Skip to content
Threat Feed

Tag

Lfi

8 briefs RSS
medium threat

FreePBX Security Advisories for Security-Reporting Module Vulnerabilities

FreePBX released security advisories addressing authenticated SQL injection and local file inclusion vulnerabilities in the Security-Reporting cdr and dashboard modules for FreePBX 16 and 17.

Security-Reporting cdr +3 freepbx sql_injection lfi vulnerability
2r 1t
high advisory

Advanced Database Cleaner Premium WordPress Plugin Vulnerable to Local File Inclusion (CVE-2026-7522)

The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion (LFI) in versions up to 4.1.0, allowing authenticated attackers with subscriber-level access to include and execute arbitrary PHP files on the server via the 'template' parameter, potentially leading to access control bypass, sensitive data access, or code execution.

Advanced Database Cleaner – Premium plugin <= 4.1.0 wordpress lfi cve-2026-7522 local-file-inclusion
2r 2t 1c
high threat

Public Exploit Available for Oracle Reports CVE-2012-3152 and CVE-2012-3153

A public exploit, rwsploit, has been released targeting CVE-2012-3152 and CVE-2012-3153 in Oracle Reports Server versions below 11g, enabling unauthenticated file read, SSRF, and JSP shell upload.

Reports Server oracle cve-2012-3152 cve-2012-3153 lfi ssrf jsp shell rwsploit
2r 1t 1c
high advisory

RTMKit Addons for Elementor WordPress Plugin LFI Vulnerability (CVE-2026-3425)

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to local file inclusion (LFI) via the 'path' parameter in the 'get_content' AJAX action, allowing authenticated attackers with Author-level access or higher to include and execute arbitrary PHP files, leading to potential code execution.

RTMKit Addons for Elementor plugin <= 2.0.2 lfi wordpress plugin cve-2026-3425
1r 2t 1c
high advisory

Yii 2 Local File Inclusion via View Parameter Name Collision (CVE-2026-39850)

A local file inclusion vulnerability (CVE-2026-39850) exists in Yii 2 versions prior to 2.0.55 due to the `View::renderPhpFile()` method's handling of the `_file_` parameter, allowing attackers to read arbitrary files and potentially achieve remote code execution if they can write PHP files.

yii2 lfi file-inclusion php cloud
2r 1t
high advisory

Case Theme User WordPress Plugin Local File Inclusion Vulnerability (CVE-2025-5804)

CVE-2025-5804 is a PHP Local File Inclusion vulnerability in the Case Theme User WordPress plugin before version 1.0.4 due to improper filename control in include/require statements, potentially allowing attackers to execute arbitrary code by including malicious local files.

php lfi wordpress cve-2025-5804
2r 1t 1c
high advisory

CactusThemes VideoPro Theme Local File Inclusion Vulnerability (CVE-2025-58913)

CVE-2025-58913 is a PHP Local File Inclusion vulnerability in the CactusThemes VideoPro WordPress theme, affecting versions from n/a through 2.3.8.1 due to improper control of the filename for include/require statements, potentially allowing unauthorized file access.

wordpress lfi cve-2025-58913
2r 1t 1c
high advisory

SmarterTools SmarterMail Local File Inclusion Vulnerability (CVE-2026-7807)

SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint (CVE-2026-7807) that allows authenticated users to read arbitrary .json files, potentially leading to credential compromise.

SmarterMail lfi file-inclusion credential-access
2r 1t 1c