Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in a
The WordPress Post Grid Layouts with Pagination – Sogrid plugin for WordPress is vulnerable to Local File Inclusion in a
The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up t
Remote file inclusion vulnerability in FireEye Central Management affecting version 9.1.1.956704. This vulnerability all
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusi
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'w
The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via
AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.
PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deseria
PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.
The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3 via a s
The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in
The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post
Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB).
FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log
FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.
An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to retrieve PHP files from the
A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code vi
PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.
PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.
Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications allow Local File Inclusion in any pag
A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12
A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Co
A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attack
The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this
A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before
An unintended require vulnerability in <v0.5.5 larvitbase-api may allow an attacker to load arbitrary non-production cod
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401,
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to pe
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cs
Frequently Asked Questions
What is CWE-98?
CWE-98 (CWE-98) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-98?
There are 1,294 CVE records associated with CWE-98 in our database. Of these, 62 are critical severity, 1162 are high severity, and 58 are medium severity.
How can I protect against CWE-98 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-98 using AI-powered security agents.
Detect CWE-98 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-98 vulnerabilities across your infrastructure.
Get Started