSS 23%wphealth · wp umbrella: update backup restore & monitoringDec 8, 2024
- CVE-2026-092642Plan
Prodigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name]
CriticalCVSS 9.8Proof of conceptEPSS 9%prodigycommerce · prodigy commerceFeb 19, 2026
- CVE-2023-345241Plan
Canto <= 3.0.4 - Unauthenticated Remote File Inclusion
CriticalCVSS 9.8Proof of conceptEPSS 7%canto · cantoAug 11, 2023
- CVE-2024-313641Plan
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
CriticalCVSS 9.8Proof of conceptEPSS 5%stylemixthemes · masterstudy lmsApr 9, 2024
- CVE-2012-1002541Plan
WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion
CriticalCVSS 10.0WeaponizedEPSS 2%advanced custom fields · wordpress pluginAug 5, 2025
- CVE-2024-1057140Plan
Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source
CriticalCVSS 9.8Proof of conceptEPSS 5%ays-pro · chartifyNov 14, 2024
- CVE-2023-581540Plan
News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusion
CriticalCVSS 9.8Proof of conceptEPSS 4%infornweb · news \& blog designer packNov 22, 2023
- CVE-2021-2180440Plan
A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).
CriticalCVSS 9.8No exploitEPSS 4%advantech · r-seenetJul 16, 2021
- CVE-2014-918640Plan
A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x bef
CriticalCVSS 9.8No exploitEPSS 4%honeywell · experion process knowledge systemApr 8, 2019
- CVE-2024-919340Plan
WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update
CriticalCVSS 9.8Proof of conceptEPSS 3%whmpress · whmcsFeb 28, 2025
- CVE-2024-380640Plan
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
CriticalCVSS 9.8Proof of conceptEPSS 3%p-themes · portoMay 14, 2024
- CVE-2022-4008940Plan
A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file
CriticalCVSS 9.8No exploitEPSS 3%simple college website project · simple college websiteSep 22, 2022
- CVE-2025-2517440Plan
WordPress BeeTeam368 Extensions Plugin <= 1.9.4 - Local File Inclusion Vulnerability
CriticalCVSS 10.0No exploitEPSS 1%beeteam368 · beeteam368 extensionsAug 14, 2025
- CVE-2024-241139Monitor
MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal
CriticalCVSS 9.8No exploitEPSS 2%stylemixthemes · masterstudy lmsMar 29, 2024
- CVE-2025-1450239Monitor
News and Blog Designer Bundle <= 1.1 - Unauthenticated Local File Inclusion
CriticalCVSS 9.8Proof of conceptEPSS 2%vaghasia3 · news and blog designer bundleJan 14, 2026
- CVE-2022-444639Monitor
PHP Remote File Inclusion in tsolucio/corebos
CriticalCVSS 9.8No exploitEPSS 1%corebos · corebosDec 13, 2022