CWE-98: CWE-98

608
Total CVEs
81
Critical
513
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
120
2025
446
2024
38
2023
3
2021
1

Top Affected Vendors

1 Axiomthemes 58
2 Ancorathemes 12
3 Thememove 12
4 Qodeinteractive 9
5 Themehorse 3
6 Joomsky 2
7 G5plus 2
8 Wptravelengine 2
9 Themewinter 2
10 La Studioweb 2

All CWE-98 CVEs (608)

CVE-2025-49360
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-49361
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Mamita WordPress theme. Attackers can potentia...

Dec 18, 2025
CVE-2025-49362
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-49363
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-49364
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-49365
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Jack Well WordPress theme. Attackers can read ...

Dec 18, 2025
CVE-2025-49366
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Hanani WordPress theme. Attackers can potentia...

Dec 18, 2025
CVE-2025-49359
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the ShieldGroup WordPress theme. ...

Dec 18, 2025
CVE-2025-14475
8.1

This vulnerability allows unauthenticated attackers to execute arbitrary PHP code on WordPress sites using the Extensive VC Addons plugin. Attackers c...

Dec 13, 2025
CVE-2025-64287
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Alloggio WordPress theme for hotel booking websites. Attackers can exploit improper...

Nov 6, 2025
CVE-2025-62045
8.1

This vulnerability allows remote attackers to include and execute arbitrary PHP files on servers running vulnerable versions of TheGem Theme Elements ...

Nov 6, 2025
CVE-2025-62014
8.1

This vulnerability allows attackers to include and execute arbitrary PHP files on servers running the ITok WordPress theme. Attackers can achieve remo...

Nov 6, 2025
CVE-2025-60198
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Nov 6, 2025
CVE-2025-60190
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Immocaster WordPress plugin that allows attackers to include arbitrary local files ...

Nov 6, 2025
CVE-2025-58994
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Nov 6, 2025
CVE-2025-58995
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Nov 6, 2025
CVE-2025-12497
8.1

This vulnerability allows unauthenticated attackers to include and execute arbitrary PHP files on WordPress servers running the vulnerable Premium Por...

Nov 5, 2025
CVE-2025-62868
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Edge CPT WordPress plugin, allowing attackers to include arbitrary local files via ...

Oct 24, 2025
CVE-2025-62029
8.1

This vulnerability allows attackers to include arbitrary local files through improper filename control in PHP's include/require statements in the Grev...

Oct 22, 2025
CVE-2025-59564
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Oct 22, 2025
CVE-2025-59555
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Oct 22, 2025
CVE-2025-9991
8.1

The Tiny Bootstrap Elements Light WordPress plugin contains a Local File Inclusion vulnerability that allows unauthenticated attackers to include and ...

Sep 30, 2025
CVE-2025-58215
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Sep 9, 2025
CVE-2025-58214
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Sep 5, 2025
CVE-2025-9990
8.1

The WordPress Helpdesk Integration plugin has a Local File Inclusion vulnerability that allows unauthenticated attackers to include and execute arbitr...

Sep 5, 2025
CVE-2025-47696
8.1

This vulnerability allows unauthenticated attackers to include local files on WordPress servers running vulnerable versions of Blog Designer PRO plugi...

Aug 31, 2025
CVE-2025-54716
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Ireca WordPress theme that allows attackers to include arbitrary local files throug...

Aug 28, 2025
CVE-2025-53578
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Kipso WordPress theme that allows attackers to include arbitrary local files via im...

Aug 28, 2025
CVE-2025-53248
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Unfoldwp Magazine WordPress theme. Attackers can include arbitrary local files thro...

Aug 28, 2025
CVE-2025-53244
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Magazine Elite WordPress them...

Aug 28, 2025
CVE-2025-53216
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Aug 28, 2025
CVE-2025-49383
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Aug 28, 2025
CVE-2025-54031
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Aug 20, 2025
CVE-2025-53567
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Ghost Kit WordPress plugin. Attackers can exploit improper filename control in incl...

Aug 20, 2025
CVE-2025-53204
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the eventlist WordPress plugin. Attackers can include arbitrary local files through imp...

Aug 20, 2025
CVE-2025-53207
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Aug 20, 2025
CVE-2025-53198
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Aug 20, 2025
CVE-2025-48171
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Aug 20, 2025
CVE-2025-48160
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Aug 20, 2025
CVE-2025-54701
8.1

This vulnerability allows attackers to include and execute local PHP files on servers running the Unicamp WordPress theme. Attackers can potentially r...

Aug 14, 2025
CVE-2025-54700
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require functions in the Makeaholic WordPress theme. At...

Aug 14, 2025
CVE-2025-54689
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Urna WordPress theme. Attackers can include arbitrary local files through improper ...

Aug 14, 2025
CVE-2025-4414
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the CMSMasters Content Composer WordPress plugin. ...

Jul 4, 2025
CVE-2025-4380
EPSS 16.5% 8.1

This vulnerability allows unauthenticated attackers to include and execute arbitrary PHP files on WordPress servers running the Ads Pro Plugin. Attack...

Jul 2, 2025
CVE-2025-52812
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Jun 27, 2025
CVE-2025-52815
8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the CityGov WordPress theme. Attackers can read se...

Jun 27, 2025
CVE-2025-52808
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements, potentially leading to sensitive in...

Jun 27, 2025
CVE-2025-52729
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Diza WordPress theme. Attackers can include arbitrary local files through improper ...

Jun 27, 2025
CVE-2025-52723
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Networker WordPress theme that allows attackers to include arbitrary local files th...

Jun 27, 2025
CVE-2025-49883
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 27, 2025

About CWE-98 (CWE-98)

Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.

External reference: View CWE-98 on MITRE CWE →

Monitor CWE-98 Vulnerabilities

Get alerted when new CWE-98 CVEs affect your infrastructure.

Start Monitoring Free