CWE-98 · 1.293 kayıt
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Bu sınıftaki CVE’ler
1.293 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
80Hemen | CVE-2025-68645Silahlaştırılmış | A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper synacor · zimbra collaboration suite · CWE-98 | Yüksek8,8 | KEV | %48,9 | 22 Ara 2025 |
69Bu hafta | CVE-2026-87902Silahlaştırılmış | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the wordpress · wordpress · CWE-98 | Yüksek8,1 | KEV | %22,5 | 22 Eyl 2026 |
56Planlayın | CVE-2023-6989Kavram kanıtı | Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusiongetshieldsecurity · shield security · CWE-98 | Kritik9,8 | — | %56,6 | 5 Şub 2024 |
54Planlayın | CVE-2023-49084Silahlaştırılmış | Local File Inclusion (RCE) in Cacticacti · cacti · CWE-98 | Yüksek8,8 | — | %64,4 | 21 Ara 2023 |
53Planlayın | CVE-2024-5762İstismar yok | Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerabilityzen-cart · zen cart · CWE-98 | Yüksek8,1 | — | %71,6 | 21 Ağu 2024 |
53Planlayın | CVE-2023-2249İstismar yok | wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contentsgvectors · wpforo forum · CWE-98 | Yüksek8,8 | — | %60,8 | 9 Haz 2023 |
52Planlayın | CVE-2025-4380Kavram kanıtı | Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusionscripteo · ads pro · CWE-98 | Kritik9,8 | — | %42,8 | 2 Tem 2025 |
50Planlayın | CVE-2022-4606İstismar yok | PHP Remote File Inclusion in flatpressblog/flatpressflatpress · flatpress · CWE-98 | Kritik9,8 | — | %35,4 | 18 Ara 2022 |
47Planlayın | CVE-2024-1600İstismar yok | Local File Inclusion in parisneo/lollms-webuilollms · lollms web ui · CWE-98 | Kritik9,3 | — | %32,5 | 10 Nis 2024 |
46Planlayın | CVE-2024-12209Kavram kanıtı | WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusionwphealth · wp umbrella: update backup restore & monitoring · CWE-98 | Kritik9,8 | — | %23,2 | 8 Ara 2024 |
42Planlayın | CVE-2026-0926Kavram kanıtı | Prodigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name]prodigycommerce · prodigy commerce · CWE-98 | Kritik9,8 | — | %9,4 | 19 Şub 2026 |
41Planlayın | CVE-2023-3452Kavram kanıtı | Canto <= 3.0.4 - Unauthenticated Remote File Inclusioncanto · canto · CWE-98 | Kritik9,8 | — | %7,0 | 11 Ağu 2023 |
41Planlayın | CVE-2024-3136Kavram kanıtı | MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via templatestylemixthemes · masterstudy lms · CWE-98 | Kritik9,8 | — | %5,0 | 9 Nis 2024 |
41Planlayın | CVE-2012-10025Silahlaştırılmış | WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusionadvanced custom fields · wordpress plugin · CWE-98 | Kritik10,0 | — | %1,8 | 5 Ağu 2025 |
40Planlayın | CVE-2024-10571Kavram kanıtı | Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via sourceays-pro · chartify · CWE-98 | Kritik9,8 | — | %4,8 | 14 Kas 2024 |
40Planlayın | CVE-2023-5815Kavram kanıtı | News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusioninfornweb · news \& blog designer pack · CWE-98 | Kritik9,8 | — | %4,3 | 22 Kas 2023 |
40Planlayın | CVE-2021-21804İstismar yok | A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).advantech · r-seenet · CWE-98 | Kritik9,8 | — | %3,7 | 16 Tem 2021 |
40Planlayın | CVE-2014-9186İstismar yok | A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x befhoneywell · experion process knowledge system · CWE-98 | Kritik9,8 | — | %3,7 | 8 Nis 2019 |
40Planlayın | CVE-2024-9193Kavram kanıtı | WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Updatewhmpress · whmcs · CWE-98 | Kritik9,8 | — | %3,3 | 28 Şub 2025 |
40Planlayın | CVE-2024-3806Kavram kanıtı | Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_postsp-themes · porto · CWE-98 | Kritik9,8 | — | %2,7 | 14 May 2024 |
40Planlayın | CVE-2022-40089İstismar yok | A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP filesimple college website project · simple college website · CWE-98 | Kritik9,8 | — | %2,7 | 22 Eyl 2022 |
40Planlayın | CVE-2025-25174İstismar yok | WordPress BeeTeam368 Extensions Plugin <= 1.9.4 - Local File Inclusion Vulnerabilitybeeteam368 · beeteam368 extensions · CWE-98 | Kritik10,0 | — | %0,5 | 14 Ağu 2025 |
39İzleyin | CVE-2024-2411İstismar yok | MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modalstylemixthemes · masterstudy lms · CWE-98 | Kritik9,8 | — | %1,5 | 29 Mar 2024 |
