CVE & CISA-KEV Catalog
| Severity | Description | ||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-88994 | Medium | 6.6 v3 | - | - | -No fix available yet | 2026-09-18 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file containing PHP code can be reached. Exploitation requires the plugin's Lightspeed subsystem to be enabled, which is not the default. |
| CVE-2026-27556 | High | 8.8 v3 | - | - | -No fix available yet | 2026-09-16 | A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device. |
| CVE-2026-27555 | High | 8.8 v3 | - | - | -No fix available yet | 2026-09-16 | A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device. |
| CVE-2026-85200 | High | 7.5 v3 | 0.8% | - | -No fix available yet | 2026-09-12 | The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. In environments where PEAR is installed with register_argc_argv enabled, this file inclusion can be leveraged to write and execute arbitrary PHP code, achieving full remote code execution. |
| CVE-2026-87927 | High | 8.2 v3 | 0.3% | - | -No fix available yet | 2026-09-09 | MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality. |
| CVE-2026-15667 | High | 7.5 v3 | 0.6% | - | -No fix available yet | 2026-09-09 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The etn_manage_event capability is assigned to Contributors by default, meaning any Contributor-level user can set the malicious event_layout value via the REST API without any additional configuration. |
| CVE-2026-15406 | High | 7.5 v3 | 0.7% | - | -No fix available yet | 2026-09-09 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. |
| CVE-2026-11613 | Critical | 9.8 v3 | 0.5% | - | -No fix available yet | 2026-09-04 | The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. This vulnerability is only exploitable when the loop_templates parameter is set to 'custom-template'. |
| CVE-2026-78478 | High | 8.1 v3 | 0.5% | - | -No fix available yet | 2026-08-25 | The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. |
| CVE-2026-14280 | Medium | 6.6 v3 | 0.7% | - | -No fix available yet | 2026-08-25 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.3.7.4 via the em_options_save function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal key is subsequently executed via an include_once() call that fires on every admin_init invocation — including unauthenticated admin-ajax.php requests — meaning once the malicious key is stored by an administrator, the |
| CVE-2026-32560 | High | 8.8 v3 | 0.3% | - | -No fix available yet | 2026-08-24 | Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions. |
| CVE-2026-66671 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-24 | Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions. |
| CVE-2026-66670 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-24 | Unauthenticated Local File Inclusion in Måne <= 1.7 versions. |
| CVE-2026-66587 | Critical | 9.8 v3 | 0.3% | - | -No fix available yet | 2026-08-24 | Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions. |
| CVE-2026-28152 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-24 | Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions. |
| CVE-2026-28151 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-24 | Unauthenticated Local File Inclusion in Tonda < 2.6 versions. |
| CVE-2026-66586 | Medium | 6.6 v3 | 0.3% | - | -No fix available yet | 2026-08-20 | Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions. |
| CVE-2026-28150 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-20 | Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. |
| CVE-2025-15637 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-20 | Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. |
| CVE-2026-75963 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-08-20 | The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, meaning post-submission execution does not require additional attacker interaction. |
| CVE-2026-73387 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-19 | Unauthenticated Local File Inclusion in Resido <= 1.5 versions. |
| CVE-2026-73400 | High | 8.1 v3 | 0.4% | - | -No fix available yet | 2026-08-18 | Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. |
| CVE-2026-32464 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-18 | Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. |
| CVE-2026-28570 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-18 | Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. |
| CVE-2026-66657 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-13 | Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. |
| CVE-2026-66656 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-13 | Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. |
| CVE-2026-66653 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-13 | Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. |
| CVE-2026-66450 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-13 | Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions. |
| CVE-2026-66710 | High | 8.1 v3 | 0.3% | - | -No fix available yet | 2026-08-06 | Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions. |
| CVE-2026-17605 | Medium | 6.6 v3 | 0.7% | - | -No fix available yet | 2026-08-01 | The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. |
| CVE-2026-63302 | Medium | 5.1 v4 | 0.3% | - | -No fix available yet | 2026-07-28 | Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application's directory structure via a crafted HTTP request. Successful exploitation allows disclosure of the server's directory structure and absolute file paths (path disclosure). The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary. |
| CVE-2026-65481 | High | 7.5 v3 | 0.4% | - | -No fix available yet | 2026-07-23 | Contributor Local File Inclusion in Vino <= 1.9 versions. |
| CVE-2026-65477 | High | 7.5 v3 | 0.4% | - | -No fix available yet | 2026-07-23 | Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions. |
