Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX OsTende ostende allows PHP Local File Inclusion.This issue affects OsTende: from n/a through <= 1.4.3.
CVE-2026-27986
NONE
EPSS 0.17%
Updated Mar 05, 2026
PHP
CVE Details
CVE ID
CVE-2026-27986
Published Date
Mar 05, 2026
Vendor
PHP
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.17%
Likelihood of exploitation in next 30 days
Percentile:
37.2th percentile (higher than 37.2% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory