CWE-98 · 1 293 записей
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE этого класса
1 293 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
80Срочно | CVE-2025-68645Готовый эксплойт | A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper synacor · zimbra collaboration suite · CWE-98 | Высокая8,8 | KEV | 48,9 % | 22 дек. 2025 г. |
69На этой неделе | CVE-2026-87902Готовый эксплойт | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the wordpress · wordpress · CWE-98 | Высокая8,1 | KEV | 22,5 % | 22 сент. 2026 г. |
56В плане | CVE-2023-6989Proof of concept | Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusiongetshieldsecurity · shield security · CWE-98 | Критическая9,8 | — | 56,6 % | 5 февр. 2024 г. |
54В плане | CVE-2023-49084Готовый эксплойт | Local File Inclusion (RCE) in Cacticacti · cacti · CWE-98 | Высокая8,8 | — | 64,4 % | 21 дек. 2023 г. |
53В плане | CVE-2024-5762Эксплойта нет | Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerabilityzen-cart · zen cart · CWE-98 | Высокая8,1 | — | 71,6 % | 21 авг. 2024 г. |
53В плане | CVE-2023-2249Эксплойта нет | wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contentsgvectors · wpforo forum · CWE-98 | Высокая8,8 | — | 60,8 % | 9 июн. 2023 г. |
52В плане | CVE-2025-4380Proof of concept | Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusionscripteo · ads pro · CWE-98 | Критическая9,8 | — | 42,8 % | 2 июл. 2025 г. |
50В плане | CVE-2022-4606Эксплойта нет | PHP Remote File Inclusion in flatpressblog/flatpressflatpress · flatpress · CWE-98 | Критическая9,8 | — | 35,4 % | 18 дек. 2022 г. |
47В плане | CVE-2024-1600Эксплойта нет | Local File Inclusion in parisneo/lollms-webuilollms · lollms web ui · CWE-98 | Критическая9,3 | — | 32,5 % | 10 апр. 2024 г. |
46В плане | CVE-2024-12209Proof of concept | WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusionwphealth · wp umbrella: update backup restore & monitoring · CWE-98 | Критическая9,8 | — | 23,2 % | 8 дек. 2024 г. |
42В плане | CVE-2026-0926Proof of concept | Prodigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name]prodigycommerce · prodigy commerce · CWE-98 | Критическая9,8 | — | 9,4 % | 19 февр. 2026 г. |
41В плане | CVE-2023-3452Proof of concept | Canto <= 3.0.4 - Unauthenticated Remote File Inclusioncanto · canto · CWE-98 | Критическая9,8 | — | 7,0 % | 11 авг. 2023 г. |
41В плане | CVE-2024-3136Proof of concept | MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via templatestylemixthemes · masterstudy lms · CWE-98 | Критическая9,8 | — | 5,0 % | 9 апр. 2024 г. |
41В плане | CVE-2012-10025Готовый эксплойт | WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusionadvanced custom fields · wordpress plugin · CWE-98 | Критическая10,0 | — | 1,8 % | 5 авг. 2025 г. |
40В плане | CVE-2024-10571Proof of concept | Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via sourceays-pro · chartify · CWE-98 | Критическая9,8 | — | 4,8 % | 14 нояб. 2024 г. |
40В плане | CVE-2023-5815Proof of concept | News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusioninfornweb · news \& blog designer pack · CWE-98 | Критическая9,8 | — | 4,3 % | 22 нояб. 2023 г. |
40В плане | CVE-2021-21804Эксплойта нет | A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).advantech · r-seenet · CWE-98 | Критическая9,8 | — | 3,7 % | 16 июл. 2021 г. |
40В плане | CVE-2014-9186Эксплойта нет | A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x befhoneywell · experion process knowledge system · CWE-98 | Критическая9,8 | — | 3,7 % | 8 апр. 2019 г. |
40В плане | CVE-2024-9193Proof of concept | WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Updatewhmpress · whmcs · CWE-98 | Критическая9,8 | — | 3,3 % | 28 февр. 2025 г. |
40В плане | CVE-2024-3806Proof of concept | Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_postsp-themes · porto · CWE-98 | Критическая9,8 | — | 2,7 % | 14 мая 2024 г. |
40В плане | CVE-2022-40089Эксплойта нет | A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP filesimple college website project · simple college website · CWE-98 | Критическая9,8 | — | 2,7 % | 22 сент. 2022 г. |
40В плане | CVE-2025-25174Эксплойта нет | WordPress BeeTeam368 Extensions Plugin <= 1.9.4 - Local File Inclusion Vulnerabilitybeeteam368 · beeteam368 extensions · CWE-98 | Критическая10,0 | — | 0,5 % | 14 авг. 2025 г. |
39Наблюдать | CVE-2024-2411Эксплойта нет | MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modalstylemixthemes · masterstudy lms · CWE-98 | Критическая9,8 | — | 1,5 % | 29 мар. 2024 г. |
39Наблюдать | CVE-2025-14502Proof of concept | News and Blog Designer Bundle <= 1.1 - Unauthenticated Local File Inclusionvaghasia3 · news and blog designer bundle · CWE-98 | Критическая9,8 | — | 1,5 % | 14 янв. 2026 г. |
39Наблюдать | CVE-2022-4446Эксплойта нет | PHP Remote File Inclusion in tsolucio/coreboscorebos · corebos · CWE-98 | Критическая9,8 | — | 1,3 % | 13 дек. 2022 г. |
- CVE-2025-6864580Срочно
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 49 %synacor · zimbra collaboration suite22 дек. 2025 г.
