Skip to content
Threat Feed

Tag

LFI

29 briefs RSS
high advisory

Local File Inclusion and RCE in /index.php/ajax/save_iodd_parameters

A local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint allows a remote attacker with a valid operator cookie to achieve remote code execution.

CVE-2026-27556 lfi rce web-security
1c
high advisory

Local File Inclusion Vulnerability in GEO my WP WordPress Plugin

The GEO my WP plugin for WordPress is vulnerable to unauthenticated local file inclusion (LFI) via the gmw_posts_locator_ajax_info_window_loader function, which can be escalated to remote code execution in specific PEAR-enabled environments.

GEO my WP wordpress lfi vulnerability rce
1r 1t 1c
high advisory

Local File Inclusion in MaxSite CMS via Ajax Dispatchers

MaxSite CMS versions up to 109.6 contain a local file inclusion vulnerability in its ajax and require-maxsite dispatchers allowing unauthenticated attackers to execute arbitrary privileged handlers.

MaxSite CMS web-application lfi vulnerability
1r 1t 1c
high advisory

Local File Inclusion in Eventin WordPress Plugin

The Eventin WordPress plugin contains a local file inclusion vulnerability in the event_layout parameter, allowing authenticated contributors to execute arbitrary PHP code.

PoC Eventin lfi vulnerability wordpress webserver
1r 1t 1c updated
high advisory

Arbitrary Command Execution in Snipe-IT Backup Restoration

Snipe-IT versions prior to 8.7.0 are vulnerable to OS command injection when a superadministrator restores a crafted backup archive, allowing arbitrary command execution via the MySQL client.

Snipe-IT +1 remote-code-execution cve vulnerability web-vulnerability css-injection account-takeover cve-2026-86751 ssrf +8
1r 14t 1c updated
critical advisory

Local File Inclusion Vulnerability in Divi Ajax Filter

An unauthenticated Local File Inclusion (LFI) vulnerability in the Divi Ajax Filter plugin for WordPress enables attackers to execute arbitrary PHP code via the custom_loop_template parameter.

PoC Divi Ajax Filter wordpress lfi web-application rce
1r 1t 1c updated
high advisory

Local File Inclusion Vulnerability in Verdure Core WordPress Plugin

An unauthenticated Local File Inclusion vulnerability in Verdure Core versions 1.2 and earlier allows remote attackers to execute arbitrary PHP code on affected WordPress sites.

Verdure Core lfi wordpress vulnerability web-application
1r 1c
high advisory

NocoBase Authenticated Remote Code Execution via File Write and LFI Chain

An authenticated admin can achieve remote code execution in NocoBase prior to v2.1.5 by chaining arbitrary file uploads via storage root manipulation with a local file inclusion vulnerability in the plugin manager.

@nocobase/server remote-code-execution lfi nocobase authentication-bypass
1r 2t
high advisory

Directory Traversal and LFI in Ray 2.56.0

Ray 2.56.0 contains a directory traversal and local file inclusion vulnerability in the /api/v0/logs endpoint allowing unauthenticated attackers to read arbitrary files.

Ray webapps directory-traversal lfi
1r 2t
high advisory

Leantime Authenticated LFI and SSRF via Blueprints

Leantime 3.6.2 contains a vulnerability in the Blueprints::import method allowing authenticated attackers to perform SSRF and LFI via the JSON-RPC API.

Leantime lfi ssrf cve-2026-66415 web-vulnerability csrf cve-2026-66416
1t 1c
high advisory

CVE-2026-3576: Planyo WordPress Plugin Vulnerable to SSRF and LFI

The Planyo Online Reservation System plugin for WordPress, in all versions up to and including 3.0, is vulnerable to Server-Side Request Forgery (SSRF) leading to Local File Inclusion (LFI), allowing an unauthenticated attacker to exploit the `ulap.php` file by supplying a `file://` URL that bypasses the host allowlist, reading arbitrary local files on the server and retrieving their contents in the HTTP response, potentially disclosing sensitive data.

PoC Planyo Online Reservation System plugin <= 3.0 wordpress plugin ssrf lfi web-application cve
1r 2t 1c updated
high advisory

Local File Inclusion Vulnerability in LA-Studio Element Kit for Elementor Plugin for WordPress

A Local File Inclusion vulnerability exists in the LA-Studio Element Kit for Elementor plugin for WordPress, affecting all versions up to and including 1.6.1, which allows authenticated attackers with contributor-level access or higher to include and execute arbitrary .php files on the server due to improper path traversal handling and an easily bypassed extension check, leading to PHP code execution, access control bypass, and sensitive data exposure.

LA-Studio Element Kit for Elementor plugin for WordPress wordpress plugin vulnerability lfi web
4t 1c
medium advisory

Ruby CSS Parser Vulnerable to SSRF and Local File Disclosure via `read_remote_file`

The `css_parser` library, specifically in versions up to and including 2.2.0, is vulnerable to Server-Side Request Forgery (SSRF) and local file disclosure through improper URI validation in the `CssParser::Parser#read_remote_file` method, allowing attackers to access internal network resources or read local files when processing attacker-controlled CSS.

css_parser <= 2.2.0 ssrf lfi supply-chain ruby vulnerability web-application
4t
critical advisory

motionEye: LFI → Pass-the-Hash Admin → Unsafe Restore → Unauthenticated Action Execution (RCE)

An attacker can chain multiple vulnerabilities in motionEye, including an arbitrary file read (LFI), a signature bypass using password hashes, and an unsafe configuration restore, to achieve unauthenticated remote code execution (RCE) if the normal user password is unset, or authenticated RCE from a normal user account.

motionEye RCE LFI vulnerability unauthenticated privilege-escalation
1r 5t
medium threat

FreePBX Security Advisories for Security-Reporting Module Vulnerabilities

FreePBX released security advisories addressing authenticated SQL injection and local file inclusion vulnerabilities in the Security-Reporting cdr and dashboard modules for FreePBX 16 and 17.

