CWE-98: CWE-98

608
Total CVEs
81
Critical
513
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
120
2025
446
2024
38
2023
3
2021
1

Top Affected Vendors

1 Axiomthemes 58
2 Ancorathemes 12
3 Thememove 12
4 Qodeinteractive 9
5 Themehorse 3
6 Joomsky 2
7 G5plus 2
8 Wptravelengine 2
9 Themewinter 2
10 La Studioweb 2

All CWE-98 CVEs (608)

CVE-2024-12859
8.8

The BoomBox Theme Extensions plugin for WordPress has a Local File Inclusion vulnerability that allows authenticated attackers with contributor-level ...

Feb 3, 2025
CVE-2025-0366
8.8

The Jupiter X Core WordPress plugin has a Local File Inclusion vulnerability that leads to Remote Code Execution. Authenticated attackers with Contrib...

Feb 1, 2025
CVE-2025-0682
8.8

The ThemeREX Addons WordPress plugin has a Local File Inclusion vulnerability that allows authenticated attackers with contributor-level permissions o...

Jan 25, 2025
CVE-2024-12272
8.8

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to perform Local File Inclusion attacks through the WP...

Dec 25, 2024
CVE-2024-12040
8.8

This vulnerability allows authenticated attackers with Contributor-level WordPress access or higher to perform Local File Inclusion via the 'theme' at...

Dec 12, 2024
CVE-2024-11429
8.8

This vulnerability allows authenticated attackers with contributor-level access or higher to perform Local File Inclusion (LFI) via a WordPress shortc...

Dec 5, 2024
CVE-2024-10873
8.8

This vulnerability allows authenticated attackers with Contributor-level WordPress access or higher to perform Local File Inclusion via the _load_temp...

Nov 23, 2024
CVE-2024-10898
8.8

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to include and execute arbitrary PHP files on the serv...

Nov 21, 2024
CVE-2024-10436
8.8

The WPC Smart Messages for WooCommerce WordPress plugin contains a Local File Inclusion vulnerability that allows authenticated attackers with Subscri...

Oct 29, 2024
CVE-2024-8252
8.8

The Clean Login WordPress plugin has a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level access or higher ...

Aug 30, 2024
CVE-2023-2551
8.8

This CVE describes a PHP Remote File Inclusion vulnerability in the bumsys software that allows attackers to include and execute arbitrary remote file...

May 5, 2023
CVE-2023-24217
8.8

AgileBio Electronic Lab Notebook v4.234 contains a local file inclusion vulnerability that allows attackers to read arbitrary files on the server. Thi...

Mar 6, 2023
CVE-2024-37479
8.5

This Local File Inclusion vulnerability in LA-Studio Element Kit for Elementor allows attackers to include arbitrary local files via the 'progress_typ...

Jul 2, 2024
CVE-2025-32925
8.3

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

May 19, 2025
CVE-2025-69040
8.2

This CVE describes a Local File Inclusion vulnerability in the Bfres WordPress theme that allows attackers to include arbitrary PHP files from the ser...

Jan 22, 2026
CVE-2025-69042
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 22, 2026
CVE-2025-69043
8.2

This vulnerability allows attackers to include local PHP files through improper filename control in the Rashy WordPress theme. Attackers can read sens...

Jan 22, 2026
CVE-2025-64205
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 18, 2025
CVE-2025-60072
8.2

This vulnerability allows attackers to include local PHP files through improper filename control in the Anchor Smooth Scroll WordPress plugin. It affe...

Dec 18, 2025
CVE-2025-60063
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-60054
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-60055
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 18, 2025
CVE-2025-60049
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-60050
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 18, 2025
CVE-2025-60051
8.2

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Rare Radio WordPress theme. A...

Dec 18, 2025
CVE-2025-60052
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-60053
8.2

This CVE describes a PHP Local File Inclusion vulnerability in the MaxCube WordPress theme. Attackers can include arbitrary local files through improp...

Dec 18, 2025
CVE-2025-58944
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58945
8.2

This vulnerability allows attackers to include local PHP files through improper filename control in the EcoGrow WordPress theme. Attackers can potenti...

Dec 18, 2025
CVE-2025-58946
8.2

This vulnerability allows attackers to include arbitrary local files through PHP's include/require functions in the Vocal WordPress theme. Attackers c...

Dec 18, 2025
CVE-2025-58947
8.2

This vulnerability allows attackers to include local PHP files through improper filename control in the Athos WordPress theme. It enables PHP Local Fi...

Dec 18, 2025
CVE-2025-58940
8.2

This CVE describes a PHP Local File Inclusion vulnerability in the Basil WordPress theme that allows attackers to include arbitrary local files via im...

Dec 18, 2025
CVE-2025-58941
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58942
8.2

This CVE describes a PHP Local File Inclusion vulnerability in the Dwell WordPress theme by axiomthemes. Attackers can include arbitrary local files t...

Dec 18, 2025
CVE-2025-58943
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58929
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58930
8.2

This vulnerability allows attackers to include local PHP files through improper filename control in the FitFlex WordPress theme. Attackers can read se...

Dec 18, 2025
CVE-2025-58931
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 18, 2025
CVE-2025-58932
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58898
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58889
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58890
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 18, 2025
CVE-2025-58891
8.2

This vulnerability allows attackers to include local PHP files through improper filename control in the Sanger WordPress theme. Attackers can read sen...

Dec 18, 2025
CVE-2025-58892
8.2

This CVE describes a PHP Local File Inclusion vulnerability in the Tourimo WordPress theme that allows attackers to include arbitrary local files via ...

Dec 18, 2025
CVE-2025-58893
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58894
8.2

This vulnerability allows attackers to include local PHP files through improper filename control in the Good Mood WordPress theme. Attackers can poten...

Dec 18, 2025
CVE-2025-58895
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58896
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58803
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 18, 2025
CVE-2025-58879
8.2

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Festy WordPress theme. Attack...

Dec 18, 2025

About CWE-98 (CWE-98)

Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.

External reference: View CWE-98 on MITRE CWE →

Monitor CWE-98 Vulnerabilities

Get alerted when new CWE-98 CVEs affect your infrastructure.

Start Monitoring Free