WAFPlanet

CVE Database - Remote File Inclusion

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

1002
Matching CVEs
15562
Critical
25943
High
66770
High WAF Coverage

CVE-2026-33130

UNKNOWN
0.00 CVSS none

Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9pq-4crh doesn't fully work to preventServer-side Template Injection (SSTI). The three mitigations added to the Liquid engine (root, relativeReference, dynamicPartials) only block quoted paths. If a project uses an unquoted absolute path, attackers can still read any file on the server. The original fix in notification-provider.js only constrains the first two steps of LiquidJS's file resolution (via root, relativeReference, and dynamicPartials options), but the third step, the require.resolve() fallback in liquid.node.js has no containment check, allowing unquoted absolute paths like /etc/passwd to resolve successfully. Quoted paths happen to be blocked only because the literal quote characters cause require.resolve('"/etc/passwd"') to throw a MODULE_NOT_FOUND error, not because of any intentional security measure. This issue has been fixed in version 2.2.1.

PHP Remote File Inclusion
WAF: High

CVE-2026-22324

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Melania allows PHP Local File Inclusion.This issue affects Melania: from n/a through 2.5.0.

PHP Remote File Inclusion
WAF: High

CVE-2026-27065

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress BuilderPress allows PHP Local File Inclusion.This issue affects BuilderPress: from n/a through 2.0.1.

PHP Remote File Inclusion
WAF: High

CVE-2026-27093

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ovatheme Tripgo allows PHP Local File Inclusion.This issue affects Tripgo: from n/a before 1.5.6.

PHP Remote File Inclusion
WAF: High

CVE-2026-29858

UNKNOWN
0.00 CVSS none

A lack of path validation in aaPanel v7.57.0 allows attackers to execute a local file inclusion (LFI), leadingot sensitive information exposure.

PHP Remote File Inclusion
WAF: High

CVE-2026-1463

HIGH
8.80 CVSS 3.1

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3 via the 'template' parameter in gallery shortcodes. This makes it possible for authenticated attackers, with Author-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

PHP Remote File Inclusion
WAF: High

CVE-2026-27894

UNKNOWN
0.00 CVSS none

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, a local file inclusion was detected in the PDF export that allows users to include local PHP files and this way execute code. In combination with GHSA-88hf-2cjm-m9g8 this allows to execute arbitrary code. Users need to login to LAM to exploit this vulnerability. Version 9.5 fixes the issue. Although upgrading is recommended, a workaround would be to make /var/lib/ldap-account-manager/config read-only for the web-server user and delete the PDF profile files (making PDF exports impossible).

PHP Remote File Inclusion
WAF: High

CVE-2026-32426

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Medilazar Core medilazar-core allows PHP Local File Inclusion.This issue affects Medilazar Core: from n/a through < 1.4.7.

PHP Remote File Inclusion
WAF: High

CVE-2026-32401

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows PHP Local File Inclusion.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.9.

PHP Remote File Inclusion
WAF: High

CVE-2026-32400

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemetechMount Boldman boldman allows PHP Local File Inclusion.This issue affects Boldman: from n/a through <= 7.7.

PHP Remote File Inclusion
WAF: High

CVE-2026-32393

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Greenly Theme Addons greenly-addons allows PHP Local File Inclusion.This issue affects Greenly Theme Addons: from n/a through < 8.2.

PHP Remote File Inclusion
WAF: High

CVE-2026-32392

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Greenly greenly allows PHP Local File Inclusion.This issue affects Greenly: from n/a through <= 8.1.

PHP Remote File Inclusion
WAF: High

CVE-2026-32384

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpBookingly service-booking-manager allows PHP Local File Inclusion.This issue affects WpBookingly: from n/a through <= 1.2.9.

PHP Remote File Inclusion
WAF: High

CVE-2026-32369

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Medilink-Core medilink-core allows PHP Local File Inclusion.This issue affects Medilink-Core: from n/a through < 2.0.7.

PHP Remote File Inclusion
WAF: High

CVE-2026-32364

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in redqteam Turbo Manager turbo-manager allows PHP Local File Inclusion.This issue affects Turbo Manager: from n/a through < 4.0.8.

PHP Remote File Inclusion
WAF: High

CVE-2026-3826

CRITICAL
9.80 CVSS 3.1

IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

PHP Remote File Inclusion
WAF: High

CVE-2026-28129

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Little Birdies little-birdies allows PHP Local File Inclusion.This issue affects Little Birdies: from n/a through <= 1.3.16.

PHP Remote File Inclusion
WAF: High

CVE-2026-28128

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Verse verse allows PHP Local File Inclusion.This issue affects Verse: from n/a through <= 1.7.0.

PHP Remote File Inclusion
WAF: High

CVE-2026-28125

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Midi midi allows PHP Local File Inclusion.This issue affects Midi: from n/a through <= 1.14.

PHP Remote File Inclusion
WAF: High

CVE-2026-28124

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Notarius notarius allows PHP Local File Inclusion.This issue affects Notarius: from n/a through <= 1.9.

PHP Remote File Inclusion
WAF: High

CVE-2026-28123

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Veil veil allows PHP Local File Inclusion.This issue affects Veil: from n/a through <= 1.9.

PHP Remote File Inclusion
WAF: High

CVE-2026-28121

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Anderson andersonclinic allows PHP Local File Inclusion.This issue affects Anderson: from n/a through <= 1.4.2.

