CVE-2026-28117 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: March 5, 2026
axiomthemes smart SEO - File Inclusion
Overview
axiomthemes smart SEO <= 2.9 contains a file inclusion vulnerability caused by improper control of filename in include/require statements, letting remote attackers include local files, exploit requires crafted request.
Severity & Score
Impact
Remote attackers can include and execute local files, potentially leading to remote code execution or information disclosure.
Mitigation
Update to the latest version beyond 2.9.
Social Media Activity(1 post)
š CVE-2026-28117 - High (8.1) Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes smart SEO smartSEO allows PHP Local File Inclusion.This issue affects smart SEO: from n/a through <= 2.9. š https://www.thehackerwire.com/vulnerability/CVE-2026-28117/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-28117
- Severity
- High
- CVSS Score
- 8.1
- Type
- file_inclusion
- Status
- unconfirmed
- EPSS
- 11.5%
- Social Posts
- 1
CWE
- CWE-98
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H