Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.1

Fiorello: Malicious Files Can Be Accessed on Your Website

CVE-2026-22395
Summary

A flaw in the Fiorello theme allows hackers to access files on your website, potentially stealing sensitive information or disrupting your site. This issue affects Fiorello versions up to 1.0, so if you're using this theme, update to a newer version to fix the problem.

Original title
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Fiorello fiorello allows PHP Local File Inclusion.This issue a...
Original description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Fiorello fiorello allows PHP Local File Inclusion.This issue affects Fiorello: from n/a through <= 1.0.
Vulnerability type
CWE-98 Improper Control of Filename for Include
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026