| CVE-2026-44177 | High | 8.8 v4 | 1.8% | - | -No fix available yet | 2026-07-16 | Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user ID, resulting in a path traversal vulnerability. Version 5.3.0 introduced a performance improvement to the Users collection that loaded user objects lazily when first needed. Users were queried by their ID, which was then used to locate the corresponding account directory under site/accounts. This affected the authentication API (accessible to unauthenticated requests), the users API (accessible only to authenticated users), and any other place that uses $users->find() to look up an individual user by a request-provided email or ID. As a result, an attacker could trigger arbitrary PHP file inclusion of files named index.php (for example, the |
| CVE-2026-46687 | High | 7.7 v4 | 0.4% | - | -No fix available yet | 2026-07-16 | Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without validation, and log_controller.php later checks file_exists and calls include View::getView($template), allowing an authenticated author to include an arbitrary local .php file when an article is viewed. No fixed version is currently identified. |
| CVE-2026-57805 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Tonda tonda allows PHP Local File Inclusion.This issue affects Tonda: from n/a through <= 2.5. |
| CVE-2026-57804 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows PHP Local File Inclusion. This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1. |
| CVE-2026-57803 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur Core allows PHP Local File Inclusion. This issue affects Struktur Core: from n/a before 2.7. |
| CVE-2026-57802 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur allows PHP Local File Inclusion. This issue affects Struktur: from n/a before 2.7. |
| CVE-2026-57801 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes SetSail setsail allows PHP Local File Inclusion.This issue affects SetSail: from n/a through <= 2.1. |
| CVE-2026-57800 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Overworld overworld allows PHP Local File Inclusion.This issue affects Overworld: from n/a through <= 1.5. |
| CVE-2026-57799 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Nuss nuss allows PHP Local File Inclusion.This issue affects Nuss: from n/a through <= 1.3.6. |
| CVE-2026-57798 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortcodes newsplus-shortcodes allows PHP Local File Inclusion.This issue affects NewsPlus Shortcodes: from n/a through <= 4.2.0. |
| CVE-2026-57796 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VLThemes Leedo leedo allows PHP Local File Inclusion.This issue affects Leedo: from n/a through <= 3.0.0. |
| CVE-2026-57795 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Kitchor kitchor allows PHP Local File Inclusion.This issue affects Kitchor: from n/a through <= 1.4.3. |
| CVE-2026-57794 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-framework allows PHP Local File Inclusion.This issue affects Golo Framework: from n/a through <= 1.7.3. |
| CVE-2026-57793 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Flow flow allows PHP Local File Inclusion.This issue affects Flow: from n/a through <= 1.8. |
| CVE-2026-57792 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through <= 2.4.1. |
| CVE-2026-57791 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This issue affects Brook: from n/a through <= 2.9.0. |
| CVE-2026-57790 | High | 7.5 v3 | 0.5% | - | -No fix available yet | 2026-07-13 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.This issue affects Billey: from n/a through <= 2.1.8. |
- MediumCVSS 6.6 v3·EPSS -·No fix yet
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file containing PHP code can be reached. Exploitation requires the plugin's Lightspeed subsystem to be enabled, which is not the default.
Published 2026-09-18
- HighCVSS 8.8 v3·EPSS -·No fix yet
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.
Published 2026-09-16
- HighCVSS 8.8 v3·EPSS -·No fix yet
A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.
Published 2026-09-16
- HighCVSS 7.5 v3·EPSS 0.8%·No fix yet
The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. In environments where PEAR is installed with register_argc_argv enabled, this file inclusion can be leveraged to write and execute arbitrary PHP code, achieving full remote code execution.
Published 2026-09-12
- HighCVSS 8.2 v3·EPSS 0.3%·No fix yet
MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.
Published 2026-09-09
- HighCVSS 7.5 v3·EPSS 0.6%·No fix yet
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The etn_manage_event capability is assigned to Contributors by default, meaning any Contributor-level user can set the malicious event_layout value via the REST API without any additional configuration.
Published 2026-09-09
- HighCVSS 7.5 v3·EPSS 0.7%·No fix yet
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Published 2026-09-09
- CriticalCVSS 9.8 v3·EPSS 0.5%·No fix yet
The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. This vulnerability is only exploitable when the loop_templates parameter is set to 'custom-template'.
Published 2026-09-04
- HighCVSS 8.1 v3·EPSS 0.5%·No fix yet
The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Published 2026-08-25
- MediumCVSS 6.6 v3·EPSS 0.7%·No fix yet
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.3.7.4 via the em_options_save function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal key is subsequently executed via an include_once() call that fires on every admin_init invocation — including unauthenticated admin-ajax.php requests — meaning once the malicious key is stored by an administrator, the
Published 2026-08-25
- HighCVSS 8.8 v3·EPSS 0.3%·No fix yet
Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.
