CWE-98: CWE-98

608
Total CVEs
81
Critical
513
High
8.1
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
120
2025
446
2024
38
2023
3
2021
1

Top Affected Vendors

1 Axiomthemes 58
2 Ancorathemes 12
3 Thememove 12
4 Qodeinteractive 9
5 Themehorse 3
6 Joomsky 2
7 G5plus 2
8 Wptravelengine 2
9 Themewinter 2
10 La Studioweb 2

All CWE-98 CVEs (608)

CVE-2024-53739
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Nov 30, 2024
CVE-2024-52381
8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Nov 14, 2024
CVE-2025-62053
8.0

This CVE describes a PHP remote file inclusion vulnerability in the Houzez WordPress theme. Attackers can include arbitrary remote files, potentially ...

Nov 6, 2025
CVE-2024-31459
8.0

CVE-2024-31459 is a critical vulnerability in Cacti monitoring software that allows remote code execution through a combination of SQL injection and f...

May 14, 2024
CVE-2023-49084
8.0

This CVE-2023-49084 vulnerability in Cacti allows authenticated users to perform SQL injection and arbitrary code execution on the server through the ...

Dec 21, 2023
CVE-2026-24538
7.6

This CVE describes a PHP Local File Inclusion vulnerability in the Omnipress WordPress plugin. Attackers can exploit improper filename control in incl...

Jan 23, 2026
CVE-2025-63062
7.6

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 9, 2025
CVE-2025-69387
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Simple Retail Menus WordPress plugin. Attackers can include arbitrary local files f...

Feb 20, 2026
CVE-2025-69383
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the WP Shop WordPress plugin. Attackers can include arbitrary local files through impro...

Feb 20, 2026
CVE-2025-69373
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 20, 2026
CVE-2026-27343
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the VanKarWai Airtifact WordPress theme. Attackers can include arbitrary local files th...

Feb 19, 2026
CVE-2026-25326
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Feb 19, 2026
CVE-2026-1988
7.5

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to perform Local File Inclusion attacks via the Flexi ...

Feb 14, 2026
CVE-2026-25027
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Unicamp WordPress theme. Attackers can include arbitrary local files through improp...

Feb 3, 2026
CVE-2024-54263
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Talemy Spirit Framework WordPress plugin. Attackers can exploit improper filename c...

Feb 2, 2026
CVE-2026-24390
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 22, 2026
CVE-2026-22464
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the My auctions allegro WordPress plugin. Attackers can exploit improper filename contr...

Jan 22, 2026
CVE-2026-22401
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Freshio WordPress theme. Attackers can include arbitrary local files through improp...

Jan 22, 2026
CVE-2026-22402
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Triply WordPress theme by pavothemes. Attackers can include arbitrary local files t...

Jan 22, 2026
CVE-2025-68913
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Miion WordPress theme by zozothemes. Attackers can exploit improper filename contro...

Jan 22, 2026
CVE-2025-68905
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the JNews - Pay Writer WordPress plugin. Attackers can exploit improper filename contro...

Jan 22, 2026
CVE-2025-67955
7.5

This vulnerability allows attackers to include local PHP files through improper filename control in the MyHome Core WordPress plugin. Attackers can po...

Jan 22, 2026
CVE-2025-63017
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Jan 22, 2026
CVE-2026-22521
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the G5Theme Handmade Framework WordPress plugin. Attackers can include arbitrary local ...

Jan 8, 2026
CVE-2025-69356
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Jan 6, 2026
CVE-2025-69342
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the VanKarWai Calafate WordPress theme. Attackers can include arbitrary local files thr...

Jan 6, 2026
CVE-2025-62753
7.5

This vulnerability allows attackers to include local files on the server through improper input validation in the MAS Videos WordPress plugin. Attacke...

Dec 30, 2025
CVE-2025-68996
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 30, 2025
CVE-2025-68870
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 29, 2025
CVE-2025-68877
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the CedCommerce Integration for Good Market WordPress plugin. Attackers can include arb...

Dec 29, 2025
CVE-2025-68560
7.5

This vulnerability allows remote attackers to include arbitrary PHP files via a filename parameter in TheGem Theme Elements for Elementor WordPress pl...

Dec 23, 2025
CVE-2025-68544
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 23, 2025
CVE-2025-68546
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 23, 2025
CVE-2025-64193
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-60076
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Ray Enterprise Translation WordPress plugin. Attackers can exploit improper filenam...

Dec 18, 2025
CVE-2025-60078
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 18, 2025
CVE-2025-68067
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Dec 16, 2025
CVE-2025-68068
7.5

This vulnerability allows attackers to include local files on the server through the Stockholm WordPress theme's PHP code. Attackers can potentially r...

Dec 16, 2025
CVE-2025-68061
7.5

This vulnerability allows attackers to include local PHP files through improper filename control in the EduMall WordPress theme. Attackers can potenti...

Dec 16, 2025
CVE-2025-68062
7.5

This CVE describes a PHP Local File Inclusion vulnerability in the MinimogWP WordPress theme. Attackers can include arbitrary local files, potentially...

Dec 16, 2025
CVE-2025-68065
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 16, 2025
CVE-2025-68066
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 16, 2025
CVE-2025-13886
7.5

The LT Unleashed WordPress plugin has a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level access or higher...

Dec 12, 2025
CVE-2025-63074
7.5

This vulnerability allows attackers to include local PHP files through improper filename control in the The7 WordPress theme. Attackers can potentiall...

Dec 9, 2025
CVE-2025-63076
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 9, 2025
CVE-2025-63036
7.5

This vulnerability allows attackers to include local PHP files through improper filename control in the Ronneby Theme Core WordPress plugin. Attackers...

Dec 9, 2025
CVE-2025-63003
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Dec 9, 2025
CVE-2025-60248
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Nov 6, 2025
CVE-2025-60204
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

Nov 6, 2025
CVE-2025-60240
7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

Nov 6, 2025

About CWE-98 (CWE-98)

Our database tracks 608 CVEs classified as CWE-98, with 81 rated critical and 513 rated high severity. The average CVSS score for CWE-98 vulnerabilities is 8.1.

External reference: View CWE-98 on MITRE CWE →

Monitor CWE-98 Vulnerabilities

Get alerted when new CWE-98 CVEs affect your infrastructure.

Start Monitoring Free