39İzleyin | CVE-2025-14502Kavram kanıtı | News and Blog Designer Bundle <= 1.1 - Unauthenticated Local File Inclusionvaghasia3 · news and blog designer bundle · CWE-98 | Kritik9,8 | — | %1,5 | 14 Oca 2026 |
39İzleyin | CVE-2022-4446İstismar yok | PHP Remote File Inclusion in tsolucio/coreboscorebos · corebos · CWE-98 | Kritik9,8 | — | %1,3 | 13 Ara 2022 |
- CVE-2025-6864580Hemen
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %49synacor · zimbra collaboration suite22 Ara 2025
- CVE-2026-8790269Bu hafta
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %22wordpress · wordpress22 Eyl 2026
- CVE-2023-698956Planlayın
Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion
KritikCVSS 9,8Kavram kanıtıEPSS %57getshieldsecurity · shield security5 Şub 2024
- CVE-2023-4908454Planlayın
Local File Inclusion (RCE) in Cacti
YüksekCVSS 8,8SilahlaştırılmışEPSS %64cacti · cacti21 Ara 2023
- CVE-2024-576253Planlayın
Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability
YüksekCVSS 8,1İstismar yokEPSS %72zen-cart · zen cart21 Ağu 2024
- CVE-2023-224953Planlayın
wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contents
YüksekCVSS 8,8İstismar yokEPSS %61gvectors · wpforo forum9 Haz 2023
- CVE-2025-438052Planlayın
Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusion
KritikCVSS 9,8Kavram kanıtıEPSS %43scripteo · ads pro2 Tem 2025
- CVE-2022-460650Planlayın
PHP Remote File Inclusion in flatpressblog/flatpress
KritikCVSS 9,8İstismar yokEPSS %35flatpress · flatpress18 Ara 2022
- CVE-2024-160047Planlayın
Local File Inclusion in parisneo/lollms-webui
KritikCVSS 9,3İstismar yokEPSS %33lollms · lollms web ui10 Nis 2024
- CVE-2024-1220946Planlayın
WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
KritikCVSS 9,8Kavram kanıtıEPSS %23wphealth · wp umbrella: update backup restore & monitoring8 Ara 2024
- CVE-2026-092642Planlayın
Prodigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name]
KritikCVSS 9,8Kavram kanıtıEPSS %9prodigycommerce · prodigy commerce19 Şub 2026
- CVE-2023-345241Planlayın
Canto <= 3.0.4 - Unauthenticated Remote File Inclusion
KritikCVSS 9,8Kavram kanıtıEPSS %7canto · canto11 Ağu 2023
- CVE-2024-313641Planlayın
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template
KritikCVSS 9,8Kavram kanıtıEPSS %5stylemixthemes · masterstudy lms9 Nis 2024
- CVE-2012-1002541Planlayın
WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion
KritikCVSS 10,0SilahlaştırılmışEPSS %2advanced custom fields · wordpress plugin5 Ağu 2025
- CVE-2024-1057140Planlayın
Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source
KritikCVSS 9,8Kavram kanıtıEPSS %5ays-pro · chartify14 Kas 2024
- CVE-2023-581540Planlayın
News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusion
KritikCVSS 9,8Kavram kanıtıEPSS %4infornweb · news \& blog designer pack22 Kas 2023
- CVE-2021-2180440Planlayın
A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).
KritikCVSS 9,8İstismar yokEPSS %4advantech · r-seenet16 Tem 2021
- CVE-2014-918640Planlayın
A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x bef
KritikCVSS 9,8İstismar yokEPSS %4honeywell · experion process knowledge system8 Nis 2019
- CVE-2024-919340Planlayın
WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update
KritikCVSS 9,8Kavram kanıtıEPSS %3whmpress · whmcs28 Şub 2025
- CVE-2024-380640Planlayın
Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts
KritikCVSS 9,8Kavram kanıtıEPSS %3p-themes · porto14 May 2024
- CVE-2022-4008940Planlayın
A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file
KritikCVSS 9,8İstismar yokEPSS %3simple college website project · simple college website22 Eyl 2022
- CVE-2025-2517440Planlayın
WordPress BeeTeam368 Extensions Plugin <= 1.9.4 - Local File Inclusion Vulnerability
KritikCVSS 10,0İstismar yokEPSS %1beeteam368 · beeteam368 extensions14 Ağu 2025
- CVE-2024-241139İzleyin
MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal
KritikCVSS 9,8İstismar yokEPSS %2stylemixthemes · masterstudy lms29 Mar 2024
- CVE-2025-1450239İzleyin
News and Blog Designer Bundle <= 1.1 - Unauthenticated Local File Inclusion
KritikCVSS 9,8Kavram kanıtıEPSS %2vaghasia3 · news and blog designer bundle14 Oca 2026
- CVE-2022-444639İzleyin
PHP Remote File Inclusion in tsolucio/corebos
KritikCVSS 9,8İstismar yokEPSS %1corebos · corebos13 Ara 2022