SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-57788

HIGH · CVSS 7.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

Aalto versions up to and including 1.8 are vulnerable to a PHP Local File Inclusion flaw, allowing attackers to manipulate file paths and potentially execute arbitrary code on the server. This vulnerability poses a high risk, as it can lead to unauthorized access and data breaches. Organizations using Aalto should prioritize patching this issue to mitigate the risk of exploitation.

CVE
CVE-2026-57788
Severity
HIGH
CVSS
7.5
EPSS
0.37%

Original NVD Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Aalto aalto allows PHP Local File Inclusion.This issue affects Aalto: from n/a through <= 1.8.