CWE-98: CWE-98

608
Total CVEs
81
Critical
513
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
120
2025
446
2024
38
2023
3
2021
1

Top Affected Vendors

1 Axiomthemes 58
2 Ancorathemes 12
3 Thememove 12
4 Qodeinteractive 9
5 Themehorse 3
6 Joomsky 2
7 G5plus 2
8 Wptravelengine 2
9 Themewinter 2
10 La Studioweb 2

All CWE-98 CVEs (608)

CVE-2025-58885
8.2

This CVE describes a PHP Local File Inclusion vulnerability in the Pathfinder WordPress theme. Attackers can include arbitrary local files, potentiall...

Dec 18, 2025
CVE-2025-58888
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-53453
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-60199
8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Nov 6, 2025
CVE-2025-60197
8.2

This vulnerability allows attackers to include local files on the server through improper input validation in the Simple Contact Forms WordPress plugi...

Nov 6, 2025
CVE-2026-22376
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Parkivia WordPress theme. Att...

Feb 20, 2026
CVE-2026-22378
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 20, 2026
CVE-2026-22380
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 20, 2026
CVE-2026-22370
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 20, 2026
CVE-2026-22372
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 20, 2026
CVE-2026-22374
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 20, 2026
CVE-2026-22362
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 20, 2026
CVE-2026-22364
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Feb 20, 2026
CVE-2026-22366
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 20, 2026
CVE-2026-22368
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Redy WordPress theme by axiomthemes, allowing attackers to include arbitrary local ...

Feb 20, 2026
CVE-2026-22344
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 20, 2026
CVE-2025-69409
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the PJ | Life & Business Coaching WordPress theme. Attackers can include arbitrary loca...

Feb 20, 2026
CVE-2025-69407
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Struktur WordPress theme. Attackers can include arbitrary local files through impro...

Feb 20, 2026
CVE-2025-69395
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the ThemeREX Gable WordPress theme. Attackers can ...

Feb 20, 2026
CVE-2025-69397
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the ThemeREX Tint WordPress theme. Attackers can exploit improper filename control in i...

Feb 20, 2026
CVE-2025-69399
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the ThemeREX Cobble WordPress theme. Attackers can include arbitrary local files throug...

Feb 20, 2026
CVE-2025-69375
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the SolverWp Portfolio Builder WordPress plugin. Attackers can exploit improper filenam...

Feb 20, 2026
CVE-2025-69322
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the PeakShops WordPress theme. Attackers can poten...

Feb 20, 2026
CVE-2025-68536
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 20, 2026
CVE-2025-68543
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 20, 2026
CVE-2025-67992
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 20, 2026
CVE-2025-67980
8.1

This CVE describes a Local File Inclusion (LFI) vulnerability in the Hara WordPress theme that allows attackers to include arbitrary local files throu...

Feb 20, 2026
CVE-2025-67982
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Urna WordPress theme. Attackers can exploit improper filename control in include/re...

Feb 20, 2026
CVE-2025-69314
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 22, 2026
CVE-2025-69078
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Malta WordPress theme. Attack...

Jan 22, 2026
CVE-2025-69100
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the North WordPress theme. Attackers can potential...

Jan 22, 2026
CVE-2025-69071
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 22, 2026
CVE-2025-69072
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 22, 2026
CVE-2025-69073
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Jan 22, 2026
CVE-2025-69074
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 22, 2026
CVE-2025-69075
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Yolox WordPress theme. Attackers can potential...

Jan 22, 2026
CVE-2025-69076
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 22, 2026
CVE-2025-69077
8.1

This vulnerability allows attackers to include local files on the server through improper input validation in the Hobo WordPress theme. Attackers can ...

Jan 22, 2026
CVE-2025-69062
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Weedles WordPress theme. Attackers can include arbitrary local files through improp...

Jan 22, 2026
CVE-2025-69064
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Pets Land WordPress theme. At...

Jan 22, 2026
CVE-2025-69065
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 22, 2026
CVE-2025-69066
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Indoor Plants WordPress theme...

Jan 22, 2026
CVE-2025-69067
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the AncoraThemes Tails WordPress theme. Attackers can exploit improper filename control...

Jan 22, 2026
CVE-2025-69068
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Muji WordPress theme. Attackers can potentiall...

Jan 22, 2026
CVE-2025-69070
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Tornados WordPress theme. Attackers can potent...

Jan 22, 2026
CVE-2025-69057
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 22, 2026
CVE-2025-69058
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the PartyMaker WordPress theme. Attackers can pote...

Jan 22, 2026
CVE-2025-69059
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the DiveIt WordPress theme that allows attackers to include arbitrary local files via i...

Jan 22, 2026
CVE-2025-69060
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 22, 2026
CVE-2025-69061
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the MoveMe WordPress theme. Attackers can exploit improper filename control in include/...

Jan 22, 2026

About CWE-98 (CWE-98)

Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.

External reference: View CWE-98 on MITRE CWE →

Monitor CWE-98 Vulnerabilities

Get alerted when new CWE-98 CVEs affect your infrastructure.

Start Monitoring Free