İçeriğe atla
Noroxi

CWE-98 · 1.293 kayıt

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Bu sınıftaki CVE’ler

1.293 kayıt

  • A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %49

    synacor · zimbra collaboration suite22 Ara 2025

  • CVE-2026-87902
    69Bu hafta

    An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %22

    wordpress · wordpress22 Eyl 2026

  • CVE-2023-6989
    56Planlayın

    Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion

    KritikCVSS 9,8Kavram kanıtıEPSS %57

    getshieldsecurity · shield security5 Şub 2024

  • CVE-2023-49084
    54Planlayın

    Local File Inclusion (RCE) in Cacti

    YüksekCVSS 8,8SilahlaştırılmışEPSS %64

    cacti · cacti21 Ara 2023

  • CVE-2024-5762
    53Planlayın

    Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability

    YüksekCVSS 8,1İstismar yokEPSS %72

    zen-cart · zen cart21 Ağu 2024

  • CVE-2023-2249
    53Planlayın

    wpForo Forum <= 2.1.7 - Authenticated (Subscriber+) Local File Include, Server-Side Request Forgery, and PHAR Deserialization via file_get_contents

    YüksekCVSS 8,8İstismar yokEPSS %61

    gvectors · wpforo forum9 Haz 2023

  • CVE-2025-4380
    52Planlayın

    Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.89 - Unauthenticated Local File Inclusion

    KritikCVSS 9,8Kavram kanıtıEPSS %43

    scripteo · ads pro2 Tem 2025

  • CVE-2022-4606
    50Planlayın

    PHP Remote File Inclusion in flatpressblog/flatpress

    KritikCVSS 9,8İstismar yokEPSS %35

    flatpress · flatpress18 Ara 2022

  • CVE-2024-1600
    47Planlayın

    Local File Inclusion in parisneo/lollms-webui

    KritikCVSS 9,3İstismar yokEPSS %33

    lollms · lollms web ui10 Nis 2024

  • CVE-2024-12209
    46Planlayın

    WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion

    KritikCVSS 9,8Kavram kanıtıEPSS %23

    wphealth · wp umbrella: update backup restore & monitoring8 Ara 2024

  • CVE-2026-0926
    42Planlayın

    Prodigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name]

    KritikCVSS 9,8Kavram kanıtıEPSS %9

    prodigycommerce · prodigy commerce19 Şub 2026

  • CVE-2023-3452
    41Planlayın

    Canto <= 3.0.4 - Unauthenticated Remote File Inclusion

    KritikCVSS 9,8Kavram kanıtıEPSS %7

    canto · canto11 Ağu 2023

  • CVE-2024-3136
    41Planlayın

    MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via template

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    stylemixthemes · masterstudy lms9 Nis 2024

  • CVE-2012-10025
    41Planlayın

    WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion

    KritikCVSS 10,0SilahlaştırılmışEPSS %2

    advanced custom fields · wordpress plugin5 Ağu 2025

  • CVE-2024-10571
    40Planlayın

    Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    ays-pro · chartify14 Kas 2024

  • CVE-2023-5815
    40Planlayın

    News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Remote Code Execution via Local File Inclusion

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    infornweb · news \& blog designer pack22 Kas 2023

  • CVE-2021-21804
    40Planlayın

    A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020).

    KritikCVSS 9,8İstismar yokEPSS %4

    advantech · r-seenet16 Tem 2021

  • CVE-2014-9186
    40Planlayın

    A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x bef

    KritikCVSS 9,8İstismar yokEPSS %4

    honeywell · experion process knowledge system8 Nis 2019

  • CVE-2024-9193
    40Planlayın

    WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    whmpress · whmcs28 Şub 2025

  • CVE-2024-3806
    40Planlayın

    Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    p-themes · porto14 May 2024

  • CVE-2022-40089
    40Planlayın

    A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file

    KritikCVSS 9,8İstismar yokEPSS %3

    simple college website project · simple college website22 Eyl 2022

  • CVE-2025-25174
    40Planlayın

    WordPress BeeTeam368 Extensions Plugin <= 1.9.4 - Local File Inclusion Vulnerability

    KritikCVSS 10,0İstismar yokEPSS %1

    beeteam368 · beeteam368 extensions14 Ağu 2025

  • CVE-2024-2411
    39İzleyin

    MasterStudy LMS <= 3.3.0 - Unauthenticated Local File Inclusion via modal

    KritikCVSS 9,8İstismar yokEPSS %2

    stylemixthemes · masterstudy lms29 Mar 2024

  • CVE-2025-14502
    39İzleyin

    News and Blog Designer Bundle <= 1.1 - Unauthenticated Local File Inclusion

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    vaghasia3 · news and blog designer bundle14 Oca 2026

  • CVE-2022-4446
    39İzleyin

    PHP Remote File Inclusion in tsolucio/corebos

    KritikCVSS 9,8İstismar yokEPSS %1

    corebos · corebos13 Ara 2022

Tüm zafiyet sınıfları