CWE-98: CWE-98

608
Total CVEs
81
Critical
513
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
120
2025
446
2024
38
2023
3
2021
1

Top Affected Vendors

1 Axiomthemes 58
2 Ancorathemes 12
3 Thememove 12
4 Qodeinteractive 9
5 Themehorse 3
6 Joomsky 2
7 G5plus 2
8 Wptravelengine 2
9 Themewinter 2
10 La Studioweb 2

All CWE-98 CVEs (608)

CVE-2025-48290
9.8

This CVE describes a PHP Local File Inclusion vulnerability in the Kinsley WordPress theme. Attackers can include arbitrary local files on the server,...

Nov 6, 2025
CVE-2025-48330
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Nov 6, 2025
CVE-2025-39468
9.8

This vulnerability allows remote attackers to include and execute arbitrary PHP files on servers running vulnerable versions of the Modal Survey WordP...

Nov 6, 2025
CVE-2025-39463
9.8

This CVE describes a PHP Local File Inclusion vulnerability in the Dessau WordPress theme. Attackers can include arbitrary local files, potentially le...

Nov 6, 2025
CVE-2025-39466
9.8

This vulnerability allows attackers to include and execute arbitrary local PHP files on servers running the vulnerable Mikado-Themes DΓΈr WordPress th...

Nov 6, 2025
CVE-2025-11023
9.8

This CVE describes a PHP Local File Inclusion vulnerability in ArkSigner's AcBakImzala software that allows attackers to include and execute arbitrary...

Oct 23, 2025
CVE-2025-7721
9.8

This vulnerability allows unauthenticated attackers to perform Local File Inclusion (LFI) in the JoomSport WordPress plugin, enabling them to include ...

Oct 3, 2025
CVE-2025-48293
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Aug 14, 2025
CVE-2025-8913
9.8

CVE-2025-8913 is a critical Local File Inclusion vulnerability in WellChoose's Organization Portal System that allows unauthenticated remote attackers...

Aug 13, 2025
CVE-2025-4689
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary code on WordPress servers running the vulnerable Ads Pro Plugin. Attackers ca...

Jul 2, 2025
CVE-2025-46468
9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

May 23, 2025
CVE-2025-39406
9.8

This vulnerability allows attackers to include arbitrary local files through PHP's include/require statements in the WPAMS WordPress plugin. Attackers...

May 19, 2025
CVE-2025-32577
9.8

This vulnerability allows attackers to include local files on the server through PHP's include/require statements, potentially leading to remote code ...

Apr 11, 2025
CVE-2025-28916
9.8

This CVE describes a PHP Local File Inclusion vulnerability in the Docpro WordPress plugin that allows attackers to include arbitrary local files via ...

Mar 26, 2025
CVE-2024-13790
9.8

This vulnerability allows unauthenticated attackers to perform Local File Inclusion (LFI) in the MinimogWP WordPress theme by manipulating the 'templa...

Mar 19, 2025
CVE-2025-1771
9.8

This vulnerability in the Traveler WordPress theme allows unauthenticated attackers to include and execute arbitrary PHP files on the server via a Loc...

Mar 15, 2025
CVE-2024-9193
EPSS 27.8% 9.8

This vulnerability in the WHMpress WordPress plugin allows unauthenticated attackers to include and execute arbitrary PHP files on the server via Loca...

Feb 28, 2025
CVE-2024-49649
9.8

This vulnerability allows attackers to include local files on the server through improper input validation in the Build App Online WordPress plugin. A...

Jan 7, 2025
CVE-2024-12571
9.8

This vulnerability allows unauthenticated attackers to include and execute arbitrary files on WordPress servers running the vulnerable Store Locator p...

Dec 20, 2024
CVE-2024-12209
9.8

The WP Umbrella WordPress plugin has a critical Local File Inclusion vulnerability that allows unauthenticated attackers to include and execute arbitr...

Dec 8, 2024
CVE-2024-10571
9.8

The Chartify WordPress plugin is vulnerable to Local File Inclusion (LFI) via the 'source' parameter, allowing unauthenticated attackers to include an...

Nov 14, 2024
CVE-2024-10871
9.8

The Category Ajax Filter WordPress plugin has a Local File Inclusion vulnerability that allows unauthenticated attackers to include and execute arbitr...

Nov 9, 2024
CVE-2024-41925
9.8

This critical vulnerability in ONS-S8 Spectra Aggregation Switch web service allows attackers to bypass authentication, traverse directories, and exec...

Oct 3, 2024
CVE-2024-33863
9.8

This vulnerability allows attackers to perform local file inclusion via the /api/Cdn/GetFile endpoint in linqi on Windows systems. Attackers can read ...

