Total
1258 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-22325 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Promo <= 1.3.0 versions. | |||||
| CVE-2026-39547 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Getaway < 1.8 versions. | |||||
| CVE-2026-39522 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Solene <= 3.4 versions. | |||||
| CVE-2025-69163 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in WineShop <= 3.17 versions. | |||||
| CVE-2026-39537 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions. | |||||
| CVE-2025-69167 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Eros <= 1.3 versions. | |||||
| CVE-2025-69173 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Tipsy <= 1.1 versions. | |||||
| CVE-2025-69165 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Choreo <= 1.6 versions. | |||||
| CVE-2025-69162 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Grecko <= 5.17 versions. | |||||
| CVE-2025-69171 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Orpheus <= 1.3 versions. | |||||
| CVE-2025-69168 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Spike <= 1.2 versions. | |||||
| CVE-2026-34893 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions. | |||||
| CVE-2026-22331 | 2026-06-17 | N/A | 8.1 HIGH | ||
| Unauthenticated Local File Inclusion in AutoParts <= 1.5.8 versions. | |||||
| CVE-2026-9200 | 2026-06-17 | N/A | 7.5 HIGH | ||
| The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2.1 via the shortcode function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. | |||||
| CVE-2026-49954 | 2026-06-17 | N/A | 7.2 HIGH | ||
| Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated administrators to execute arbitrary code by importing a specially crafted plugin configuration containing path traversal sequences in the directory attribute. Attackers can trigger an exception during plugin installation to bypass sanitization routines, causing malicious paths to be stored unsanitized and subsequently passed to include(), which combined with file upload functionality escalates to arbitrary code execution in the context of the web server user. | |||||
| CVE-2026-48972 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SeedProd LLC SeedProd Pro allows PHP Local File Inclusion. This issue affects SeedProd Pro: from n/a before 6.19.5. | |||||
| CVE-2026-41228 | 1 Froxlor | 1 Froxlor | 2026-06-17 | N/A | 9.9 CRITICAL |
| Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated customer can set `def_language` to a path traversal payload (e.g., `../../../../../var/customers/webs/customer1/evil`), which is stored in the database. On subsequent requests, `Language::loadLanguage()` constructs a file path using this value and executes it via `require`, achieving arbitrary PHP code execution as the web server user. Version 2.3.6 fixes the issue. | |||||
| CVE-2026-3826 | 1 Wellchoose | 1 Organization Portal System | 2026-06-17 | N/A | 9.8 CRITICAL |
| IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server. | |||||
| CVE-2026-3425 | 2026-06-17 | N/A | 8.8 HIGH | ||
| The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path' parameter of the 'get_content' AJAX action. This makes it possible for authenticated attackers, with Author-level access and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included. | |||||
| CVE-2026-37266 | 2026-06-17 | N/A | 8.0 HIGH | ||
| An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component | |||||
