VulnSea

CWE-98

CVEs classified under CWE-98, newest first.

16 CVEsRSS

CVE-2026-88994Medium· 6.6
4d ago

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include ar…

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include ar…

SunlitEPSS 0.28%via NVD
CVE-2026-27556High· 8.8
6d ago

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.86%via NVD
CVE-2026-27555High· 8.8
6d ago

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.83%via NVD
CVE-2026-85200High· 7.5PoC
1w ago

The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function

The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to in…

Midnightninjew · GEO my WPEPSS 1.9%via NVD
CVE-2026-15406High· 7.5
1w ago

Eventin <= 4.1.22 - Authenticated (Custom+) Local File Inclusion via 'event_layout' Parameter

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This mak…

Twilightarraytics · Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceEPSS 0.67%via CVEORG
CVE-2026-15667High· 7.5PoC
1w ago

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This mak…

Midnightarraytics · Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceEPSS 0.56%via NVD
CVE-2026-87927High· 8.2PoC
1w ago

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequ…

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequ…

MidnightMaxSite · MaxSite CMSEPSS 0.34%via NVD
CVE-2026-11613Critical· 9.8PoC
2w ago

The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter

The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to inclu…

AbyssalEPSS 0.46%via NVD
CVE-2026-17605Medium· 6.6
1mo ago

The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function

The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possi…

SunlitEPSS 0.69%via NVD
CVE-2026-15540Medium· 4.3
2mo ago

A vulnerability was detected in SourceCodester Online Book Store System 1.0

A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument pa…

SunlitEPSS 0.42%via NVD
CVE-2026-15338High· 7.5
2mo ago

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function. This makes it possible for authenticated attackers, with c…

TwilightEPSS 0.96%via NVD
CVE-2026-12194None
2mo ago

PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system

PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations.

SunlitEPSS 0.38%via NVD
CVE-2026-5137Medium· 4.3
2mo ago

The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.7 This is due to insufficient path validation on the 'template' parameter in the render_templates AJAX …

The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.7 This is due to insufficient path validation on the 'template' parameter in the render_templates AJAX …

SunlitEPSS 0.45%via NVD
CVE-2026-9559Critical· 9.9
2mo ago

Mautic vulnerable to Path Traversal via Campaign Import

Mautic vulnerable to Path Traversal via Campaign Import

Midnightmautic · mautic/coreEPSS 0.58%via GHSA
CVE-2019-25760Medium· 6.2
3mo ago

Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths

Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the o…

Sunlitjoomtech · easy_shopEPSS 0.51%via NVD
CVE-2025-31098High· 7.5
1y ago

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in debounce DeBounce Email Validator debounce-io-email-validator allows PHP Local File Inclusion. This issue affects D…

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in debounce DeBounce Email Validator debounce-io-email-validator allows PHP Local File Inclusion. This issue affects D…

TwilightEPSS 0.70%via NVD
CWE-98 vulnerabilities (CVEs) · VulnSea