WAFPlanet

CVE Database - Remote File Inclusion

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

1002
Matching CVEs
15562
Critical
25943
High
66770
High WAF Coverage

CVE-2026-22344

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes FiveStar fivestar allows PHP Local File Inclusion.This issue affects FiveStar: from n/a through <= 1.7.

PHP Remote File Inclusion
WAF: High

CVE-2025-69410

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Belletrist belletrist allows PHP Local File Inclusion.This issue affects Belletrist: from n/a through <= 1.2.

PHP Remote File Inclusion
WAF: High

CVE-2025-69409

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes PJ | Life & Business Coaching pj allows PHP Local File Inclusion.This issue affects PJ | Life & Business Coaching: from n/a through <= 3.0.0.

PHP Remote File Inclusion
WAF: High

CVE-2025-69408

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes HealthFirst healthfirst allows PHP Local File Inclusion.This issue affects HealthFirst: from n/a through <= 1.0.1.

PHP Remote File Inclusion
WAF: High

CVE-2025-69407

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur struktur allows PHP Local File Inclusion.This issue affects Struktur: from n/a through <= 2.5.1.

PHP Remote File Inclusion
WAF: High

CVE-2025-69406

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX FreightCo freightco allows PHP Local File Inclusion.This issue affects FreightCo: from n/a through <= 1.1.7.

PHP Remote File Inclusion
WAF: High

CVE-2025-69402

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX R&F rf allows PHP Local File Inclusion.This issue affects R&F: from n/a through <= 1.5.

PHP Remote File Inclusion
WAF: High

CVE-2025-69400

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Yokoo yokoo allows PHP Local File Inclusion.This issue affects Yokoo: from n/a through <= 1.1.11.

PHP Remote File Inclusion
WAF: High

CVE-2025-69399

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Cobble cobble allows PHP Local File Inclusion.This issue affects Cobble: from n/a through <= 1.7.

PHP Remote File Inclusion
WAF: High

CVE-2025-69398

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Plank plank allows PHP Local File Inclusion.This issue affects Plank: from n/a through <= 1.7.

PHP Remote File Inclusion
WAF: High

CVE-2025-69397

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Tint tint allows PHP Local File Inclusion.This issue affects Tint: from n/a through <= 1.7.

PHP Remote File Inclusion
WAF: High

CVE-2025-69396

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Splendour splendour allows PHP Local File Inclusion.This issue affects Splendour: from n/a through <= 1.23.

PHP Remote File Inclusion
WAF: High

CVE-2025-69395

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Gable gable allows PHP Local File Inclusion.This issue affects Gable: from n/a through <= 1.5.

PHP Remote File Inclusion
WAF: High

CVE-2025-69387

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in whatwouldjessedo Simple Retail Menus simple-retail-menus allows PHP Local File Inclusion.This issue affects Simple Retail Menus: from n/a through <= 4.2.1.

PHP Remote File Inclusion
WAF: High

CVE-2025-69383

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows PHP Local File Inclusion.This issue affects WP shop: from n/a through <= 2.6.1.

PHP Remote File Inclusion
WAF: High

CVE-2025-69375

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SolverWp Portfolio Builder swp-portfolio allows PHP Local File Inclusion.This issue affects Portfolio Builder: from n/a through <= 1.2.5.

PHP Remote File Inclusion
WAF: High

CVE-2025-69374

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SolverWp Eleblog – Elementor Blog And Magazine Addons ele-blog allows PHP Local File Inclusion.This issue affects Eleblog – Elementor Blog And Magazine Addons: from n/a through <= 2.0.3.

PHP Remote File Inclusion
WAF: High

CVE-2025-69373

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 VidoRev vidorev allows PHP Local File Inclusion.This issue affects VidoRev: from n/a through <= 2.9.9.9.9.9.7.

PHP Remote File Inclusion
WAF: High

CVE-2025-69322

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes PeakShops peakshops allows PHP Local File Inclusion.This issue affects PeakShops: from n/a through < 1.5.9.

PHP Remote File Inclusion
WAF: High

CVE-2025-68841

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themepul TopperPack – Complete Elementor Addons, Theme &amp; CPT Builder topper-pack allows PHP Local File Inclusion.This issue affects TopperPack – Complete Elementor Addons, Theme &amp; CPT Builder: from n/a through <= 1.2.1.

PHP Remote File Inclusion
WAF: High

CVE-2025-68552

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace WooCommerce Coming Soon Product with Countdown woo-coming-soon-product allows PHP Local File Inclusion.This issue affects WooCommerce Coming Soon Product with Countdown: from n/a through <= 5.0.

PHP Remote File Inclusion
WAF: High

CVE-2025-68545

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Nika nika allows PHP Local File Inclusion.This issue affects Nika: from n/a through <= 1.2.14.

PHP Remote File Inclusion
WAF: High

CVE-2025-68543

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Diza diza allows PHP Local File Inclusion.This issue affects Diza: from n/a through <= 1.3.15.

PHP Remote File Inclusion
WAF: High

CVE-2025-68539

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local File Inclusion.This issue affects Fana: from n/a through <= 1.1.35.

PHP Remote File Inclusion
WAF: High

CVE-2025-68536

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Zota zota allows PHP Local File Inclusion.This issue affects Zota: from n/a through <= 1.3.14.

PHP Remote File Inclusion
WAF: High

CVE-2025-67992

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean PatioTime patiotime allows PHP Local File Inclusion.This issue affects PatioTime: from n/a through < 2.1.

