SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-57805

HIGH · CVSS 7.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability allows for local file inclusion in the Select-Themes Tonda PHP application, enabling attackers to execute arbitrary PHP code by manipulating file paths. This could lead to unauthorized access to sensitive data or system compromise. Organizations using Tonda versions up to 2.5 should prioritize patching this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-57805
Severity
HIGH
CVSS
7.5
EPSS
0.30%

Original NVD Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Tonda tonda allows PHP Local File Inclusion.This issue affects Tonda: from n/a through <= 2.5.