CWE-98

CWE-98 · 10 records · 4 with a public proof-of-concept

Records the NVD classes under CWE-98, highest CVSS first.

  1. CRITICAL 9.8CVE-2026-12227

    The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary…

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.1CVE-2026-39353public PoC

    InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an administrator-controlle…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.8CVE-2026-27556

    A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie allowing execution of arbitrary PHP code on the device.

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 8.8CVE-2026-27555

    A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie allowing execution of arbitrary PHP code on the device.

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 8.1CVE-2026-87902public PoC

    An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to …

    wordpress

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 8.1CVE-2026-92969

    The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.4 via the 'shortcode' parameter parameter. This makes it possible for unauthenticated attackers to inc…

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7.5CVE-2026-50547public PoC

    InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Invoices::generate_xml() method appends a database-derived xml_id to the XMLconfigs helper directory and includes the resulting P…

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 7.5CVE-2026-49850public PoC

    InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without requiring POST and validating a CSRF…

    AI risk analysis on Exploit-DB.ai →

  9. HIGH 7.5CVE-2026-13456

    The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8 via the 'page' parameter parameter. This makes it possible for authe…

    AI risk analysis on Exploit-DB.ai →

  10. HIGH 7.5CVE-2026-9231

    The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template function. This makes it possible for authenticated attackers, wi…

    AI risk analysis on Exploit-DB.ai →