CWE-98: CWE-98

608
Total CVEs
81
Critical
513
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
120
2025
446
2024
38
2023
3
2021
1

Top Affected Vendors

1 Axiomthemes 58
2 Ancorathemes 12
3 Thememove 12
4 Qodeinteractive 9
5 Themehorse 3
6 Joomsky 2
7 G5plus 2
8 Wptravelengine 2
9 Themewinter 2
10 La Studioweb 2

All CWE-98 CVEs (608)

CVE-2025-30890
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Mar 27, 2025
CVE-2025-30868
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the DynamicWebLab Team Manager WordPress plugin. Attackers can include arbitrary local ...

Mar 27, 2025
CVE-2025-30871
7.5

This vulnerability allows attackers to include local files on the server through improper input validation in WP Travel Engine WordPress plugin. Attac...

Mar 27, 2025
CVE-2025-30845
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Mar 27, 2025
CVE-2025-30829
7.5

This vulnerability allows attackers to include local files on the server through improper input validation in the WPCafe WordPress plugin. Attackers c...

Mar 27, 2025
CVE-2025-30831
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Mar 27, 2025
CVE-2025-30820
7.5

This vulnerability allows attackers to include local files on the server through improper input validation in the WishSuite WordPress plugin. Attacker...

Mar 27, 2025
CVE-2025-30814
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Mar 27, 2025
CVE-2025-30785
7.5

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Subscribe to Download Lite Wo...

Mar 27, 2025
CVE-2025-27015
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Mar 26, 2025
CVE-2025-26979
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 25, 2025
CVE-2025-26957
7.5

This vulnerability allows attackers to include local files on the server through the Affiliate Coupons WordPress plugin. Attackers can potentially rea...

Feb 25, 2025
CVE-2025-26964
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 25, 2025
CVE-2025-26932
7.5

This CVE describes a PHP Local File Inclusion vulnerability in QuantumCloud ChatBot WordPress plugin. Attackers can include arbitrary local files thro...

Feb 25, 2025
CVE-2025-27272
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 24, 2025
CVE-2024-13592
7.5

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to perform Local File Inclusion attacks via the 'team-...

Feb 19, 2025
CVE-2025-25141
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Feb 7, 2025
CVE-2024-13408
7.5

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to include and execute arbitrary PHP files on the serv...

Jan 24, 2025
CVE-2024-13593
7.5

The BMLT Meeting Map WordPress plugin has a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level access or hi...

Jan 23, 2025
CVE-2025-23938
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 22, 2025
CVE-2025-22311
7.5

This vulnerability allows attackers to include arbitrary local files via PHP's include/require statements in the Private Messages for UserPro WordPres...

Jan 21, 2025
CVE-2025-23915
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the FAT Event Lite WordPress plugin, allowing authenticated attackers to include arbitr...

Jan 16, 2025
CVE-2025-22364
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 7, 2025
CVE-2024-56281
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 7, 2025
CVE-2024-56282
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 7, 2025
CVE-2024-56230
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 31, 2024
CVE-2024-54376
7.5

This vulnerability allows attackers to include arbitrary local files via PHP's include/require statements in the EazyDocs WordPress plugin. Attackers ...

Dec 16, 2024
CVE-2024-54225
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the CodegearThemes Designer WordPress plugin, allowing attackers to include and execute...

Dec 9, 2024
CVE-2024-53824
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 6, 2024
CVE-2024-52501
7.5

This vulnerability allows attackers to include and execute arbitrary PHP files from remote servers in the Office Locator WordPress plugin. It affects ...

Nov 28, 2024
CVE-2024-52496
7.5

This vulnerability allows attackers to include local PHP files through improper filename control in the Absolute Addons for Elementor WordPress plugin...

Nov 28, 2024
CVE-2024-50436
7.5

This vulnerability allows attackers to include arbitrary local files through improper filename control in PHP's include/require statements in the Clea...

Oct 28, 2024
CVE-2024-50457
7.5

This vulnerability allows attackers to include arbitrary local files in WordPress sites using the Qode Essential Addons plugin. Attackers can potentia...

Oct 28, 2024
CVE-2024-50434
7.5

This vulnerability allows attackers to include arbitrary local files in the NewsCard WordPress theme, potentially leading to remote code execution. It...

Oct 28, 2024
CVE-2024-49701
7.5

This vulnerability allows attackers to include and execute arbitrary PHP files on WordPress sites using the Mags theme. Attackers can achieve remote c...

Oct 23, 2024
CVE-2024-49243
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Oct 18, 2024
CVE-2024-49251
7.5

This vulnerability allows attackers to include local PHP files through improper filename control in the Maan Addons For Elementor WordPress plugin. At...

Oct 16, 2024
CVE-2024-48029
7.5

This vulnerability allows attackers to include local files on the server through the SB Random Posts Widget WordPress plugin. Attackers can potentiall...

Oct 16, 2024
CVE-2023-52325
7.5

A local file inclusion vulnerability in Trend Micro Apex Central widgets could allow remote attackers to execute arbitrary code on affected systems. T...

Jan 23, 2024
CVE-2025-62066
7.4

This vulnerability allows attackers to include and execute arbitrary PHP files on servers running the Revolution WordPress theme. Attackers can achiev...

Nov 6, 2025
CVE-2025-49935
7.4

This CVE describes a PHP Local File Inclusion vulnerability in the WoodMart WordPress theme. Attackers can include arbitrary local files through impro...

Oct 22, 2025
CVE-2025-49921
7.3

This vulnerability allows attackers to include local PHP files through improper filename control in the JetReviews WordPress plugin. It affects all Wo...

Oct 22, 2025
CVE-2024-51319
7.3

This vulnerability allows authenticated attackers to include local files and upload malicious JSP files to achieve remote code execution on Zucchetti ...

Mar 11, 2025
CVE-2024-8392
7.2

The WordPress Sogrid plugin (versions up to 1.5.2) contains a Local File Inclusion vulnerability via the 'tab' parameter. This allows authenticated at...

Oct 26, 2024
CVE-2025-66115
6.6

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Nov 21, 2025
CVE-2024-8393
6.6

The WooCommerce Blocks - Woolook WordPress plugin contains a Local File Inclusion vulnerability that allows authenticated administrators to include an...

Aug 16, 2025
CVE-2025-51057
6.5

This CVE describes a local file inclusion vulnerability in Vedo Suite version 2024.17 that allows authenticated remote attackers to read arbitrary fil...

Aug 6, 2025
CVE-2025-25539
6.5

A Local File Inclusion vulnerability in Vasco v3.14 and earlier allows remote attackers to read sensitive files on the server through the help menu fu...

May 21, 2025
CVE-2025-24782
6.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 27, 2025
CVE-2025-24733
6.5

This CVE describes a PHP Local File Inclusion vulnerability in the Post Grid Master WordPress plugin. Attackers can exploit improper filename control ...

Jan 24, 2025

About CWE-98 (CWE-98)

Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.

External reference: View CWE-98 on MITRE CWE →

Monitor CWE-98 Vulnerabilities

Get alerted when new CWE-98 CVEs affect your infrastructure.

Start Monitoring Free