Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,777
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,941 - 9,960 of 13,238 CVEs
CVE-2026-22456 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Askka askka allows PHP Local File Inclusion.This issue affects Askka: from n/a through <= 1.0.

Vendor: Elated-Themes
Product: Askka
Published: Mar 05, 2026
Source: NVD
CVE-2026-22455 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree Thebe thebe allows Reflected XSS.This issue affects Thebe: from n/a through <= 1.3.0.

Vendor: foreverpinetree
Product: Thebe
Published: Mar 05, 2026
Source: NVD
CVE-2026-22452 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Hoverex hoverex allows PHP Local File Inclusion.This issue affects Hoverex: from n/a through <= 1.5.10.

Vendor: ThemeREX
Product: Hoverex
Published: Mar 05, 2026
Source: NVD
CVE-2026-22449 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Don Peppe donpeppe allows PHP Local File Inclusion.This issue affects Don Peppe: from n/a through <= 1.3.

Vendor: Select-Themes
Product: Don Peppe
Published: Mar 05, 2026
Source: NVD
CVE-2026-22446 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Prowess prowess allows PHP Local File Inclusion.This issue affects Prowess: from n/a through <= 1.8.1.

Vendor: Select-Themes
Product: Prowess
Published: Mar 05, 2026
Source: NVD
CVE-2026-22443 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Alliance alliance allows PHP Local File Inclusion.This issue affects Alliance: from n/a through <= 3.1.1.

Vendor: ThemeREX
Product: Alliance
Published: Mar 05, 2026
Source: NVD
CVE-2026-22442 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LaunchandSell Tribe tribe allows PHP Local File Inclusion.This issue affects Tribe: from n/a through <= 1.7.3.

Vendor: LaunchandSell
Product: Tribe
Published: Mar 05, 2026
Source: NVD
CVE-2026-22441 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Zentrum zentrum allows PHP Local File Inclusion.This issue affects Zentrum: from n/a through <= 1.0.

Vendor: Elated-Themes
Product: Zentrum
Published: Mar 05, 2026
Source: NVD
CVE-2026-22440 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree Thecs thecs allows Reflected XSS.This issue affects Thecs: from n/a through <= 1.4.7.

Vendor: foreverpinetree
Product: Thecs
Published: Mar 05, 2026
Source: NVD
CVE-2026-22439 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Green Planet green-planet allows PHP Local File Inclusion.This issue affects Green Planet: from n/a through <= 1.1.14.

Vendor: AncoraThemes
Product: Green Planet
Published: Mar 05, 2026
Source: NVD
CVE-2026-22438 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree TheBi thebi allows Reflected XSS.This issue affects TheBi: from n/a through <= 1.0.5.

Vendor: foreverpinetree
Product: TheBi
Published: Mar 05, 2026
Source: NVD
CVE-2026-22437 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Playa playa allows PHP Local File Inclusion.This issue affects Playa: from n/a through <= 1.3.9.

Vendor: AncoraThemes
Product: Playa
Published: Mar 05, 2026
Source: NVD
CVE-2026-22436 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Helvig helvig allows PHP Local File Inclusion.This issue affects Helvig: from n/a through <= 1.0.

Vendor: Elated-Themes
Product: Helvig
Published: Mar 05, 2026
Source: NVD
CVE-2026-22435 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes ElectroServ electroserv allows PHP Local File Inclusion.This issue affects ElectroServ: from n/a through <= 1.3.2.

Vendor: AncoraThemes
Product: ElectroServ
Published: Mar 05, 2026
Source: NVD
CVE-2026-22434 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Crown Art crown-art allows PHP Local File Inclusion.This issue affects Crown Art: from n/a through <= 1.2.11.

Vendor: AncoraThemes
Product: Crown Art
Published: Mar 05, 2026
Source: NVD
CVE-2026-22433 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CloudMe cloudme allows PHP Local File Inclusion.This issue affects CloudMe: from n/a through <= 1.2.2.

Vendor: AncoraThemes
Product: CloudMe
Published: Mar 05, 2026
Source: NVD
CVE-2026-22432 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Woopy woopy allows PHP Local File Inclusion.This issue affects Woopy: from n/a through <= 1.2.

Vendor: AncoraThemes
Product: Woopy
Published: Mar 05, 2026
Source: NVD
CVE-2026-22431 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Wabi-Sabi wabi-sabi allows PHP Local File Inclusion.This issue affects Wabi-Sabi: from n/a through <= 1.2.

Vendor: AncoraThemes
Product: Wabi-Sabi
Published: Mar 05, 2026
Source: NVD
CVE-2026-22429 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Verdure verdure allows PHP Local File Inclusion.This issue affects Verdure: from n/a through <= 1.6.

Vendor: Mikado-Themes
Product: Verdure
Published: Mar 05, 2026
Source: NVD
CVE-2026-22428 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Tooth Fairy tooth-fairy allows PHP Local File Inclusion.This issue affects Tooth Fairy: from n/a through <= 1.16.

Vendor: AncoraThemes
Product: Tooth Fairy
Published: Mar 05, 2026
Source: NVD