Vulnerabilities (CVE)

Filtered by CWE-98
Total 1258 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-22325 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Promo <= 1.3.0 versions.
CVE-2026-39547 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Getaway < 1.8 versions.
CVE-2026-39522 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Solene <= 3.4 versions.
CVE-2025-69163 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in WineShop <= 3.17 versions.
CVE-2026-39537 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions.
CVE-2025-69167 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Eros <= 1.3 versions.
CVE-2025-69173 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Tipsy <= 1.1 versions.
CVE-2025-69165 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Choreo <= 1.6 versions.
CVE-2025-69162 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Grecko <= 5.17 versions.
CVE-2025-69171 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Orpheus <= 1.3 versions.
CVE-2025-69168 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Spike <= 1.2 versions.
CVE-2026-34893 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions.
CVE-2026-22331 2026-06-17 N/A 8.1 HIGH
Unauthenticated Local File Inclusion in AutoParts <= 1.5.8 versions.
CVE-2026-9200 2026-06-17 N/A 7.5 HIGH
The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2.1 via the shortcode function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
CVE-2026-49954 2026-06-17 N/A 7.2 HIGH
Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated administrators to execute arbitrary code by importing a specially crafted plugin configuration containing path traversal sequences in the directory attribute. Attackers can trigger an exception during plugin installation to bypass sanitization routines, causing malicious paths to be stored unsanitized and subsequently passed to include(), which combined with file upload functionality escalates to arbitrary code execution in the context of the web server user.
CVE-2026-48972 2026-06-17 N/A 7.5 HIGH
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SeedProd LLC SeedProd Pro allows PHP Local File Inclusion. This issue affects SeedProd Pro: from n/a before 6.19.5.
CVE-2026-41228 1 Froxlor 1 Froxlor 2026-06-17 N/A 9.9 CRITICAL
Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated customer can set `def_language` to a path traversal payload (e.g., `../../../../../var/customers/webs/customer1/evil`), which is stored in the database. On subsequent requests, `Language::loadLanguage()` constructs a file path using this value and executes it via `require`, achieving arbitrary PHP code execution as the web server user. Version 2.3.6 fixes the issue.
CVE-2026-3826 1 Wellchoose 1 Organization Portal System 2026-06-17 N/A 9.8 CRITICAL
IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.
CVE-2026-3425 2026-06-17 N/A 8.8 HIGH
The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path' parameter of the 'get_content' AJAX action. This makes it possible for authenticated attackers, with Author-level access and above, to include and execute arbitrary PHP files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where PHP files can be uploaded and included.
CVE-2026-37266 2026-06-17 N/A 8.0 HIGH
An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component