Total
1258 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-51057 | 1 Vedo Suite Project | 1 Vedo Suite | 2026-07-05 | N/A | 6.5 MEDIUM |
| A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'readfile()' function call in '/api_vedo/video/preview'. | |||||
| CVE-2026-27412 | 2026-07-02 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions. | |||||
| CVE-2026-57748 | 2026-07-02 | N/A | 7.5 HIGH | ||
| Contributor Local File Inclusion in Shopify <= 1.0.0 versions. | |||||
| CVE-2025-69133 | 2026-07-02 | N/A | 7.5 HIGH | ||
| Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions. | |||||
| CVE-2025-58902 | 2026-07-02 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions. | |||||
| CVE-2026-42382 | 2026-07-02 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Audrey <= 1.5 versions. | |||||
| CVE-2026-57749 | 2026-07-02 | N/A | 7.5 HIGH | ||
| Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions. | |||||
| CVE-2026-12923 | 2026-07-01 | N/A | 7.5 HIGH | ||
| The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3. This is due to insufficient validation of the 'path' parameter in the emd_delete_file() AJAX handler in includes/common-functions.php. The user-supplied value is passed through sanitize_text_field(), has its trailing '_PLUGIN_DIR' substring stripped, and is then invoked as a PHP function name with no arguments via `$sess_name()`. The handler is gated only by a nonce — no current_user_can() check is present — and the nonce is emitted on any front-end page that renders a form shortcode containing file fields. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke arbitrary zero-argument PHP functions (such as phpinfo, phpversion, get_defined_vars, error_get_last), resulting in sensitive information disclosure and potential further compromise depending on the functions available in the environment. | |||||
| CVE-2025-68063 | 2026-06-26 | N/A | 7.5 HIGH | ||
| Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions. | |||||
| CVE-2026-57647 | 2026-06-26 | N/A | 7.5 HIGH | ||
| Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions. | |||||
| CVE-2025-68064 | 2026-06-26 | N/A | 7.5 HIGH | ||
| Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions. | |||||
| CVE-2026-54845 | 2026-06-26 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions. | |||||
| CVE-2026-48820 | 2026-06-23 | N/A | N/A | ||
| CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11. | |||||
| CVE-2026-7515 | 2026-06-22 | N/A | 9.8 CRITICAL | ||
| The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. | |||||
| CVE-2019-25760 | 2026-06-22 | N/A | 6.2 MEDIUM | ||
| Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task set to ajax.loadImage, and a base64-encoded file path in the file parameter to retrieve sensitive files like configuration.php and system files. | |||||
| CVE-2026-40721 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions. | |||||
| CVE-2026-39590 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions. | |||||
| CVE-2026-39582 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions. | |||||
| CVE-2026-22338 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in EcoBlue <= 1.15 versions. | |||||
| CVE-2026-22330 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Right Way <= 4.0 versions. | |||||