May 14, 2024
CVE-2021-21804
9.8

This CVE describes a local file inclusion vulnerability in Advantech R-SeeNet's options.php script that allows attackers to execute arbitrary PHP code...

Jul 16, 2021
CVE-2025-26909
9.6

This vulnerability allows attackers to include arbitrary local files through PHP's include/require statements in the Hide My WP Ghost WordPress plugin...

Mar 27, 2025
CVE-2024-43261
9.6

This vulnerability allows attackers to include remote PHP files through improper filename control in the Compute Links WordPress plugin. Attackers can...

Aug 19, 2024
CVE-2024-1600
9.3

This CVE describes a Local File Inclusion vulnerability in the parisneo/lollms-webui application that allows attackers to read arbitrary files on the ...

Apr 10, 2024
CVE-2024-36415
9.1

This vulnerability in SuiteCRM allows attackers to upload malicious files that bypass verification checks, leading to remote code execution. All Suite...

Jun 10, 2024
CVE-2025-47586
9.0

This CVE describes an unauthenticated Local File Inclusion vulnerability in the WordPress Motors - Events plugin by StylemixThemes. Attackers can incl...

Jun 6, 2025
CVE-2025-26916
9.0

This vulnerability allows unauthenticated attackers to include arbitrary local files in PHP applications, potentially leading to remote code execution...

Mar 10, 2025
CVE-2025-15368
8.8

The SportsPress WordPress plugin has a Local File Inclusion vulnerability in all versions up to 2.7.26. Authenticated attackers with contributor-level...

Feb 4, 2026
CVE-2025-68645
KEV EPSS 29.3% 8.8

An unauthenticated remote attacker can exploit this Local File Inclusion vulnerability in Zimbra Collaboration's Webmail Classic UI to read arbitrary ...

Dec 22, 2025
CVE-2025-13641
8.8

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to include and execute arbitrary PHP files on the serv...

Dec 18, 2025
CVE-2025-13088
8.8

The Category and Product Woocommerce Tabs WordPress plugin has a Local File Inclusion vulnerability that allows authenticated attackers with contribut...

Nov 18, 2025
CVE-2025-11920
8.8

The WPCOM Member WordPress plugin has a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level access or higher...

Nov 1, 2025
CVE-2025-60126
8.8

This CVE describes a PHP Local File Inclusion vulnerability in the WordPress Testimonial Slider plugin. Attackers can exploit improper filename contro...

Sep 26, 2025
CVE-2025-8142
8.8

The Soledad WordPress theme contains a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level access or higher ...

Aug 16, 2025
CVE-2025-6746
8.8

The WoodMart WordPress theme plugin contains a Local File Inclusion vulnerability in the 'layout' attribute that allows authenticated attackers with C...

Jul 8, 2025
CVE-2025-7327
8.8

The Widget for Google Reviews WordPress plugin contains a directory traversal vulnerability that allows authenticated attackers with Subscriber-level ...

Jul 8, 2025
CVE-2025-47576
8.8

This vulnerability allows attackers to include arbitrary files from remote servers in PHP applications, potentially leading to remote code execution. ...

May 19, 2025
CVE-2025-32614
8.8

This vulnerability allows attackers to include local files on the server through improper input validation in EventON WordPress plugin. Attackers can ...

Apr 11, 2025
CVE-2025-32141
8.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 4, 2025
CVE-2025-32146
8.8

This vulnerability allows attackers to include local files on the server through improper input validation in JS Job Manager's PHP code. Attackers can...

Apr 4, 2025
CVE-2025-30891
8.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Mar 27, 2025
CVE-2025-30846
8.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Mar 27, 2025
CVE-2024-12563
8.8

The s2Member Pro WordPress plugin has a Local File Inclusion vulnerability that allows authenticated attackers with contributor-level permissions or h...

Mar 18, 2025
CVE-2025-1707
8.8

The Review Schema WordPress plugin has a Local File Inclusion vulnerability that allows authenticated attackers with contributor-level permissions or ...

Mar 11, 2025
CVE-2024-12811
8.8

The Traveler WordPress theme has a Local File Inclusion vulnerability in the 'hotel_alone_slider' shortcode that allows authenticated attackers with c...

Feb 28, 2025
CVE-2024-13353
8.8

This vulnerability allows authenticated attackers with Contributor-level access or higher to perform Local File Inclusion (LFI) in the Responsive Addo...

Feb 21, 2025

About CWE-98 (CWE-98)

Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.

External reference: View CWE-98 on MITRE CWE →

Monitor CWE-98 Vulnerabilities

Get alerted when new CWE-98 CVEs affect your infrastructure.

Start Monitoring Free