CWE-98: CWE-98
Yearly Trend
Top Affected Vendors
All CWE-98 CVEs (608)
This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Mar 27, 2025This CVE describes a PHP Local File Inclusion vulnerability in the DynamicWebLab Team Manager WordPress plugin. Attackers can include arbitrary local ...
Mar 27, 2025This vulnerability allows attackers to include local files on the server through improper input validation in WP Travel Engine WordPress plugin. Attac...
Mar 27, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Mar 27, 2025This vulnerability allows attackers to include local files on the server through improper input validation in the WPCafe WordPress plugin. Attackers c...
Mar 27, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Mar 27, 2025This vulnerability allows attackers to include local files on the server through improper input validation in the WishSuite WordPress plugin. Attacker...
Mar 27, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Mar 27, 2025This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Subscribe to Download Lite Wo...
Mar 27, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Mar 26, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Feb 25, 2025This vulnerability allows attackers to include local files on the server through the Affiliate Coupons WordPress plugin. Attackers can potentially rea...
Feb 25, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Feb 25, 2025This CVE describes a PHP Local File Inclusion vulnerability in QuantumCloud ChatBot WordPress plugin. Attackers can include arbitrary local files thro...
Feb 25, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Feb 24, 2025This vulnerability allows authenticated WordPress users with Contributor-level access or higher to perform Local File Inclusion attacks via the 'team-...
Feb 19, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Feb 7, 2025This vulnerability allows authenticated WordPress users with Contributor-level access or higher to include and execute arbitrary PHP files on the serv...
Jan 24, 2025The BMLT Meeting Map WordPress plugin has a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level access or hi...
Jan 23, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Jan 22, 2025This vulnerability allows attackers to include arbitrary local files via PHP's include/require statements in the Private Messages for UserPro WordPres...
Jan 21, 2025This CVE describes a PHP Local File Inclusion vulnerability in the FAT Event Lite WordPress plugin, allowing authenticated attackers to include arbitr...
Jan 16, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Jan 7, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Jan 7, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Jan 7, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 31, 2024This vulnerability allows attackers to include arbitrary local files via PHP's include/require statements in the EazyDocs WordPress plugin. Attackers ...
Dec 16, 2024This CVE describes a PHP Local File Inclusion vulnerability in the CodegearThemes Designer WordPress plugin, allowing attackers to include and execute...
Dec 9, 2024This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 6, 2024This vulnerability allows attackers to include and execute arbitrary PHP files from remote servers in the Office Locator WordPress plugin. It affects ...
Nov 28, 2024This vulnerability allows attackers to include local PHP files through improper filename control in the Absolute Addons for Elementor WordPress plugin...
Nov 28, 2024This vulnerability allows attackers to include arbitrary local files through improper filename control in PHP's include/require statements in the Clea...
Oct 28, 2024This vulnerability allows attackers to include arbitrary local files in WordPress sites using the Qode Essential Addons plugin. Attackers can potentia...
Oct 28, 2024This vulnerability allows attackers to include arbitrary local files in the NewsCard WordPress theme, potentially leading to remote code execution. It...
Oct 28, 2024This vulnerability allows attackers to include and execute arbitrary PHP files on WordPress sites using the Mags theme. Attackers can achieve remote c...
Oct 23, 2024This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Oct 18, 2024This vulnerability allows attackers to include local PHP files through improper filename control in the Maan Addons For Elementor WordPress plugin. At...
Oct 16, 2024This vulnerability allows attackers to include local files on the server through the SB Random Posts Widget WordPress plugin. Attackers can potentiall...
Oct 16, 2024A local file inclusion vulnerability in Trend Micro Apex Central widgets could allow remote attackers to execute arbitrary code on affected systems. T...
Jan 23, 2024This vulnerability allows attackers to include and execute arbitrary PHP files on servers running the Revolution WordPress theme. Attackers can achiev...
Nov 6, 2025This CVE describes a PHP Local File Inclusion vulnerability in the WoodMart WordPress theme. Attackers can include arbitrary local files through impro...
Oct 22, 2025This vulnerability allows attackers to include local PHP files through improper filename control in the JetReviews WordPress plugin. It affects all Wo...
Oct 22, 2025This vulnerability allows authenticated attackers to include local files and upload malicious JSP files to achieve remote code execution on Zucchetti ...
Mar 11, 2025The WordPress Sogrid plugin (versions up to 1.5.2) contains a Local File Inclusion vulnerability via the 'tab' parameter. This allows authenticated at...
Oct 26, 2024This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Nov 21, 2025The WooCommerce Blocks - Woolook WordPress plugin contains a Local File Inclusion vulnerability that allows authenticated administrators to include an...
Aug 16, 2025This CVE describes a local file inclusion vulnerability in Vedo Suite version 2024.17 that allows authenticated remote attackers to read arbitrary fil...
Aug 6, 2025A Local File Inclusion vulnerability in Vasco v3.14 and earlier allows remote attackers to read sensitive files on the server through the help menu fu...
May 21, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Jan 27, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Post Grid Master WordPress plugin. Attackers can exploit improper filename control ...
Jan 24, 2025About CWE-98 (CWE-98)
Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.
External reference: View CWE-98 on MITRE CWE →
Monitor CWE-98 Vulnerabilities
Get alerted when new CWE-98 CVEs affect your infrastructure.
Start Monitoring Free