CWE-98: CWE-98

608
Total CVEs
81
Critical
513
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
120
2025
446
2024
38
2023
3
2021
1

Top Affected Vendors

1 Axiomthemes 58
2 Ancorathemes 12
3 Thememove 12
4 Qodeinteractive 9
5 Themehorse 3
6 Joomsky 2
7 G5plus 2
8 Wptravelengine 2
9 Themewinter 2
10 La Studioweb 2

All CWE-98 CVEs (608)

CVE-2025-47572
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 17, 2025
CVE-2025-32549
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 17, 2025
CVE-2025-39476
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 9, 2025
CVE-2025-49313
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 6, 2025
CVE-2025-49307
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in the WP Multilang WordPress plugin. It af...

Jun 6, 2025
CVE-2025-30999
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 6, 2025
CVE-2023-25995
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 6, 2025
CVE-2025-39396
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

May 19, 2025
CVE-2025-26735
7.5

This CVE describes a PHP remote file inclusion vulnerability in the Grip WordPress theme. Attackers can include arbitrary remote files, potentially le...

May 19, 2025
CVE-2025-39364
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

May 19, 2025
CVE-2025-48136
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

May 16, 2025
CVE-2025-39507
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

May 16, 2025
CVE-2025-47653
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

May 7, 2025
CVE-2025-47531
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

May 7, 2025
CVE-2025-47510
7.5

This vulnerability allows attackers to include local PHP files through improper filename control in the Display Eventbrite Events WordPress plugin. At...

May 7, 2025
CVE-2025-47508
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the GamiPress WordPress plugin. Attackers can include arbitrary local files through imp...

May 7, 2025
CVE-2025-47496
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

May 7, 2025
CVE-2025-47498
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

May 7, 2025
CVE-2025-47494
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

May 7, 2025
CVE-2025-47439
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

May 7, 2025
CVE-2025-39387
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 24, 2025
CVE-2025-39391
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 24, 2025
CVE-2025-39399
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 24, 2025
CVE-2025-39378
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 24, 2025
CVE-2025-39383
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 24, 2025
CVE-2025-32921
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in the Arrival WordPress theme. Attackers c...

Apr 24, 2025
CVE-2025-39360
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 24, 2025
CVE-2025-39452
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 17, 2025
CVE-2025-39461
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Docket Cache WordPress plugin. Attackers can include arbitrary local files on the s...

Apr 17, 2025
CVE-2025-39429
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Széchenyi 2020 Logo WordPress plugin. Attackers can exploit improper filename cont...

Apr 17, 2025
CVE-2025-31030
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Ray Enterprise Translation WordPress plugin. Attackers can exploit improper filenam...

Apr 17, 2025
CVE-2025-39584
7.5

This vulnerability allows attackers to include local files on the server through improper input validation in the Eventin WordPress plugin. Attackers ...

Apr 16, 2025
CVE-2025-39592
7.5

This vulnerability allows attackers to include arbitrary local files on the server through PHP's include/require statements in the Subscribe to Unlock...

Apr 16, 2025
CVE-2025-26889
7.5

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the hockeydata LOS WordPress plug...

Apr 15, 2025
CVE-2025-31014
7.5

This vulnerability allows attackers to include local files on the server through PHP's include/require statements, potentially leading to sensitive in...

Apr 11, 2025
CVE-2025-22279
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Apr 10, 2025
CVE-2025-32158
7.5

This vulnerability allows attackers to include arbitrary PHP files from remote servers in the aThemes Addons for Elementor WordPress plugin. Attackers...

Apr 10, 2025
CVE-2025-32692
7.5

This vulnerability allows attackers to include local PHP files through improper filename control in the WP Subscription Forms WordPress plugin. Attack...

Apr 9, 2025
CVE-2025-32156
7.5

This vulnerability allows attackers to include local files on the server through improper input validation in the Just Post Preview Widget WordPress p...

Apr 4, 2025
CVE-2025-32159
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Apr 4, 2025
CVE-2025-32150
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 4, 2025
CVE-2025-32152
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 4, 2025
CVE-2025-32154
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 4, 2025
CVE-2025-31098
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the DeBounce Email Validator WordPress plugin. Attackers can exploit improper filename ...

Apr 3, 2025
CVE-2025-30782
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Apr 1, 2025
CVE-2025-30835
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Mar 31, 2025
CVE-2025-31016
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the JetWooBuilder WordPress plugin. Attackers can include arbitrary local files through...

Mar 31, 2025
CVE-2025-31387
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Mar 31, 2025
CVE-2025-31432
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Pop-Up Chop Chop WordPress plugin. Attackers can include arbitrary local files, pot...

Mar 28, 2025
CVE-2025-26890
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the HUSKY plugin for WordPress. Attackers can exploit improper filename control in incl...

Mar 27, 2025

About CWE-98 (CWE-98)

Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.

External reference: View CWE-98 on MITRE CWE →

Monitor CWE-98 Vulnerabilities

Get alerted when new CWE-98 CVEs affect your infrastructure.

Start Monitoring Free