SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-57803

HIGH · CVSS 7.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability in Struktur Core allows for local file inclusion due to improper control of filenames in PHP's include/require statements, potentially enabling attackers to execute arbitrary PHP code. This poses a high risk to any applications using affected versions (up to 2.5.1), as it can lead to unauthorized access and manipulation of sensitive files. Organizations utilizing Struktur Core should prioritize patching this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-57803
Severity
HIGH
CVSS
7.5
EPSS
0.37%

Original NVD Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur Core allows PHP Local File Inclusion. This issue affects Struktur Core: from n/a before 2.7.