Published 2026-08-24
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.
Published 2026-08-24
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in Måne <= 1.7 versions.
Published 2026-08-24
- CriticalCVSS 9.8 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
Published 2026-08-24
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
Published 2026-08-24
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in Tonda < 2.6 versions.
Published 2026-08-24
- MediumCVSS 6.6 v3·EPSS 0.3%·No fix yet
Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
Published 2026-08-20
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.
Published 2026-08-20
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.
Published 2026-08-20
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, meaning post-submission execution does not require additional attacker interaction.
Published 2026-08-20
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in Resido <= 1.5 versions.
Published 2026-08-19
- HighCVSS 8.1 v3·EPSS 0.4%·No fix yet
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
Published 2026-08-18
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.
Published 2026-08-18
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.
Published 2026-08-18
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.
Published 2026-08-13
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.
Published 2026-08-13
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.
Published 2026-08-13
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions.
Published 2026-08-13
- HighCVSS 8.1 v3·EPSS 0.3%·No fix yet
Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
Published 2026-08-06
- MediumCVSS 6.6 v3·EPSS 0.7%·No fix yet
The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Published 2026-08-01
- MediumCVSS 5.1 v4·EPSS 0.3%·No fix yet
Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application's directory structure via a crafted HTTP request. Successful exploitation allows disclosure of the server's directory structure and absolute file paths (path disclosure). The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.
Published 2026-07-28
- HighCVSS 7.5 v3·EPSS 0.4%·No fix yet
Contributor Local File Inclusion in Vino <= 1.9 versions.
Published 2026-07-23
- HighCVSS 7.5 v3·EPSS 0.4%·No fix yet
Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
Published 2026-07-23
- HighCVSS 8.8 v4·EPSS 1.8%·No fix yet
Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user ID, resulting in a path traversal vulnerability. Version 5.3.0 introduced a performance improvement to the Users collection that loaded user objects lazily when first needed. Users were queried by their ID, which was then used to locate the corresponding account directory under site/accounts. This affected the authentication API (accessible to unauthenticated requests), the users API (accessible only to authenticated users), and any other place that uses $users->find() to look up an individual user by a request-provided email or ID. As a result, an attacker could trigger arbitrary PHP file inclusion of files named index.php (for example, the
Published 2026-07-16
- HighCVSS 7.7 v4·EPSS 0.4%·No fix yet
Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without validation, and log_controller.php later checks file_exists and calls include View::getView($template), allowing an authenticated author to include an arbitrary local .php file when an article is viewed. No fixed version is currently identified.
Published 2026-07-16
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Tonda tonda allows PHP Local File Inclusion.This issue affects Tonda: from n/a through <= 2.5.
Published 2026-07-13
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows PHP Local File Inclusion. This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1.
Published 2026-07-13
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur Core allows PHP Local File Inclusion. This issue affects Struktur Core: from n/a before 2.7.
Published 2026-07-13
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur allows PHP Local File Inclusion. This issue affects Struktur: from n/a before 2.7.
Published 2026-07-13
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes SetSail setsail allows PHP Local File Inclusion.This issue affects SetSail: from n/a through <= 2.1.
Published 2026-07-13
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Overworld overworld allows PHP Local File Inclusion.This issue affects Overworld: from n/a through <= 1.5.
Published 2026-07-13
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Nuss nuss allows PHP Local File Inclusion.This issue affects Nuss: from n/a through <= 1.3.6.
Published 2026-07-13
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortcodes newsplus-shortcodes allows PHP Local File Inclusion.This issue affects NewsPlus Shortcodes: from n/a through <= 4.2.0.
Published 2026-07-13
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VLThemes Leedo leedo allows PHP Local File Inclusion.This issue affects Leedo: from n/a through <= 3.0.0.
Published 2026-07-13
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Kitchor kitchor allows PHP Local File Inclusion.This issue affects Kitchor: from n/a through <= 1.4.3.
Published 2026-07-13
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-framework allows PHP Local File Inclusion.This issue affects Golo Framework: from n/a through <= 1.7.3.
Published 2026-07-13
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Flow flow allows PHP Local File Inclusion.This issue affects Flow: from n/a through <= 1.8.
Published 2026-07-13
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through <= 2.4.1.
Published 2026-07-13
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This issue affects Brook: from n/a through <= 2.9.0.
Published 2026-07-13
- HighCVSS 7.5 v3·EPSS 0.5%·No fix yet
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.This issue affects Billey: from n/a through <= 2.1.8.
Published 2026-07-13
Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.