CVE & CISA-KEV Catalog

384,676 CVEs1,686 actively exploited (KEV)
Active:
  • CVSS 8.1 v3·EPSS 0.5%·No fix yet

    The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published 2026-08-25

  • CVSS 8.1 v3·EPSS 0.5%·No fix yet

    The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published 2026-08-25

  • CVSS 8.1 v3·EPSS 0.5%·No fix yet

    The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

    Published 2026-08-25

  • CVSS 6.6 v3·EPSS 0.7%·No fix yet

    The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.3.7.4 via the em_options_save function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal key is subsequently executed via an include_once() call that fires on every admin_init invocation — including unauthenticated admin-ajax.php requests — meaning once the malicious key is stored by an administrator, the

    Published 2026-08-25

  • CVSS 8.8 v3·EPSS 0.3%·No fix yet

    Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.

    Published 2026-08-24

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.

    Published 2026-08-24

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in Måne <= 1.7 versions.

    Published 2026-08-24

  • CVSS 9.8 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

    Published 2026-08-24

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.

    Published 2026-08-24

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in Tonda < 2.6 versions.

    Published 2026-08-24

  • CVSS 6.6 v3·EPSS 0.3%·No fix yet

    Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

    Published 2026-08-20

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.

    Published 2026-08-20

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.

    Published 2026-08-20

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The stored traversal payload is triggered passively when any visitor loads the affected single-event page, meaning post-submission execution does not require additional attacker interaction.

    Published 2026-08-20

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in Resido <= 1.5 versions.

    Published 2026-08-19

  • CVSS 8.1 v3·EPSS 0.4%·No fix yet

    Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.

    Published 2026-08-18

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.

    Published 2026-08-18

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.

    Published 2026-08-18

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.

    Published 2026-08-13

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.

    Published 2026-08-13

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.

    Published 2026-08-13

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions.

    Published 2026-08-13

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.

    Published 2026-08-06

  • CVSS 6.6 v3·EPSS 0.7%·No fix yet

    The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

    Published 2026-08-01

  • CVSS 5.1 v4·EPSS 0.3%·No fix yet

    Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application's directory structure via a crafted HTTP request. Successful exploitation allows disclosure of the server's directory structure and absolute file paths (path disclosure). The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.

    Published 2026-07-28

  • CVSS 7.5 v3·EPSS 0.4%·No fix yet

    Contributor Local File Inclusion in Vino <= 1.9 versions.

    Published 2026-07-23

  • CVSS 7.5 v3·EPSS 0.4%·No fix yet

    Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.

    Published 2026-07-23

  • CVSS 8.8 v4·EPSS 0.7%·No fix yet

    Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user ID, resulting in a path traversal vulnerability. Version 5.3.0 introduced a performance improvement to the Users collection that loaded user objects lazily when first needed. Users were queried by their ID, which was then used to locate the corresponding account directory under site/accounts. This affected the authentication API (accessible to unauthenticated requests), the users API (accessible only to authenticated users), and any other place that uses $users->find() to look up an individual user by a request-provided email or ID. As a result, an attacker could trigger arbitrary PHP file inclusion of files named index.php (for example, the

    Published 2026-07-16

  • CVSS 7.7 v4·EPSS 0.4%·No fix yet

    Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without validation, and log_controller.php later checks file_exists and calls include View::getView($template), allowing an authenticated author to include an arbitrary local .php file when an article is viewed. No fixed version is currently identified.

    Published 2026-07-16

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Tonda tonda allows PHP Local File Inclusion.This issue affects Tonda: from n/a through <= 2.5.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows PHP Local File Inclusion. This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur Core allows PHP Local File Inclusion. This issue affects Struktur Core: from n/a before 2.7.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur allows PHP Local File Inclusion. This issue affects Struktur: from n/a before 2.7.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes SetSail setsail allows PHP Local File Inclusion.This issue affects SetSail: from n/a through <= 2.1.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Overworld overworld allows PHP Local File Inclusion.This issue affects Overworld: from n/a through <= 1.5.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Nuss nuss allows PHP Local File Inclusion.This issue affects Nuss: from n/a through <= 1.3.6.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortcodes newsplus-shortcodes allows PHP Local File Inclusion.This issue affects NewsPlus Shortcodes: from n/a through <= 4.2.0.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VLThemes Leedo leedo allows PHP Local File Inclusion.This issue affects Leedo: from n/a through <= 3.0.0.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Kitchor kitchor allows PHP Local File Inclusion.This issue affects Kitchor: from n/a through <= 1.4.3.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-framework allows PHP Local File Inclusion.This issue affects Golo Framework: from n/a through <= 1.7.3.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Flow flow allows PHP Local File Inclusion.This issue affects Flow: from n/a through <= 1.8.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through <= 2.4.1.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This issue affects Brook: from n/a through <= 2.9.0.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.This issue affects Billey: from n/a through <= 2.1.8.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PHP Local File Inclusion.This issue affects Aqua: from n/a through <= 5.1.2.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 0.5%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Aalto aalto allows PHP Local File Inclusion.This issue affects Aalto: from n/a through <= 1.8.

    Published 2026-07-13

  • CVSS 8.1 v3·EPSS 0.6%·No fix yet

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP Local File Inclusion.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

    Published 2026-07-13

  • CVSS 4.3 v3·EPSS 0.4%·No fix yet

    A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php program. It is possible to initiate the attack remotely. The exploit is now public and may be used.

    Published 2026-07-13

  • CVSS 7.5 v3·EPSS 1.0%·No fix yet

    The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The wp_normalize_path function used in get_template only normalizes directory separators and does not resolve or reject path traversal sequences, while the extension check is trivially bypassed because the caller already appends the required extension to the t

    Published 2026-07-11

  • CVSS 6.6 v3·EPSS 0.9%·No fix yet

    The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.26.12 via the happyforms_get_form_partial() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

    Published 2026-07-10

Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.