CWE-98: CWE-98

608
Total CVEs
81
Critical
513
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
120
2025
446
2024
38
2023
3
2021
1

Top Affected Vendors

1 Axiomthemes 58
2 Ancorathemes 12
3 Thememove 12
4 Qodeinteractive 9
5 Themehorse 3
6 Joomsky 2
7 G5plus 2
8 Wptravelengine 2
9 Themewinter 2
10 La Studioweb 2

All CWE-98 CVEs (608)

CVE-2025-30992
8.1

This CVE describes a Local File Inclusion vulnerability in the Puca WordPress theme that allows attackers to include arbitrary local files via imprope...

Jun 27, 2025
CVE-2025-28998
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 27, 2025
CVE-2025-28990
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 27, 2025
CVE-2025-28947
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 27, 2025
CVE-2025-24769
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 27, 2025
CVE-2025-24760
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 27, 2025
CVE-2025-49261
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 17, 2025
CVE-2025-49255
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 17, 2025
CVE-2025-49257
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 17, 2025
CVE-2025-49259
8.1

This CVE describes a Local File Inclusion vulnerability in the Hara WordPress theme that allows attackers to include arbitrary local files via PHP's i...

Jun 17, 2025
CVE-2025-49251
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 17, 2025
CVE-2025-49253
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Lasa WordPress theme. Attackers can exploit improper filename control in include/re...

Jun 17, 2025
CVE-2025-28991
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Jun 17, 2025
CVE-2025-24761
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 17, 2025
CVE-2025-4200
8.1

This vulnerability allows unauthenticated attackers to include and execute arbitrary PHP files on WordPress servers running the Zagg WooCommerce theme...

Jun 14, 2025
CVE-2025-49454
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the TinySalt WordPress theme. Attackers can include arbitrary local files on the server...

Jun 10, 2025
CVE-2025-48126
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 9, 2025
CVE-2025-28944
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Jun 9, 2025
CVE-2025-28992
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 9, 2025
CVE-2025-24770
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 9, 2025
CVE-2025-27362
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 9, 2025
CVE-2023-25999
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jun 9, 2025
CVE-2025-47453
8.1

This vulnerability allows attackers to include and execute arbitrary local PHP files on WordPress sites using the WP Smart Import plugin. Attackers ca...

May 23, 2025
CVE-2025-46444
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

May 23, 2025
CVE-2025-39494
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

May 23, 2025
CVE-2025-32309
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

May 23, 2025
CVE-2025-32289
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

May 23, 2025
CVE-2025-32294
8.1

This vulnerability allows attackers to include local files on the server through improper input validation in the Oxpitan WordPress theme. It affects ...

May 23, 2025
CVE-2025-31633
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

May 23, 2025
CVE-2025-31912
8.1

This vulnerability allows attackers to include arbitrary local files through PHP's include/require statements in the Enzio WordPress theme. Attackers ...

May 23, 2025
CVE-2025-31064
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

May 23, 2025
CVE-2025-2101
8.1

The Edumall WordPress theme contains a Local File Inclusion vulnerability that allows unauthenticated attackers to include and execute arbitrary PHP f...

Apr 26, 2025
CVE-2025-32663
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in the FAT Cooming Soon WordPress plugin. A...

Apr 11, 2025
CVE-2025-32672
8.1

This vulnerability allows attackers to include and execute arbitrary PHP files on servers running the affected WordPress plugin. It affects all WordPr...

Apr 11, 2025
CVE-2025-32654
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 11, 2025
CVE-2025-32627
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 11, 2025
CVE-2025-31040
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 11, 2025
CVE-2025-32668
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 10, 2025
CVE-2025-30849
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Essential Real Estate WordPre...

Apr 1, 2025
CVE-2025-30870
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Apr 1, 2025
CVE-2025-24690
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Mar 26, 2025
CVE-2025-23937
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Mar 26, 2025
CVE-2025-23952
8.1

This vulnerability allows attackers to include local files on the server through the WordPress custom-field-list-widget plugin. Attackers can potentia...

Mar 26, 2025
CVE-2025-26985
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements, potentially leading to sensitive in...

Feb 25, 2025
CVE-2025-23948
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 22, 2025
CVE-2025-23949
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 22, 2025
CVE-2025-22508
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 9, 2025
CVE-2024-53800
8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements, potentially leading to sensitive in...

Jan 7, 2025
CVE-2024-54270
8.1

This CVE describes a PHP Local File Inclusion vulnerability in the Axeptio WordPress plugin that allows attackers to include arbitrary local files via...

Dec 18, 2024
CVE-2024-11289
8.1

The Soledad WordPress theme contains a Local File Inclusion vulnerability that allows unauthenticated attackers to include and execute arbitrary PHP f...

Dec 6, 2024

About CWE-98 (CWE-98)

Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.

External reference: View CWE-98 on MITRE CWE →

Monitor CWE-98 Vulnerabilities

Get alerted when new CWE-98 CVEs affect your infrastructure.

Start Monitoring Free