Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-98 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 159 | 158 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▃▂
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 10 · 2026-06 102 · 2026-07 36 · 2026-08 10
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-48133 | 7.5 | 91.2 | — | Identity Awareness Captive Portal - Unauthenticated Local File Inclusion |
| CVE-2026-7515 | 9.8 | 58.2 | — | BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style |
| CVE-2016-20079 | 6.9 | 53.0 | — | WordPress Dharma Booking 2.28.3 Local File Inclusion via proccess.php |
| CVE-2026-7522 | 8.8 | 52.3 | — | Advanced Database Cleaner – Premium <= 4.1.0 - Authenticated (Subscriber+) Local File I… |
| CVE-2026-8134 | 9.4 | 51.8 | — | Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemp… |
| CVE-2026-17605 | 6.6 | 50.7 | — | Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.56 - Authenticate… |
| CVE-2026-13080 | 6.6 | 50.0 | — | WPFunnels <= 3.12.7 - Authenticated (Administrator+) Local File Inclusion via 'logKey' … |
| CVE-2016-20078 | 6.9 | 49.9 | — | WordPress IMDb Profile Widget 1.0.8 Local File Inclusion via pic.php |
| CVE-2025-31098 | 7.5 | 49.4 | — | WordPress DeBounce Email Validator plugin <= 5.7 - Local File Inclusion Vulnerability |
| CVE-2016-20064 | 6.9 | 49.2 | — | WP Vault 0.8.6.6 Local File Inclusion via wpv-image Parameter |
| CVE-2026-9559 | 9.9 | 45.3 | — | — |
| CVE-2026-9662 | 8.1 | 43.7 | — | Recover Exit For WooCommerce <= 1.0.3 - Unauthenticated Local File Inclusion via 'tpf' … |
| CVE-2026-15338 | 7.5 | 43.6 | — | LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File … |
| CVE-2019-25760 | 6.9 | 43.2 | — | Joomla! Component Easy Shop 1.2.3 Local File Inclusion |
| CVE-2026-49954 | 8.6 | 42.3 | — | Discuz! X5.0 Local File Inclusion via enable_disable.php Plugin Directory |
| CVE-2025-11977 | 6.6 | 40.8 | — | HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion |
| CVE-2026-9200 | 7.5 | 40.5 | — | Query Shortcode <= 0.2.1 - Authenticated (Contributor+) Local File Inclusion via 'lens'… |
| CVE-2025-69177 | 8.1 | 39.2 | — | WordPress Roneous theme <= 2.1.5 - Local File Inclusion vulnerability |
| CVE-2026-39850 | 7.4 | 37.9 | — | Yii 2: Local file inclusion via view parameter name collision |
| CVE-2026-44177 | 8.8 | 37.9 | — | Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup |
| Vendor | CVEs |
|---|---|
| themerex | 53 |
| elated-themes | 8 |
| axiomthemes | 7 |
| select-themes | 7 |
| mikado-themes | 5 |
| edge-themes | 3 |
| stylemixthemes | 3 |
| thememove | 3 |
| webgeniuslab | 3 |
| themelogi | 2 |
| themerex group | 2 |
| uxper | 2 |
| aa-team | 1 |
| abtest | 1 |
| ancorathemes | 1 |