CVE-2025-5804
High Severity
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Case Themes Case Theme User allows PHP L...
Related Vulnerabilities
- CVE-2026-40100: FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool end MEDIUM
- CVE-2026-25854: Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via th MEDIUM
- CVE-2026-35594: Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrad MEDIUM
- CVE-2026-23781: An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user cred CRITICAL
- CVE-2026-4895: The GreenShift - Animation and Page Builder Blocks plugin for WordPress is vulnerable to Stored Cros MEDIUM
Related Coverage
Threat Actors