CWE-98 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-98 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2025-68645A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration …48.9%높음8.8● 실제 악용이 확인됨CVE-2026-87902An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen…45.5%높음8.1CVE-2026-12227The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in al…2.9%심각9.8CVE-2026-27556A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/…0.9%높음8.8CVE-2026-27555A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/…0.8%높음8.8CVE-2026-85200The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and …0.8%높음7.5CVE-2026-13456The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for …0.7%높음7.5CVE-2026-75028The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vu…0.7%높음7.5
전체 목록
22건
CVE-2026-15406The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulne…0.7%높음7.5
CVE-2026-89294The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up…0.6%높음7.5
CVE-2026-92969The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Incl…0.7%높음8.1
CVE-2026-9231The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Loca…0.6%높음7.5
CVE-2026-15667The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulne…0.6%높음7.5
CVE-2026-92174The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to…0.6%높음7.5
CVE-2026-11613The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc…0.5%심각9.8
CVE-2026-50547InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1…0.5%높음7.5
CVE-2026-39353InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1…0.4%심각9.1
CVE-2026-88994The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it t…0.4%보통6.6
CVE-2026-87927MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispat…0.3%높음8.8
CVE-2026-71426GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS.…0.3%높음7.1
CVE-2026-49850InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1…0.3%높음7.5
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.