Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-98

62
CRITICAL
1,162
HIGH
58
MEDIUM
1,294 CVEs · Page 11/26
7.5
CVE-2025-5804

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2018-25329

WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers

7.5
CVE-2026-39661

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-48133

When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to r

7.5
CVE-2026-9200

The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2

7.5
CVE-2026-48972

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2025-58024

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2025-49403

Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions.

7.5
CVE-2026-40721

Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions.

7.5
CVE-2025-68063

Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versio

7.5
CVE-2025-68064

Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

7.5
CVE-2026-57647

Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions.

7.5
CVE-2026-12923

The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3

7.5
CVE-2025-69133

Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.

7.5
CVE-2026-57748

Contributor Local File Inclusion in Shopify <= 1.0.0 versions.

7.5
CVE-2026-57749

Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.

7.5
CVE-2026-15338

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to

7.5
CVE-2026-57788

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57789

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57790

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57791

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57792

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57793

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57794

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57795

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57796

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57798

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57799

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57800

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57801

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57802

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57803

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57804

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-57805

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2026-65477

Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.

7.5
CVE-2026-65481

Contributor Local File Inclusion in Vino <= 1.9 versions.

7.5
CVE-2026-75963

The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.

7.4
CVE-2026-39850

Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method V

7.2
CVE-2026-32401

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.2
CVE-2026-39387

BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. V

7.2
CVE-2026-8134

Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTempl

7.2
CVE-2026-49954

Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated a

6.6
CVE-2026-13080

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Lo

6.6
CVE-2025-11977

The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin fo

6.6
CVE-2026-17605

The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Incl

6.6
CVE-2026-66586

Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

6.6
CVE-2026-14280

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion i

6.5
CVE-2026-33130

Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9p

6.5
CVE-2026-34036

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versio

6.5
CVE-2026-34787

Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability

Frequently Asked Questions

What is CWE-98?

CWE-98 (CWE-98) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-98?

There are 1,294 CVE records associated with CWE-98 in our database. Of these, 62 are critical severity, 1162 are high severity, and 58 are medium severity.

How can I protect against CWE-98 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-98 using AI-powered security agents.

Detect CWE-98 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-98 vulnerabilities across your infrastructure.

Get Started