PHP Remote File Inclusion
WAF: High

CVE-2025-67988

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean CozyStay cozystay allows PHP Local File Inclusion.This issue affects CozyStay: from n/a through < 1.9.1.

PHP Remote File Inclusion
WAF: High

CVE-2025-67982

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna urna allows PHP Local File Inclusion.This issue affects Urna: from n/a through <= 2.5.12.

PHP Remote File Inclusion
WAF: High

CVE-2025-67981

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP Local File Inclusion.This issue affects Besa: from n/a through <= 2.3.15.

PHP Remote File Inclusion
WAF: High

CVE-2025-67980

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Hara hara allows PHP Local File Inclusion.This issue affects Hara: from n/a through <= 1.2.17.

PHP Remote File Inclusion
WAF: High

CVE-2025-60087

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nenad Obradovic Extensive VC Addons for WPBakery page builder extensive-vc-addon allows PHP Local File Inclusion.This issue affects Extensive VC Addons for WPBakery page builder: from n/a through <= 1.9.1.

PHP Remote File Inclusion
WAF: High

CVE-2026-27343

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VanKarWai Airtifact airtifact allows PHP Local File Inclusion.This issue affects Airtifact: from n/a through <= 1.2.91.

PHP Remote File Inclusion
WAF: High

CVE-2026-27052

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in villatheme Sales Countdown Timer for WooCommerce and WordPress sctv-sales-countdown-timer allows PHP Local File Inclusion.This issue affects Sales Countdown Timer for WooCommerce and WordPress: from n/a through <= 1.1.8.1.

PHP Remote File Inclusion
WAF: High

CVE-2026-25326

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through <= 1.4.5.

PHP Remote File Inclusion
WAF: High

CVE-2026-0926

CRITICAL
9.80 CVSS 3.1

The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.9 via the 'parameters[template_name]' parameter. This makes it possible for unauthenticated attackers to include and read arbitrary files or execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

PHP Remote File Inclusion
WAF: High

CVE-2026-25548

UNKNOWN
0.00 CVSS none

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7.0 through a chained Local File Inclusion (LFI) and Log Poisoning attack. An authenticated administrator can execute arbitrary system commands on the server by manipulating the `public_invoice_template` setting to include poisoned log files containing PHP code. Version 1.7.1 patches the issue.

Code Injection PHP Remote File Inclusion
WAF: High

CVE-2026-1988

HIGH
7.50 CVSS 3.1

The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.5 via the `flexipsg_carousel` shortcode. This is due to the `theme` parameter being directly concatenated into a file path without proper sanitization or validation, allowing directory traversal. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary PHP files on the server via the `theme` parameter granted they can create posts with shortcodes.

PHP Remote File Inclusion
WAF: High

CVE-2025-15368

HIGH
8.80 CVSS 3.1

The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

PHP Remote File Inclusion
WAF: High

CVE-2026-25027

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp allows PHP Local File Inclusion.This issue affects Unicamp: from n/a through <= 2.7.1.

PHP Remote File Inclusion
WAF: High

CVE-2024-54263

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Talemy Spirit Framework allows PHP Local File Inclusion.This issue affects Spirit Framework: from n/a through 1.2.13.

PHP Remote File Inclusion
WAF: High

CVE-2021-47900

CRITICAL
9.80 CVSS 3.1

Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP headers. Attackers can inject PHP code in the User-Agent header with shell_exec() to run system commands by sending crafted requests to the admin endpoint.

PHP Remote File Inclusion
WAF: High

CVE-2026-1257

HIGH
7.50 CVSS 3.1

The Administrative Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.3.4 via the 'slug' attribute of the 'get_template' shortcode. This is due to insufficient path validation on user-supplied input passed to the get_template_part() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.

PHP Remote File Inclusion
WAF: High

CVE-2026-24635

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DevsBlink EduBlink Core edublink-core allows PHP Local File Inclusion.This issue affects EduBlink Core: from n/a through <= 2.0.7.

PHP Remote File Inclusion
WAF: High

CVE-2026-24609

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent laurent allows PHP Local File Inclusion.This issue affects Laurent: from n/a through <= 3.1.

PHP Remote File Inclusion
WAF: High

CVE-2026-24608

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent Core laurent-core allows PHP Local File Inclusion.This issue affects Laurent Core: from n/a through <= 2.4.1.

PHP Remote File Inclusion
WAF: High

CVE-2026-24538

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in omnipressteam Omnipress omnipress allows PHP Local File Inclusion.This issue affects Omnipress: from n/a through <= 1.6.6.

PHP Remote File Inclusion
WAF: High

CVE-2026-24531

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Prowess prowess allows PHP Local File Inclusion.This issue affects Prowess: from n/a through <= 2.3.

PHP Remote File Inclusion
WAF: High

CVE-2026-24390

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QantumThemes Kentha Elementor Widgets kentha-elementor allows PHP Local File Inclusion.This issue affects Kentha Elementor Widgets: from n/a through < 3.1.

PHP Remote File Inclusion
WAF: High

CVE-2026-23978

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Softwebmedia Gyan Elements gyan-elements allows PHP Local File Inclusion.This issue affects Gyan Elements: from n/a through <= 2.2.1.

PHP Remote File Inclusion
WAF: High

CVE-2026-23975

UNKNOWN
0.00 CVSS none

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo golo allows PHP Local File Inclusion.This issue affects Golo: from n/a through < 1.7.5.

PHP Remote File Inclusion
WAF: High
Page 5 of 21 (1002 CVEs)