Security-Reporting cdr +3 freepbx sql_injection lfi vulnerability
2r 1t
high advisory

Advanced Database Cleaner Premium WordPress Plugin Vulnerable to Local File Inclusion (CVE-2026-7522)

The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion (LFI) in versions up to 4.1.0, allowing authenticated attackers with subscriber-level access to include and execute arbitrary PHP files on the server via the 'template' parameter, potentially leading to access control bypass, sensitive data access, or code execution.

Advanced Database Cleaner – Premium plugin <= 4.1.0 wordpress lfi cve-2026-7522 local-file-inclusion
2r 2t 1c
high threat

Public Exploit Available for Oracle Reports CVE-2012-3152 and CVE-2012-3153

A public exploit, rwsploit, has been released targeting CVE-2012-3152 and CVE-2012-3153 in Oracle Reports Server versions below 11g, enabling unauthenticated file read, SSRF, and JSP shell upload.

Reports Server oracle cve-2012-3152 cve-2012-3153 lfi ssrf jsp shell rwsploit
2r 1t 1c
high advisory

RTMKit Addons for Elementor WordPress Plugin LFI Vulnerability (CVE-2026-3425)

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to local file inclusion (LFI) via the 'path' parameter in the 'get_content' AJAX action, allowing authenticated attackers with Author-level access or higher to include and execute arbitrary PHP files, leading to potential code execution.

RTMKit Addons for Elementor plugin <= 2.0.2 lfi wordpress plugin cve-2026-3425
1r 2t 1c
high advisory

Yii 2 Local File Inclusion via View Parameter Name Collision (CVE-2026-39850)

A local file inclusion vulnerability (CVE-2026-39850) exists in Yii 2 versions prior to 2.0.55 due to the `View::renderPhpFile()` method's handling of the `_file_` parameter, allowing attackers to read arbitrary files and potentially achieve remote code execution if they can write PHP files.

yii2 lfi file-inclusion php cloud
2r 1t
high advisory

Case Theme User WordPress Plugin Local File Inclusion Vulnerability (CVE-2025-5804)

CVE-2025-5804 is a PHP Local File Inclusion vulnerability in the Case Theme User WordPress plugin before version 1.0.4 due to improper filename control in include/require statements, potentially allowing attackers to execute arbitrary code by including malicious local files.

php lfi wordpress cve-2025-5804
2r 1t 1c
high advisory

CactusThemes VideoPro Theme Local File Inclusion Vulnerability (CVE-2025-58913)

CVE-2025-58913 is a PHP Local File Inclusion vulnerability in the CactusThemes VideoPro WordPress theme, affecting versions from n/a through 2.3.8.1 due to improper control of the filename for include/require statements, potentially allowing unauthorized file access.

wordpress lfi cve-2025-58913
2r 1t 1c
medium advisory

Web Server Local File Inclusion Activity Detected

Detection of potential Local File Inclusion (LFI) activity on web servers through HTTP GET requests attempting to access sensitive local files via directory traversal or known file paths, potentially leading to information disclosure and system compromise.

Nginx +4 web-server lfi file-inclusion discovery credential-access initial-access
3r 4t
critical advisory

Froxlor API Local File Inclusion leads to Remote Code Execution

Froxlor is vulnerable to local file inclusion via path traversal in the `def_language` parameter of the API, leading to remote code execution as the web server user.

Froxlor rce lfi php
2r 3t
high advisory

WWBN AVideo Arbitrary Local File Read Vulnerability (CVE-2026-33354)

WWBN AVideo versions up to 26.0 are vulnerable to an arbitrary local file read via the `chunkFile` parameter in the `POST /objects/aVideoEncoder.json.php` endpoint, allowing authenticated users to read sensitive server files.

AVideo lfi cve-2026-33354 webserver
2r 1t
high advisory

Kubernetes Nginx Ingress LFI Attack

Detection of local file inclusion (LFI) attacks targeting Kubernetes Nginx ingress controllers through analysis of Kubernetes logs.

Nginx Ingress Controller kubernetes lfi nginx ingress cloud
2r 1t
medium advisory

Web Server Local File Inclusion Activity

This rule detects potential Local File Inclusion (LFI) exploitation on web servers by identifying HTTP GET requests attempting to access sensitive local files through directory traversal or known file paths, potentially leading to sensitive information disclosure.

Nginx +4 lfi web-server directory-traversal information-disclosure
2r 1t
high advisory

SmarterTools SmarterMail Local File Inclusion Vulnerability (CVE-2026-7807)

SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint (CVE-2026-7807) that allows authenticated users to read arbitrary .json files, potentially leading to credential compromise.

SmarterMail lfi file-inclusion credential-access
2r 1t 1c
critical advisory

Livemesh Addons for Elementor Plugin LFI Vulnerability (CVE-2026-1620)

The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion (LFI) due to insufficient sanitization of the template name parameter, allowing authenticated attackers to include and execute arbitrary files on the server.

Livemesh Addons for Elementor wordpress lfi cve-2026-1620 elementor
2r 1t 1c
high advisory

AVideo EncoderReceiveImage Local File Inclusion Vulnerability

AVideo is vulnerable to local file inclusion (LFI) via the EncoderReceiveImage endpoint, allowing authenticated uploaders to read sensitive server files by bypassing path traversal restrictions.

AVideo lfi file-disclosure php
2r 1t 1c