Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-98 (PHP程序中Include/Require语句包含文件控制不恰当(PHP远程文件包含)) — Vulnerability Class 1082

1082 vulnerabilities classified as CWE-98 (PHP程序中Include/Require语句包含文件控制不恰当(PHP远程文件包含)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-52745 WordPress Farm Agrico theme <= 1.3.11 - Local File Inclusion vulnerability — Farm Agrico 8.8AIHighAI2025-12-18
CVE-2025-52768 WordPress Faith & Hope theme <= 2.13.0 - Local File Inclusion vulnerability — Faith & Hope 9.8AICriticalAI2025-12-18
CVE-2025-49942 WordPress Gardis theme <= 1.2.13 - Local File Inclusion vulnerability — Gardis 8.1AIHighAI2025-12-18
CVE-2025-49941 WordPress GlamChic theme <= 1.0.11 - Local File Inclusion vulnerability — GlamChic 9.8AICriticalAI2025-12-18
CVE-2025-49370 WordPress Lymcoin theme <= 1.3.12 - Local File Inclusion vulnerability — Lymcoin 9.8AICriticalAI2025-12-18
CVE-2025-49367 WordPress Monyxi theme <= 1.1.8 - Local File Inclusion vulnerability — Monyxi 9.1AICriticalAI2025-12-18
CVE-2025-49368 WordPress Palladio theme <= 1.1.10 - Local File Inclusion vulnerability — Palladio 9.8AICriticalAI2025-12-18
CVE-2025-49371 WordPress Strux theme <= 1.9 - Local File Inclusion vulnerability — Strux 9.1AICriticalAI2025-12-18
CVE-2025-49369 WordPress Lettuce theme <= 1.1.7 - Local File Inclusion vulnerability — Lettuce 9.8AICriticalAI2025-12-18
CVE-2025-49366 WordPress Hanani theme <= 1.2.11 - Local File Inclusion vulnerability — Hanani 8.1 High2025-12-18
CVE-2025-49363 WordPress Kings & Queens theme <= 1.1.16 - Local File Inclusion vulnerability — Kings & Queens 8.1 High2025-12-18
CVE-2025-49364 WordPress Ludos Paradise theme <= 2.1.3 - Local File Inclusion vulnerability — Ludos Paradise 8.1 High2025-12-18
CVE-2025-49362 WordPress Gracioza theme <= 1.0.15 - Local File Inclusion vulnerability — Gracioza 8.1 High2025-12-18
CVE-2025-49365 WordPress Jack Well theme <= 1.0.14 - Local File Inclusion vulnerability — Jack Well 8.1 High2025-12-18
CVE-2025-49359 WordPress ShieldGroup theme <= 2.13 - Local File Inclusion vulnerability — ShieldGroup 8.1 High2025-12-18
CVE-2025-49360 WordPress Militarology theme <= 1.0.15 - Local File Inclusion vulnerability — Militarology 8.1 High2025-12-18
CVE-2025-49361 WordPress Mamita theme <= 1.0.9 - Local File Inclusion vulnerability — Mamita 8.1 High2025-12-18
CVE-2025-68068 WordPress Stockholm theme <= 9.14.1 - Local File Inclusion vulnerability — Stockholm 8.1AIHighAI2025-12-16
CVE-2025-68067 WordPress Stockholm Core plugin <= 2.4.6 - Local File Inclusion vulnerability — Stockholm Core 7.5 High2025-12-16
CVE-2025-68066 WordPress Soledad theme <= 8.7.0 - Local File Inclusion vulnerability — Soledad 9.1AICriticalAI2025-12-16
CVE-2025-68061 WordPress EduMall theme <= 4.4.7 - Local File Inclusion vulnerability — EduMall 7.5 High2025-12-16
CVE-2025-68065 WordPress Hub Core plugin <= 5.0.8 - Local File Inclusion vulnerability — Hub Core 7.5 High2025-12-16
CVE-2025-68062 WordPress MinimogWP theme <= 3.9.6 - Local File Inclusion vulnerability — MinimogWP 8.1AIHighAI2025-12-16
CVE-2025-14475 Extensive VC Addons for WPBakery page builder <= 1.9.1 - Unauthenticated Local File Inclusion via 'shortcode_name' Parameter — Extensive VC Addons for WPBakery page builder 8.1 High2025-12-13
CVE-2025-13886 LT Unleashed <= 1.1.1 - Authenticated (Contributor+) Local File Inclusion via 'template' Parameter — LT Unleashed 7.5 High2025-12-12
CVE-2024-58302 FoF Pretty Mail 1.1.2 Local File Inclusion via Email Template Settings — FriendsofFlarum Pretty Mail 4.9AIMediumAI2025-12-11
CVE-2025-63076 WordPress The7 Elements plugin <= 2.7.11 - Local File Inclusion vulnerability — The7 Elements 8.1AIHighAI2025-12-09
CVE-2025-63074 WordPress The7 theme < 12.8.1.1 - Local File Inclusion vulnerability — The7 8.1AIHighAI2025-12-09
CVE-2025-63062 WordPress UDesign Core plugin <= 4.14.0 - Local File Inclusion vulnerability — UDesign Core 7.5 High2025-12-09
CVE-2025-63036 WordPress Ronneby Theme Core plugin <= 1.5.68 - Local File Inclusion vulnerability — Ronneby Theme Core 7.5 High2025-12-09

Vulnerabilities classified as CWE-98 (PHP程序中Include/Require语句包含文件控制不恰当(PHP远程文件包含)) represent 1082 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.