CWE-98: CWE-98
Yearly Trend
Top Affected Vendors
All CWE-98 CVEs (608)
This CVE describes a PHP Local File Inclusion vulnerability in the Premmerce WordPress plugin. Attackers can include arbitrary local files from the se...
Nov 6, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Nov 6, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Nov 6, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Nov 6, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Nov 6, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Nov 6, 2025This vulnerability allows attackers to include local files on the server through improper input validation in the Premmerce Wholesale Pricing for WooC...
Nov 6, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Premmerce User Roles WordPress plugin. Attackers can exploit improper filename cont...
Nov 6, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Nov 6, 2025This vulnerability allows attackers to include local files on the server through PHP's include/require statements, potentially leading to sensitive in...
Nov 6, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Responsive Sidebar WordPress plugin. Attackers can include arbitrary local files fr...
Nov 6, 2025This CVE describes a Local File Inclusion vulnerability in the Lazy Load Optimizer WordPress plugin. Attackers can include arbitrary local files on th...
Nov 6, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Nov 6, 2025The Elegance Menu WordPress plugin contains a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level access or ...
Nov 4, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Consulting WordPress theme by StylemixThemes. Attackers can include arbitrary local...
Oct 31, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Kleo WordPress theme. Attackers can exploit improper filename control in include/re...
Oct 31, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Majestic Support WordPress plugin. Attackers can include arbitrary local files, pot...
Oct 29, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Oct 29, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Eduma WordPress theme by ThimPress. Attackers can exploit improper filename control...
Oct 29, 2025This vulnerability allows remote attackers to include arbitrary files from external servers via PHP's include/require statements, potentially leading ...
Oct 22, 2025The WooCommerce Category and Products Accordion Panel WordPress plugin contains a Local File Inclusion vulnerability in all versions up to 1.0. Authen...
Oct 15, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Sep 26, 2025This CVE describes a PHP Local File Inclusion vulnerability in the WordPress Subscribe To Unlock plugin. Attackers can include arbitrary local files o...
Sep 26, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Sep 22, 2025This vulnerability allows attackers to include local PHP files through improper filename control in the Easy Elementor Addons WordPress plugin. Attack...
Sep 22, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Sep 22, 2025This vulnerability allows attackers to include local files on the server through improper input validation in the Easy Pricing Table WP WordPress plug...
Sep 22, 2025The Catch Dark Mode WordPress plugin contains a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level access o...
Sep 17, 2025The Ultimate Classified Listings WordPress plugin has a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level ...
Sep 11, 2025This vulnerability allows authenticated attackers to include local files in WordPress Blog Designer PRO plugin, potentially leading to information dis...
Sep 9, 2025This vulnerability allows attackers to include arbitrary local files via PHP's include/require statements in the Super Store Finder WordPress plugin. ...
Sep 9, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Sep 5, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Sep 3, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Sep 3, 2025This vulnerability allows attackers to include local files on the server through the WordPress Poll, Survey & Quiz Maker Plugin by Opinion Stage. Atta...
Aug 28, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Aug 20, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Aug 20, 2025This vulnerability allows attackers to include local files on the server through improper input validation in the ZoloBlocks WordPress plugin. Attacke...
Aug 20, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Aug 20, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Responsive Posts Carousel WordPress plugin. Attackers can exploit improper filename...
Aug 14, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Aug 14, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Aug 14, 2025This vulnerability allows attackers to include local files on the server through PHP's include/require statements, potentially leading to remote code ...
Aug 14, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Aug 14, 2025This vulnerability in LibreNMS allows remote file inclusion via the ajax_form.php endpoint, potentially leading to remote code execution. Attackers ca...
Jul 22, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Jul 4, 2025This vulnerability allows attackers to include local files on the server through improper input validation in the PrivateContent - Mail Actions WordPr...
Jul 4, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Jun 27, 2025This CVE describes a PHP Local File Inclusion vulnerability in the RealMag777 HUSKY WordPress plugin. Attackers can exploit improper filename control ...
Jun 20, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Jun 20, 2025About CWE-98 (CWE-98)
Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.
External reference: View CWE-98 on MITRE CWE →
Monitor CWE-98 Vulnerabilities
Get alerted when new CWE-98 CVEs affect your infrastructure.
Start Monitoring Free