CVE-2025-22145

Vulnerability Description

Carbon is an international PHP extension for DateTime. Application passing unsanitized user input to Carbon::setLocale are at risk of arbitrary file include, if the application allows users to upload files with .php extension in an folder that allows include or require to read it, then they are at risk of arbitrary code ran on their servers. This vulnerability is fixed in 3.8.4 and 2.72.6.

CVSS:9.9(Critical)

PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3.

CWE-982023
CVSS:9.8(Critical)

A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file ...

CWE-982014
CVSS:9.8(Critical)

A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow...

CWE-982022
CVSS:9.8(Critical)

PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.

CWE-982022
CVSS:9.8(Critical)

The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unau...

CWE-982024
CVSS:9.8(Critical)

The Category Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.2 via the 'params[caf-post-layout]' parameter. This makes it possible for ...

CWE-982024