CWE-98: CWE-98

608
Total CVEs
81
Critical
513
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
120
2025
446
2024
38
2023
3
2021
1

Top Affected Vendors

1 Axiomthemes 58
2 Ancorathemes 12
3 Thememove 12
4 Qodeinteractive 9
5 Themehorse 3
6 Joomsky 2
7 G5plus 2
8 Wptravelengine 2
9 Themewinter 2
10 La Studioweb 2

All CWE-98 CVEs (608)

CVE-2025-60241
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Premmerce WordPress plugin. Attackers can include arbitrary local files from the se...

Nov 6, 2025
CVE-2025-60200
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Nov 6, 2025
CVE-2025-60201
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Nov 6, 2025
CVE-2025-60202
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Nov 6, 2025
CVE-2025-60203
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Nov 6, 2025
CVE-2025-60191
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Nov 6, 2025
CVE-2025-60192
7.5

This vulnerability allows attackers to include local files on the server through improper input validation in the Premmerce Wholesale Pricing for WooC...

Nov 6, 2025
CVE-2025-60193
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Premmerce User Roles WordPress plugin. Attackers can exploit improper filename cont...

Nov 6, 2025
CVE-2025-60194
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Nov 6, 2025
CVE-2025-60196
7.5

This vulnerability allows attackers to include local files on the server through PHP's include/require statements, potentially leading to sensitive in...

Nov 6, 2025
CVE-2025-60073
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Responsive Sidebar WordPress plugin. Attackers can include arbitrary local files fr...

Nov 6, 2025
CVE-2025-60074
7.5

This CVE describes a Local File Inclusion vulnerability in the Lazy Load Optimizer WordPress plugin. Attackers can include arbitrary local files on th...

Nov 6, 2025
CVE-2025-60189
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Nov 6, 2025
CVE-2025-11704
7.5

The Elegance Menu WordPress plugin contains a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level access or ...

Nov 4, 2025
CVE-2025-64359
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Consulting WordPress theme by StylemixThemes. Attackers can include arbitrary local...

Oct 31, 2025
CVE-2025-64363
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Kleo WordPress theme. Attackers can exploit improper filename control in include/re...

Oct 31, 2025
CVE-2025-64284
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Majestic Support WordPress plugin. Attackers can include arbitrary local files, pot...

Oct 29, 2025
CVE-2025-64216
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Oct 29, 2025
CVE-2025-64195
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Eduma WordPress theme by ThimPress. Attackers can exploit improper filename control...

Oct 29, 2025
CVE-2025-62054
7.5

This vulnerability allows remote attackers to include arbitrary files from external servers via PHP's include/require statements, potentially leading ...

Oct 22, 2025
CVE-2025-11722
7.5

The WooCommerce Category and Products Accordion Panel WordPress plugin contains a Local File Inclusion vulnerability in all versions up to 1.0. Authen...

Oct 15, 2025
CVE-2025-60150
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Sep 26, 2025
CVE-2025-60153
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the WordPress Subscribe To Unlock plugin. Attackers can include arbitrary local files o...

Sep 26, 2025
CVE-2025-59588
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Sep 22, 2025
CVE-2025-58973
7.5

This vulnerability allows attackers to include local PHP files through improper filename control in the Easy Elementor Addons WordPress plugin. Attack...

Sep 22, 2025
CVE-2025-57925
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Sep 22, 2025
CVE-2025-53450
7.5

This vulnerability allows attackers to include local files on the server through improper input validation in the Easy Pricing Table WP WordPress plug...

Sep 22, 2025
CVE-2025-10143
7.5

The Catch Dark Mode WordPress plugin contains a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level access o...

Sep 17, 2025
CVE-2025-9874
7.5

The Ultimate Classified Listings WordPress plugin has a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level ...

Sep 11, 2025
CVE-2025-47695
7.5

This vulnerability allows authenticated attackers to include local files in WordPress Blog Designer PRO plugin, potentially leading to information dis...

Sep 9, 2025
CVE-2025-47571
7.5

This vulnerability allows attackers to include arbitrary local files via PHP's include/require statements in the Super Store Finder WordPress plugin. ...

Sep 9, 2025
CVE-2025-57889
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Sep 5, 2025
CVE-2025-58637
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Sep 3, 2025
CVE-2025-58608
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Sep 3, 2025
CVE-2025-53328
7.5

This vulnerability allows attackers to include local files on the server through the WordPress Poll, Survey & Quiz Maker Plugin by Opinion Stage. Atta...

Aug 28, 2025
CVE-2025-54750
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Aug 20, 2025
CVE-2025-54034
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Aug 20, 2025
CVE-2025-53210
7.5

This vulnerability allows attackers to include local files on the server through improper input validation in the ZoloBlocks WordPress plugin. Attacke...

Aug 20, 2025
CVE-2025-48302
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Aug 20, 2025
CVE-2025-52728
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Responsive Posts Carousel WordPress plugin. Attackers can exploit improper filename...

Aug 14, 2025
CVE-2025-52716
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Aug 14, 2025
CVE-2025-49271
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Aug 14, 2025
CVE-2025-49264
7.5

This vulnerability allows attackers to include local files on the server through PHP's include/require statements, potentially leading to remote code ...

Aug 14, 2025
CVE-2025-24766
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Aug 14, 2025
CVE-2025-54138
7.5

This vulnerability in LibreNMS allows remote file inclusion via the ajax_form.php endpoint, potentially leading to remote code execution. Attackers ca...

Jul 22, 2025
CVE-2025-49070
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jul 4, 2025
CVE-2025-47627
7.5

This vulnerability allows attackers to include local files on the server through improper input validation in the PrivateContent - Mail Actions WordPr...

Jul 4, 2025
CVE-2025-53281
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 27, 2025
CVE-2025-52708
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the RealMag777 HUSKY WordPress plugin. Attackers can exploit improper filename control ...

Jun 20, 2025
CVE-2025-52715
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 20, 2025

About CWE-98 (CWE-98)

Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.

External reference: View CWE-98 on MITRE CWE →

Monitor CWE-98 Vulnerabilities

Get alerted when new CWE-98 CVEs affect your infrastructure.

Start Monitoring Free