SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-57801

HIGH · CVSS 7.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability in Select-Themes SetSail allows for improper control of filenames in PHP, leading to potential local file inclusion attacks. This could enable an attacker to execute arbitrary PHP code on the server, compromising the integrity and confidentiality of the affected system. Organizations using SetSail versions up to 2.1 should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-57801
Severity
HIGH
CVSS
7.5
EPSS
0.37%

Original NVD Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes SetSail setsail allows PHP Local File Inclusion.This issue affects SetSail: from n/a through <= 2.1.