PHP Remote File Inclusion
WAF: High

CVE-2026-28120

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Dr.Patterson dr-patterson allows PHP Local File Inclusion.This issue affects Dr.Patterson: from n/a through <= 1.3.2.

PHP Remote File Inclusion
WAF: High

CVE-2026-28119

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Nirvana nirvana allows PHP Local File Inclusion.This issue affects Nirvana: from n/a through <= 2.6.

PHP Remote File Inclusion
WAF: High

CVE-2026-28118

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Welldone welldone allows PHP Local File Inclusion.This issue affects Welldone: from n/a through <= 2.4.

PHP Remote File Inclusion
WAF: High

CVE-2026-28117

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes smart SEO smartSEO allows PHP Local File Inclusion.This issue affects smart SEO: from n/a through <= 2.9.

PHP Remote File Inclusion
WAF: High

CVE-2026-28107

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Muzicon muzicon allows PHP Local File Inclusion.This issue affects Muzicon: from n/a through <= 1.9.0.

PHP Remote File Inclusion
WAF: High

CVE-2026-28098

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Save Life save-life allows PHP Local File Inclusion.This issue affects Save Life: from n/a through <= 1.2.13.

PHP Remote File Inclusion
WAF: High

CVE-2026-28097

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Artrium artrium allows PHP Local File Inclusion.This issue affects Artrium: from n/a through <= 1.0.14.

PHP Remote File Inclusion
WAF: High

CVE-2026-28096

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX WealthCo wealthco allows PHP Local File Inclusion.This issue affects WealthCo: from n/a through <= 2.18.

PHP Remote File Inclusion
WAF: High

CVE-2026-28095

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Marcell marcell allows PHP Local File Inclusion.This issue affects Marcell: from n/a through <= 1.2.14.

PHP Remote File Inclusion
WAF: High

CVE-2026-28094

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX RexCoin rexcoin allows PHP Local File Inclusion.This issue affects RexCoin: from n/a through <= 1.2.6.

PHP Remote File Inclusion
WAF: High

CVE-2026-28093

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Ozisti ozisti allows PHP Local File Inclusion.This issue affects Ozisti: from n/a through <= 1.1.10.

PHP Remote File Inclusion
WAF: High

CVE-2026-28092

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Sounder sounder allows PHP Local File Inclusion.This issue affects Sounder: from n/a through <= 1.3.11.

PHP Remote File Inclusion
WAF: High

CVE-2026-28091

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Coleo coleo allows PHP Local File Inclusion.This issue affects Coleo: from n/a through <= 1.1.7.

PHP Remote File Inclusion
WAF: High

CVE-2026-28090

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Gamezone gamezone allows PHP Local File Inclusion.This issue affects Gamezone: from n/a through <= 1.1.11.

PHP Remote File Inclusion
WAF: High

CVE-2026-28089

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Daiquiri daiquiri allows PHP Local File Inclusion.This issue affects Daiquiri: from n/a through <= 1.2.4.

PHP Remote File Inclusion
WAF: High

CVE-2026-28088

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Aqualots aqualots allows PHP Local File Inclusion.This issue affects Aqualots: from n/a through <= 1.1.6.

PHP Remote File Inclusion
WAF: High

CVE-2026-28087

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Filmax filmax allows PHP Local File Inclusion.This issue affects Filmax: from n/a through <= 1.1.11.

PHP Remote File Inclusion
WAF: High

CVE-2026-28086

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Run Gran run-gran allows PHP Local File Inclusion.This issue affects Run Gran: from n/a through <= 2.0.

PHP Remote File Inclusion
WAF: High

CVE-2026-28085

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Mahogany mahogany allows PHP Local File Inclusion.This issue affects Mahogany: from n/a through <= 2.9.

PHP Remote File Inclusion
WAF: High

CVE-2026-28084

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Bazinga bazinga allows PHP Local File Inclusion.This issue affects Bazinga: from n/a through <= 1.1.9.

PHP Remote File Inclusion
WAF: High

CVE-2026-28081

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Windsor windsor allows PHP Local File Inclusion.This issue affects Windsor: from n/a through <= 2.5.0.

PHP Remote File Inclusion
WAF: High

CVE-2026-28079

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Conquerors conquerors allows PHP Local File Inclusion.This issue affects Conquerors: from n/a through <= 1.2.13.

PHP Remote File Inclusion
WAF: High

CVE-2026-28077

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Vapester vapester allows PHP Local File Inclusion.This issue affects Vapester: from n/a through <= 1.1.10.

PHP Remote File Inclusion
WAF: High

CVE-2026-28069

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Le Truffe letruffe allows PHP Local File Inclusion.This issue affects Le Truffe: from n/a through <= 1.1.7.

PHP Remote File Inclusion
WAF: High

CVE-2026-28068

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Rhythmo rhythmo allows PHP Local File Inclusion.This issue affects Rhythmo: from n/a through <= 1.3.4.

PHP Remote File Inclusion
WAF: High

CVE-2026-28067

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Bassein bassein allows PHP Local File Inclusion.This issue affects Bassein: from n/a through <= 1.0.15.

PHP Remote File Inclusion
WAF: High

CVE-2026-28066

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Legrand legrand allows PHP Local File Inclusion.This issue affects Legrand: from n/a through <= 2.17.

PHP Remote File Inclusion
WAF: High

CVE-2026-28065

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Eject eject allows PHP Local File Inclusion.This issue affects Eject: from n/a through <= 2.17.

PHP Remote File Inclusion
WAF: High
Page 1 of 21 (1002 CVEs)