CWE-98: CWE-98
Yearly Trend
Top Affected Vendors
All CWE-98 CVEs (608)
This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 18, 2025This vulnerability allows attackers to include local PHP files through improper filename control in the Mamita WordPress theme. Attackers can potentia...
Dec 18, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 18, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 18, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Dec 18, 2025This vulnerability allows attackers to include local PHP files through improper filename control in the Jack Well WordPress theme. Attackers can read ...
Dec 18, 2025This vulnerability allows attackers to include local PHP files through improper filename control in the Hanani WordPress theme. Attackers can potentia...
Dec 18, 2025This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the ShieldGroup WordPress theme. ...
Dec 18, 2025This vulnerability allows unauthenticated attackers to execute arbitrary PHP code on WordPress sites using the Extensive VC Addons plugin. Attackers c...
Dec 13, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Alloggio WordPress theme for hotel booking websites. Attackers can exploit improper...
Nov 6, 2025This vulnerability allows remote attackers to include and execute arbitrary PHP files on servers running vulnerable versions of TheGem Theme Elements ...
Nov 6, 2025This vulnerability allows attackers to include and execute arbitrary PHP files on servers running the ITok WordPress theme. Attackers can achieve remo...
Nov 6, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Nov 6, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Immocaster WordPress plugin that allows attackers to include arbitrary local files ...
Nov 6, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Nov 6, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Nov 6, 2025This vulnerability allows unauthenticated attackers to include and execute arbitrary PHP files on WordPress servers running the vulnerable Premium Por...
Nov 5, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Edge CPT WordPress plugin, allowing attackers to include arbitrary local files via ...
Oct 24, 2025This vulnerability allows attackers to include arbitrary local files through improper filename control in PHP's include/require statements in the Grev...
Oct 22, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Oct 22, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Oct 22, 2025The Tiny Bootstrap Elements Light WordPress plugin contains a Local File Inclusion vulnerability that allows unauthenticated attackers to include and ...
Sep 30, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Sep 9, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Sep 5, 2025The WordPress Helpdesk Integration plugin has a Local File Inclusion vulnerability that allows unauthenticated attackers to include and execute arbitr...
Sep 5, 2025This vulnerability allows unauthenticated attackers to include local files on WordPress servers running vulnerable versions of Blog Designer PRO plugi...
Aug 31, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Ireca WordPress theme that allows attackers to include arbitrary local files throug...
Aug 28, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Kipso WordPress theme that allows attackers to include arbitrary local files via im...
Aug 28, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Unfoldwp Magazine WordPress theme. Attackers can include arbitrary local files thro...
Aug 28, 2025This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Magazine Elite WordPress them...
Aug 28, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Aug 28, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Aug 28, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Aug 20, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Ghost Kit WordPress plugin. Attackers can exploit improper filename control in incl...
Aug 20, 2025This CVE describes a PHP Local File Inclusion vulnerability in the eventlist WordPress plugin. Attackers can include arbitrary local files through imp...
Aug 20, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Aug 20, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Aug 20, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Aug 20, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Aug 20, 2025This vulnerability allows attackers to include and execute local PHP files on servers running the Unicamp WordPress theme. Attackers can potentially r...
Aug 14, 2025This vulnerability allows attackers to include local files on the server through PHP's include/require functions in the Makeaholic WordPress theme. At...
Aug 14, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Urna WordPress theme. Attackers can include arbitrary local files through improper ...
Aug 14, 2025This vulnerability allows attackers to include local PHP files through improper filename control in the CMSMasters Content Composer WordPress plugin. ...
Jul 4, 2025This vulnerability allows unauthenticated attackers to include and execute arbitrary PHP files on WordPress servers running the Ads Pro Plugin. Attack...
Jul 2, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
Jun 27, 2025This vulnerability allows attackers to include local PHP files through improper filename control in the CityGov WordPress theme. Attackers can read se...
Jun 27, 2025This vulnerability allows attackers to include local files on the server through PHP's include/require statements, potentially leading to sensitive in...
Jun 27, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Diza WordPress theme. Attackers can include arbitrary local files through improper ...
Jun 27, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Networker WordPress theme that allows attackers to include arbitrary local files th...
Jun 27, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
Jun 27, 2025About CWE-98 (CWE-98)
Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.
External reference: View CWE-98 on MITRE CWE →
Monitor CWE-98 Vulnerabilities
Get alerted when new CWE-98 CVEs affect your infrastructure.
Start Monitoring Free