CyberRota Analysis
AI-GeneratedAalto versions up to and including 1.8 are vulnerable to a PHP Local File Inclusion flaw, allowing attackers to manipulate file paths and potentially execute arbitrary code on the server. This vulnerability poses a high risk, as it can lead to unauthorized access and data breaches. Organizations using Aalto should prioritize patching this issue to mitigate the risk of exploitation.
CVE
CVE-2026-57788
Severity
HIGH
CVSS
7.5
EPSS
0.37%
Original NVD Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Aalto aalto allows PHP Local File Inclusion.This issue affects Aalto: from n/a through <= 1.8.