CWE-98: CWE-98

608
Total CVEs
81
Critical
513
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
120
2025
446
2024
38
2023
3
2021
1

Top Affected Vendors

1 Axiomthemes 58
2 Ancorathemes 12
3 Thememove 12
4 Qodeinteractive 9
5 Themehorse 3
6 Joomsky 2
7 G5plus 2
8 Wptravelengine 2
9 Themewinter 2
10 La Studioweb 2

All CWE-98 CVEs (608)

CVE-2025-60042
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Chinchilla WordPress theme. Attackers can include arbitrary local files through imp...

Dec 18, 2025
CVE-2025-60043
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Wanderic WordPress theme. Attackers can potent...

Dec 18, 2025
CVE-2025-60044
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Fribbo WordPress theme. Attackers can potentia...

Dec 18, 2025
CVE-2025-58948
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58949
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Spock WordPress theme. It enables PHP Local Fi...

Dec 18, 2025
CVE-2025-58950
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58936
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58937
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58927
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Stallion WordPress theme. Attackers can include arbitrary local files on the server...

Dec 18, 2025
CVE-2025-58928
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58933
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Anubis WordPress theme. Attackers can potentia...

Dec 18, 2025
CVE-2025-58934
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the The Gig WordPress theme. Atta...

Dec 18, 2025
CVE-2025-58899
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 18, 2025
CVE-2025-58900
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the UniTravel WordPress theme. Attackers can poten...

Dec 18, 2025
CVE-2025-58901
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Takeout WordPress theme. Attackers can read se...

Dec 18, 2025
CVE-2025-58923
8.1

This vulnerability allows attackers to include and execute arbitrary local files on servers running the Critique WordPress theme. Attackers can potent...

Dec 18, 2025
CVE-2025-58925
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Neptunus WordPress theme. Attackers can exploit improper filename control in includ...

Dec 18, 2025
CVE-2025-58926
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58709
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Legacy WordPress theme by axiomthemes. Attackers can exploit improper filename cont...

Dec 18, 2025
CVE-2025-58225
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-58706
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Woo Hoo WordPress theme. Atta...

Dec 18, 2025
CVE-2025-58708
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-53446
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Beautique WordPress theme. Attackers can include arbitrary local files through impr...

Dec 18, 2025
CVE-2025-53447
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 18, 2025
CVE-2025-53448
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 18, 2025
CVE-2025-53449
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Convex WordPress theme. Attackers can include arbitrary local files through imprope...

Dec 18, 2025
CVE-2025-53437
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-53438
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements, potentially leading to sensitive in...

Dec 18, 2025
CVE-2025-53439
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-53441
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-53442
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Rentic WordPress theme. Attac...

Dec 18, 2025
CVE-2025-53443
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-53445
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Catwalk WordPress theme. It enables PHP Local ...

Dec 18, 2025
CVE-2025-53429
8.1

This vulnerability allows attackers to include arbitrary local files on the server through the Exit Game WordPress theme. Attackers can potentially re...

Dec 18, 2025
CVE-2025-53430
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Etta WordPress theme. Attackers can potentiall...

Dec 18, 2025
CVE-2025-53431
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Emberlyn WordPress theme, allowing attackers to include and execute arbitrary local...

Dec 18, 2025
CVE-2025-53432
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 18, 2025
CVE-2025-53434
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the ChildHope WordPress theme. Attackers can poten...

Dec 18, 2025
CVE-2025-53435
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Plan My Day WordPress theme. Attackers can include arbitrary local files, potential...

Dec 18, 2025
CVE-2025-53436
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-49941
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-49942
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-49943
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-52745
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Farm Agrico WordPress theme. Attackers can include arbitrary local files through im...

Dec 18, 2025
CVE-2025-52768
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Faith & Hope WordPress theme....

Dec 18, 2025
CVE-2025-49367
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-49368
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Palladio WordPress theme. Attackers can potent...

Dec 18, 2025
CVE-2025-49369
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Lettuce WordPress theme. Attackers can include arbitrary local files on the server,...

Dec 18, 2025
CVE-2025-49370
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-49371
8.1

This vulnerability allows attackers to include and execute arbitrary local files on servers running the Strux WordPress theme. Attackers can potential...

Dec 18, 2025

About CWE-98 (CWE-98)

Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.

External reference: View CWE-98 on MITRE CWE →

Monitor CWE-98 Vulnerabilities

Get alerted when new CWE-98 CVEs affect your infrastructure.

Start Monitoring Free