CWE-98: CWE-98
Yearly Trend
Top Affected Vendors
All CWE-98 CVEs (608)
This CVE describes a PHP Local File Inclusion vulnerability in the BeeTeam368 Extensions WordPress plugin, allowing attackers to include and execute a...
Aug 14, 2025The Prodigy Commerce WordPress plugin has a Local File Inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execut...
Feb 19, 2026CVE-2021-47900 is a critical remote code execution vulnerability in Gila CMS that allows unauthenticated attackers to execute arbitrary system command...
Jan 27, 2026This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Jan 23, 2026This CVE describes a PHP Local File Inclusion vulnerability in the Golo WordPress theme that allows attackers to include arbitrary local files through...
Jan 22, 2026This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Jan 22, 2026This vulnerability allows attackers to include local PHP files through improper filename control in the Depot WordPress theme. Attackers can potential...
Jan 22, 2026This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Jan 22, 2026This vulnerability allows attackers to include local PHP files through improper filename control in the Amuli WordPress theme. Attackers can potential...
Jan 22, 2026This vulnerability allows attackers to include local PHP files through improper filename control in the Anarkali WordPress theme. Attackers can potent...
Jan 22, 2026The News and Blog Designer Bundle WordPress plugin has a Local File Inclusion vulnerability that allows unauthenticated attackers to include and execu...
Jan 14, 2026This vulnerability allows attackers to include local PHP files through improper filename control in the Neo Ocular WordPress theme, potentially leadin...
Jan 8, 2026This vulnerability allows attackers to include arbitrary local files through PHP's include/require statements in the Atlas WordPress theme. Attackers ...
Jan 8, 2026This vulnerability allows attackers to include arbitrary local files through PHP's include/require statements in the Moody WordPress theme. Attackers ...
Jan 8, 2026This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements in the Mi...
Jan 8, 2026This vulnerability allows attackers to include arbitrary local files through PHP's include/require statements in the Typify WordPress theme. Attackers...
Jan 8, 2026This vulnerability allows attackers to include local PHP files through improper filename control in the ThemeMove AeroLand WordPress theme. Attackers ...
Jan 8, 2026This CVE describes a PHP Local File Inclusion vulnerability in the Brook WordPress theme that allows attackers to include arbitrary local files via im...
Jan 8, 2026This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Jan 8, 2026This CVE describes a PHP Local File Inclusion vulnerability in the OchaHouse WordPress theme that allows attackers to include arbitrary local files th...
Jan 8, 2026This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Jan 8, 2026This CVE describes a PHP Local File Inclusion vulnerability in the Rozy - Flower Shop WordPress theme. Attackers can include arbitrary local files via...
Jan 8, 2026This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 30, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 30, 2025This vulnerability allows attackers to include and execute arbitrary local files on servers running the vulnerable Cinerama WordPress theme. Attackers...
Dec 30, 2025This vulnerability allows attackers to include local PHP files through improper filename control in the Greenmart WordPress theme. Attackers can read ...
Dec 30, 2025This vulnerability allows attackers to include local files on the server through the WordPress Social Login and Register plugin. Attackers can potenti...
Dec 30, 2025This vulnerability allows attackers to include arbitrary local files through PHP's include/require statements in the Fana WordPress theme. Attackers c...
Dec 24, 2025This CVE describes a PHP Local File Inclusion vulnerability in the WordPress Subscribe to Unlock Lite plugin. Attackers can include arbitrary local fi...
Dec 24, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Bookory WordPress theme. Attackers can include arbitrary local files through improp...
Dec 24, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 24, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Docket Cache WordPress plugin. Attackers can include arbitrary local files on the s...
Dec 24, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 18, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 18, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 9, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 9, 2025This vulnerability allows attackers to include arbitrary local files via PHP's include/require statements in the Opal_WP Fashion fashion2 WordPress th...
Dec 9, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Dec 9, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Turitor WordPress theme. Attackers can include arbitrary local files through improp...
Dec 9, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 9, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 9, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 9, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Dec 9, 2025This CVE describes a PHP Local File Inclusion vulnerability in the NooTheme Jobmonster WordPress theme. Attackers can include arbitrary local files th...
Dec 9, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Exhibz WordPress theme that allows attackers to include arbitrary local files via i...
Dec 9, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Wilmër WordPress theme by Mikado-Themes. Attackers can include arbitrary local fil...
Dec 9, 2025CVE-2025-65656 is a file inclusion vulnerability in dcat-admin v2.2.3-beta and earlier that allows attackers to include arbitrary files from the serve...
Dec 2, 2025A remote code execution vulnerability exists in ThinkPHP 5.0.24's template file driver. Attackers can exploit the read function in File.php to execute...
Nov 20, 2025This critical vulnerability allows unauthenticated remote attackers to execute arbitrary PHP files on affected devices, leading to complete system com...
Nov 18, 2025This vulnerability allows attackers to include local PHP files through improper filename control in the Zegen WordPress theme. Attackers can potential...
Nov 6, 2025About CWE-98 (CWE-98)
Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.
External reference: View CWE-98 on MITRE CWE →
Monitor CWE-98 Vulnerabilities
Get alerted when new CWE-98 CVEs affect your infrastructure.
Start Monitoring Free