Vulnerabilities (CVE)

Filtered by CWE-98
Total 1258 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-51057 1 Vedo Suite Project 1 Vedo Suite 2026-07-05 N/A 6.5 MEDIUM
A local file inclusion (LFI) vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'readfile()' function call in '/api_vedo/video/preview'.
CVE-2026-27412 2026-07-02 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.
CVE-2026-57748 2026-07-02 N/A 7.5 HIGH
Contributor Local File Inclusion in Shopify <= 1.0.0 versions.
CVE-2025-69133 2026-07-02 N/A 7.5 HIGH
Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
CVE-2025-58902 2026-07-02 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.
CVE-2026-42382 2026-07-02 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.
CVE-2026-57749 2026-07-02 N/A 7.5 HIGH
Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.
CVE-2026-12923 2026-07-01 N/A 7.5 HIGH
The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3. This is due to insufficient validation of the 'path' parameter in the emd_delete_file() AJAX handler in includes/common-functions.php. The user-supplied value is passed through sanitize_text_field(), has its trailing '_PLUGIN_DIR' substring stripped, and is then invoked as a PHP function name with no arguments via `$sess_name()`. The handler is gated only by a nonce — no current_user_can() check is present — and the nonce is emitted on any front-end page that renders a form shortcode containing file fields. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke arbitrary zero-argument PHP functions (such as phpinfo, phpversion, get_defined_vars, error_get_last), resulting in sensitive information disclosure and potential further compromise depending on the functions available in the environment.
CVE-2025-68063 2026-06-26 N/A 7.5 HIGH
Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions.
CVE-2026-57647 2026-06-26 N/A 7.5 HIGH
Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions.
CVE-2025-68064 2026-06-26 N/A 7.5 HIGH
Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.
CVE-2026-54845 2026-06-26 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.
CVE-2026-48820 2026-06-23 N/A N/A
CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11.
CVE-2026-7515 2026-06-22 N/A 9.8 CRITICAL
The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
CVE-2019-25760 2026-06-22 N/A 6.2 MEDIUM
Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task set to ajax.loadImage, and a base64-encoded file path in the file parameter to retrieve sensitive files like configuration.php and system files.
CVE-2026-40721 2026-06-17 N/A 7.5 HIGH
Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions.
CVE-2026-39590 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.
CVE-2026-39582 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions.
CVE-2026-22338 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in EcoBlue <= 1.15 versions.
CVE-2026-22330 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Right Way <= 4.0 versions.