SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-57796

HIGH · CVSS 7.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

VLThemes Leedo versions up to and including 3.0.0 are vulnerable to a PHP Local File Inclusion (LFI) flaw due to improper control of filenames in include/require statements. This vulnerability could allow an attacker to execute arbitrary PHP code, potentially leading to unauthorized access or data exposure. Organizations using affected versions of Leedo should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-57796
Severity
HIGH
CVSS
7.5
EPSS
0.37%

Original NVD Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VLThemes Leedo leedo allows PHP Local File Inclusion.This issue affects Leedo: from n/a through <= 3.0.0.