SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-57790

HIGH · CVSS 7.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability in ThemeMove Billey allows for local file inclusion due to improper control of filenames in PHP include/require statements, potentially enabling attackers to execute arbitrary PHP code on affected systems. This issue impacts all versions of Billey up to and including 2.1.8, making it critical for users of this software to prioritize patching or upgrading to mitigate the risk of exploitation. Organizations using this application should urgently assess their exposure and implement necessary security measures.

CVE
CVE-2026-57790
Severity
HIGH
CVSS
7.5
EPSS
0.37%

Original NVD Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.This issue affects Billey: from n/a through <= 2.1.8.