Перейти к содержимому
Noroxi

CWE-98 · 1 293 записей

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

CVE этого класса

1 293 записей

  • CVE-2025-68645
    80Срочно

    A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 49 %

    synacor · zimbra collaboration suite22 дек. 2025 г.

  • CVE-2026-87902
    69На этой неделе

    An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the

    ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 22 %

    wordpress · wordpress22 сент. 2026 г.

  • CVE-2023-6989
    56В плане

    Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion

    КритическаяCVSS 9,8Proof of conceptEPSS 57 %

    getshieldsecurity · shield security5 февр. 2024 г.

  • CVE-2023-49084
    54В плане

    Local File Inclusion (RCE) in Cacti

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 64 %

    cacti · cacti21 дек. 2023 г.

  • CVE-2024-5762
    53В плане

    Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability

    ВысокаяCVSS 8,1Эксплойта нетEPSS 72 %

    zen-cart · zen cart21 авг. 2024 г.

  • CVE-2023-2249
    53В плане

    wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contents

    ВысокаяCVSS 8,8Эксплойта нетEPSS 61 %

    gvectors · wpforo forum9 июн. 2023 г.

  • CVE-2025-4380
    52В плане

    Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusion

    КритическаяCVSS 9,8Proof of conceptEPSS 43 %

    scripteo · ads pro2 июл. 2025 г.

  • CVE-2022-4606
    50В плане

    PHP Remote File Inclusion in flatpressblog/flatpress

    КритическаяCVSS 9,8Эксплойта нетEPSS 35 %

    flatpress · flatpress18 дек. 2022 г.

  • CVE-2024-1600
    47В плане

    Local File Inclusion in parisneo/lollms-webui

    КритическаяCVSS 9,3Эксплойта нетEPSS 33 %

    lollms · lollms web ui10 апр. 2024 г.

  • CVE-2024-12209
    46В плане

    WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion

    КритическаяCVSS 9,8Proof of conceptEPSS 23 %

    wphealth · wp umbrella: update backup restore & monitoring8 дек. 2024 г.

  • CVE-2026-0926
    42В плане

    Prodigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name]

    КритическаяCVSS 9,8Proof of conceptEPSS 9 %

    prodigycommerce · prodigy commerce19 февр. 2026 г.

  • CVE-2023-3452
    41В плане

    Canto <= 3.0.4 - Unauthenticated Remote File Inclusion

    КритическаяCVSS 9,8Proof of conceptEPSS 7 %

    canto · canto11 авг. 2023 г.

  • CVE-2024-3136
    41В плане

    MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    stylemixthemes · masterstudy lms9 апр. 2024 г.

  • CVE-2012-10025
    41В плане

    WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion

    КритическаяCVSS 10,0Готовый эксплойтEPSS 2 %

    advanced custom fields · wordpress plugin5 авг. 2025 г.

  • CVE-2024-10571
    40В плане

    Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    ays-pro · chartify14 нояб. 2024 г.

  • CVE-2023-5815
    40В плане

    News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusion

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    infornweb · news \& blog designer pack22 нояб. 2023 г.

  • CVE-2021-21804
    40В плане

    A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    advantech · r-seenet16 июл. 2021 г.

  • CVE-2014-9186
    40В плане

    A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x bef

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    honeywell · experion process knowledge system8 апр. 2019 г.

  • CVE-2024-9193
    40В плане

    WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update

    КритическаяCVSS 9,8Proof of conceptEPSS 3 %

    whmpress · whmcs28 февр. 2025 г.

  • CVE-2024-3806
    40В плане

    Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts

    КритическаяCVSS 9,8Proof of conceptEPSS 3 %

    p-themes · porto14 мая 2024 г.

  • CVE-2022-40089
    40В плане

    A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    simple college website project · simple college website22 сент. 2022 г.

  • CVE-2025-25174
    40В плане

    WordPress BeeTeam368 Extensions Plugin <= 1.9.4 - Local File Inclusion Vulnerability

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    beeteam368 · beeteam368 extensions14 авг. 2025 г.

  • CVE-2024-2411
    39Наблюдать

    MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    stylemixthemes · masterstudy lms29 мар. 2024 г.

  • CVE-2025-14502
    39Наблюдать

    News and Blog Designer Bundle <= 1.1 - Unauthenticated Local File Inclusion

    КритическаяCVSS 9,8Proof of conceptEPSS 2 %

    vaghasia3 · news and blog designer bundle14 янв. 2026 г.

  • CVE-2022-4446
    39Наблюдать

    PHP Remote File Inclusion in tsolucio/corebos

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    corebos · corebos13 дек. 2022 г.

Все классы уязвимостей