Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-98

62
CRITICAL
1,162
HIGH
58
MEDIUM
1,294 CVEs · Page 9/26
8.1
CVE-2026-39522

Unauthenticated Local File Inclusion in Solene <= 3.4 versions.

8.1
CVE-2026-39537

Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions.

8.1
CVE-2026-39547

Unauthenticated Local File Inclusion in Getaway < 1.8 versions.

8.1
CVE-2026-39549

Unauthenticated Local File Inclusion in Aperitif <= 1.5 versions.

8.1
CVE-2026-39558

Unauthenticated Local File Inclusion in Malmö <= 2.2 versions.

8.1
CVE-2026-39568

Unauthenticated Local File Inclusion in Mr. SEO <= 2.0 versions.

8.1
CVE-2026-39582

Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions.

8.1
CVE-2026-40731

Unauthenticated Local File Inclusion in ChapterOne <= 1.7 versions.

8.1
CVE-2025-69106

Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.

8.1
CVE-2025-69115

Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions.

8.1
CVE-2025-69120

Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions.

8.1
CVE-2025-69123

Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions.

8.1
CVE-2025-69126

Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions.

8.1
CVE-2025-69144

Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.

8.1
CVE-2025-69157

Unauthenticated Local File Inclusion in Gamic <= 1.15 versions.

8.1
CVE-2025-69158

Unauthenticated Local File Inclusion in Granola <= 1.13 versions.

8.1
CVE-2025-69164

Unauthenticated Local File Inclusion in Skyward <= 1.10 versions.

8.1
CVE-2025-69166

Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.

8.1
CVE-2025-69170

Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.

8.1
CVE-2025-69174

Unauthenticated Local File Inclusion in Etude <= 1.6 versions.

8.1
CVE-2025-69175

Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.

8.1
CVE-2026-39523

Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.

8.1
CVE-2026-39559

Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.

8.1
CVE-2026-39590

Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.

8.1
CVE-2026-54814

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

8.1
CVE-2026-54845

Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.

8.1
CVE-2025-58902

Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.

8.1
CVE-2026-27412

Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.

8.1
CVE-2026-42382

Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.

8.1
CVE-2026-57743

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

8.1
CVE-2026-66710

Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.

8.1
CVE-2026-66450

Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions.

8.1
CVE-2026-66653

Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.

8.1
CVE-2026-66656

Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.

8.1
CVE-2026-66657

Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.

8.1
CVE-2026-28570

Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.

8.1
CVE-2026-32464

Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.

8.1
CVE-2026-73400

Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.

8.1
CVE-2026-73387

Unauthenticated Local File Inclusion in Resido <= 1.5 versions.

8.1
CVE-2025-15637

Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.

8.1
CVE-2026-28150

Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.

8.1
CVE-2026-28151

Unauthenticated Local File Inclusion in Tonda < 2.6 versions.

8.1
CVE-2026-28152

Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.

8.1
CVE-2026-66670

Unauthenticated Local File Inclusion in Måne <= 1.7 versions.

8.1
CVE-2026-66671

Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.

8.1
CVE-2026-78478

The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes

8.1
CVE-2026-78562

The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. T

8.1
CVE-2026-78566

The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This ma

8.0
CVE-2026-37266

An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary

7.5
CVE-2025-69342

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

Frequently Asked Questions

What is CWE-98?

CWE-98 (CWE-98) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-98?

There are 1,294 CVE records associated with CWE-98 in our database. Of these, 62 are critical severity, 1162 are high severity, and 58 are medium severity.

How can I protect against CWE-98 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-98 using AI-powered security agents.

Detect CWE-98 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-98 vulnerabilities across your infrastructure.

Get Started