CWE-98: CWE-98

608
Total CVEs
81
Critical
513
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
120
2025
446
2024
38
2023
3
2021
1

Top Affected Vendors

1 Axiomthemes 58
2 Ancorathemes 12
3 Thememove 12
4 Qodeinteractive 9
5 Themehorse 3
6 Joomsky 2
7 G5plus 2
8 Wptravelengine 2
9 Themewinter 2
10 La Studioweb 2

All CWE-98 CVEs (608)

CVE-2025-25174
10.0

This CVE describes a PHP Local File Inclusion vulnerability in the BeeTeam368 Extensions WordPress plugin, allowing attackers to include and execute a...

Aug 14, 2025
CVE-2026-0926
9.8

The Prodigy Commerce WordPress plugin has a Local File Inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execut...

Feb 19, 2026
CVE-2021-47900
9.8

CVE-2021-47900 is a critical remote code execution vulnerability in Gila CMS that allows unauthenticated attackers to execute arbitrary system command...

Jan 27, 2026
CVE-2026-24531
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 23, 2026
CVE-2026-23975
9.8

This CVE describes a PHP Local File Inclusion vulnerability in the Golo WordPress theme that allows attackers to include arbitrary local files through...

Jan 22, 2026
CVE-2026-23978
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 22, 2026
CVE-2025-54003
9.8

This vulnerability allows attackers to include local PHP files through improper filename control in the Depot WordPress theme. Attackers can potential...

Jan 22, 2026
CVE-2025-49994
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Jan 22, 2026
CVE-2025-50003
9.8

This vulnerability allows attackers to include local PHP files through improper filename control in the Amuli WordPress theme. Attackers can potential...

Jan 22, 2026
CVE-2025-47474
9.8

This vulnerability allows attackers to include local PHP files through improper filename control in the Anarkali WordPress theme. Attackers can potent...

Jan 22, 2026
CVE-2025-14502
9.8

The News and Blog Designer Bundle WordPress plugin has a Local File Inclusion vulnerability that allows unauthenticated attackers to include and execu...

Jan 14, 2026
CVE-2025-67920
9.8

This vulnerability allows attackers to include local PHP files through improper filename control in the Neo Ocular WordPress theme, potentially leadin...

Jan 8, 2026
CVE-2025-22509
9.8

This vulnerability allows attackers to include arbitrary local files through PHP's include/require statements in the Atlas WordPress theme. Attackers ...

Jan 8, 2026
CVE-2025-22707
9.8

This vulnerability allows attackers to include arbitrary local files through PHP's include/require statements in the Moody WordPress theme. Attackers ...

Jan 8, 2026
CVE-2025-22708
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements in the Mi...

Jan 8, 2026
CVE-2025-22712
9.8

This vulnerability allows attackers to include arbitrary local files through PHP's include/require statements in the Typify WordPress theme. Attackers...

Jan 8, 2026
CVE-2025-14429
9.8

This vulnerability allows attackers to include local PHP files through improper filename control in the ThemeMove AeroLand WordPress theme. Attackers ...

Jan 8, 2026
CVE-2025-14430
9.8

This CVE describes a PHP Local File Inclusion vulnerability in the Brook WordPress theme that allows attackers to include arbitrary local files via im...

Jan 8, 2026
CVE-2025-14431
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 8, 2026
CVE-2025-12550
9.8

This CVE describes a PHP Local File Inclusion vulnerability in the OchaHouse WordPress theme that allows attackers to include arbitrary local files th...

Jan 8, 2026
CVE-2025-14359
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 8, 2026
CVE-2025-12549
9.8

This CVE describes a PHP Local File Inclusion vulnerability in the Rozy - Flower Shop WordPress theme. Attackers can include arbitrary local files via...

Jan 8, 2026
CVE-2025-68984
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 30, 2025
CVE-2025-68985
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 30, 2025
CVE-2025-68987
9.8

This vulnerability allows attackers to include and execute arbitrary local files on servers running the vulnerable Cinerama WordPress theme. Attackers...

Dec 30, 2025
CVE-2025-68983
9.8

This vulnerability allows attackers to include local PHP files through improper filename control in the Greenmart WordPress theme. Attackers can read ...

Dec 30, 2025
CVE-2025-68974
9.8

This vulnerability allows attackers to include local files on the server through the WordPress Social Login and Register plugin. Attackers can potenti...

Dec 30, 2025
CVE-2025-68540
9.8

This vulnerability allows attackers to include arbitrary local files through PHP's include/require statements in the Fana WordPress theme. Attackers c...

Dec 24, 2025
CVE-2025-68563
9.8

This CVE describes a PHP Local File Inclusion vulnerability in the WordPress Subscribe to Unlock Lite plugin. Attackers can include arbitrary local fi...

Dec 24, 2025
CVE-2025-68530
9.8

This CVE describes a PHP Local File Inclusion vulnerability in the Bookory WordPress theme. Attackers can include arbitrary local files through improp...

Dec 24, 2025
CVE-2025-68537
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 24, 2025
CVE-2025-68506
9.8

This CVE describes a PHP Local File Inclusion vulnerability in the Docket Cache WordPress plugin. Attackers can include arbitrary local files on the s...

Dec 24, 2025
CVE-2025-58935
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-53433
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-67526
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 9, 2025
CVE-2025-67527
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 9, 2025
CVE-2025-67529
9.8

This vulnerability allows attackers to include arbitrary local files via PHP's include/require statements in the Opal_WP Fashion fashion2 WordPress th...

Dec 9, 2025
CVE-2025-67530
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 9, 2025
CVE-2025-67531
9.8

This CVE describes a PHP Local File Inclusion vulnerability in the Turitor WordPress theme. Attackers can include arbitrary local files through improp...

Dec 9, 2025
CVE-2025-67532
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 9, 2025
CVE-2025-67524
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 9, 2025
CVE-2025-67525
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 9, 2025
CVE-2025-67521
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 9, 2025
CVE-2025-67522
9.8

This CVE describes a PHP Local File Inclusion vulnerability in the NooTheme Jobmonster WordPress theme. Attackers can include arbitrary local files th...

Dec 9, 2025
CVE-2025-67523
9.8

This CVE describes a PHP Local File Inclusion vulnerability in the Exhibz WordPress theme that allows attackers to include arbitrary local files via i...

Dec 9, 2025
CVE-2025-67515
9.8

This CVE describes a PHP Local File Inclusion vulnerability in the Wilmër WordPress theme by Mikado-Themes. Attackers can include arbitrary local fil...

Dec 9, 2025
CVE-2025-65656
9.8

CVE-2025-65656 is a file inclusion vulnerability in dcat-admin v2.2.3-beta and earlier that allows attackers to include arbitrary files from the serve...

Dec 2, 2025
CVE-2025-63888
9.8

A remote code execution vulnerability exists in ThinkPHP 5.0.24's template file driver. Attackers can exploit the read function in File.php to execute...

Nov 20, 2025
CVE-2025-41734
9.8

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary PHP files on affected devices, leading to complete system com...

Nov 18, 2025
CVE-2025-53252
9.8

This vulnerability allows attackers to include local PHP files through improper filename control in the Zegen WordPress theme. Attackers can potential...

Nov 6, 2025

About CWE-98 (CWE-98)

Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.

External reference: View CWE-98 on MITRE CWE →

Monitor CWE-98 Vulnerabilities

Get alerted when new CWE-98 CVEs affect your infrastructure.

Start Monitoring Free