SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-57743

HIGH · CVSS 8.1 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability allows for improper control of filenames in PHP, leading to local file inclusion in the RT-Theme 18 and its extensions, specifically versions up to 2.5. This could enable an attacker to execute arbitrary PHP code, potentially compromising the server and exposing sensitive data. Organizations using affected versions of RT-Theme 18 should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-57743
Severity
HIGH
CVSS
8.1
EPSS
0.40%

Original NVD Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP Local File Inclusion.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.