- CVE-2026-8790269На этой неделе
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 22 %wordpress · wordpress22 сент. 2026 г.
- CVE-2023-698956В плане
Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion
КритическаяCVSS 9,8Proof of conceptEPSS 57 %getshieldsecurity · shield security5 февр. 2024 г.
- CVE-2023-4908454В плане
Local File Inclusion (RCE) in Cacti
ВысокаяCVSS 8,8Готовый эксплойтEPSS 64 %cacti · cacti21 дек. 2023 г.
- CVE-2024-576253В плане
Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability
ВысокаяCVSS 8,1Эксплойта нетEPSS 72 %zen-cart · zen cart21 авг. 2024 г.
- CVE-2023-224953В плане
wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contents
ВысокаяCVSS 8,8Эксплойта нетEPSS 61 %gvectors · wpforo forum9 июн. 2023 г.
- CVE-2025-438052В плане
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusion
КритическаяCVSS 9,8Proof of conceptEPSS 43 %scripteo · ads pro2 июл. 2025 г.
- CVE-2022-460650В плане
PHP Remote File Inclusion in flatpressblog/flatpress
КритическаяCVSS 9,8Эксплойта нетEPSS 35 %flatpress · flatpress18 дек. 2022 г.
- CVE-2024-160047В плане
Local File Inclusion in parisneo/lollms-webui
КритическаяCVSS 9,3Эксплойта нетEPSS 33 %lollms · lollms web ui10 апр. 2024 г.
- CVE-2024-1220946В плане
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
КритическаяCVSS 9,8Proof of conceptEPSS 23 %wphealth · wp umbrella: update backup restore & monitoring8 дек. 2024 г.
- CVE-2026-092642В плане
Prodigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name]
КритическаяCVSS 9,8Proof of conceptEPSS 9 %prodigycommerce · prodigy commerce19 февр. 2026 г.
- CVE-2023-345241В плане
Canto <= 3.0.4 - Unauthenticated Remote File Inclusion
КритическаяCVSS 9,8Proof of conceptEPSS 7 %canto · canto11 авг. 2023 г.
- CVE-2024-313641В плане
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
КритическаяCVSS 9,8Proof of conceptEPSS 5 %stylemixthemes · masterstudy lms9 апр. 2024 г.
- CVE-2012-1002541В плане
WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion
КритическаяCVSS 10,0Готовый эксплойтEPSS 2 %advanced custom fields · wordpress plugin5 авг. 2025 г.
- CVE-2024-1057140В плане
Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source
КритическаяCVSS 9,8Proof of conceptEPSS 5 %ays-pro · chartify14 нояб. 2024 г.
- CVE-2023-581540В плане
News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusion
КритическаяCVSS 9,8Proof of conceptEPSS 4 %infornweb · news \& blog designer pack22 нояб. 2023 г.
- CVE-2021-2180440В плане
A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %advantech · r-seenet16 июл. 2021 г.
- CVE-2014-918640В плане
A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x bef
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %honeywell · experion process knowledge system8 апр. 2019 г.
- CVE-2024-919340В плане
WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update
КритическаяCVSS 9,8Proof of conceptEPSS 3 %whmpress · whmcs28 февр. 2025 г.
- CVE-2024-380640В плане
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
КритическаяCVSS 9,8Proof of conceptEPSS 3 %p-themes · porto14 мая 2024 г.
- CVE-2022-4008940В плане
A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %simple college website project · simple college website22 сент. 2022 г.
- CVE-2025-2517440В плане
WordPress BeeTeam368 Extensions Plugin <= 1.9.4 - Local File Inclusion Vulnerability
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %beeteam368 · beeteam368 extensions14 авг. 2025 г.
- CVE-2024-241139Наблюдать
MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %stylemixthemes · masterstudy lms29 мар. 2024 г.
- CVE-2025-1450239Наблюдать
News and Blog Designer Bundle <= 1.1 - Unauthenticated Local File Inclusion
КритическаяCVSS 9,8Proof of conceptEPSS 2 %vaghasia3 · news and blog designer bundle14 янв. 2026 г.
- CVE-2022-444639Наблюдать
PHP Remote File Inclusion in tsolucio/corebos
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %corebos · corebos13 дек. 2022 г.