CVE-2025-31098
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in debounce DeBounce Email Validator allows PHP Local File Inclusion. This issue affects DeBounce Email Validator: from n/a through 5.7.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.70%
- CWE
- CWE-98, CWE-98
- Published
- 2025-04-03
- Last modified
- 2026-08-13
Affected products
- debounce DeBounce Email Validator
- debounce DeBounce Email Validator
Weakness type
Related vulnerabilities
- CVE-2026-41228 — Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Execution
- CVE-2026-9559 — A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files dur
- CVE-2026-11613 — Divi Ajax Filter <= 5.1.2 - Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter
- CVE-2026-7515 — BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
- CVE-2026-66587 — WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability
- CVE-2026-8134 — Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusion
- CVE-2026-8208 — Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the re
- CVE-2026-44177 — Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup