boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-98

Weakness type CWE-98 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
1591580

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▂█▃▂

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 10 · 2026-06 102 · 2026-07 36 · 2026-08 10

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-481337.591.2Identity Awareness Captive Portal - Unauthenticated Local File Inclusion
CVE-2026-75159.858.2BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
CVE-2016-200796.953.0WordPress Dharma Booking 2.28.3 Local File Inclusion via proccess.php
CVE-2026-75228.852.3Advanced Database Cleaner – Premium <= 4.1.0 - Authenticated (Subscriber+) Local File I…
CVE-2026-81349.451.8Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemp…
CVE-2026-176056.650.7Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.56 - Authenticate…
CVE-2026-130806.650.0WPFunnels <= 3.12.7 - Authenticated (Administrator+) Local File Inclusion via 'logKey' …
CVE-2016-200786.949.9WordPress IMDb Profile Widget 1.0.8 Local File Inclusion via pic.php
CVE-2025-310987.549.4WordPress DeBounce Email Validator plugin <= 5.7 - Local File Inclusion Vulnerability
CVE-2016-200646.949.2WP Vault 0.8.6.6 Local File Inclusion via wpv-image Parameter
CVE-2026-95599.945.3
CVE-2026-96628.143.7Recover Exit For WooCommerce <= 1.0.3 - Unauthenticated Local File Inclusion via 'tpf' …
CVE-2026-153387.543.6LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File …
CVE-2019-257606.943.2Joomla! Component Easy Shop 1.2.3 Local File Inclusion
CVE-2026-499548.642.3Discuz! X5.0 Local File Inclusion via enable_disable.php Plugin Directory
CVE-2025-119776.640.8HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion
CVE-2026-92007.540.5Query Shortcode <= 0.2.1 - Authenticated (Contributor+) Local File Inclusion via 'lens'…
CVE-2025-691778.139.2WordPress Roneous theme <= 2.1.5 - Local File Inclusion vulnerability
CVE-2026-398507.437.9Yii 2: Local file inclusion via view parameter name collision
CVE-2026-441778.837.9Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
themerex53
elated-themes8
axiomthemes7
select-themes7
mikado-themes5
edge-themes3
stylemixthemes3
thememove3
webgeniuslab3
themelogi2
themerex group2
uxper2
aa-team1
abtest1
ancorathemes1