Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.1

ThemeREX Asia Garden allows hackers to access local files

CVE-2026-28063
Summary

A security issue in ThemeREX Asia Garden allows hackers to access files on your website by tricking the system into including malicious files. This could allow an attacker to view sensitive information or even take control of your website. Update to ThemeREX Asia Garden version 1.3.2 or later to fix this issue.

Original title
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Asia Garden asia-garden allows PHP Local File Inclusion.This issue ...
Original description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Asia Garden asia-garden allows PHP Local File Inclusion.This issue affects Asia Garden: from n/a through <= 1.3.1.
nvd CVSS3.1 8.1
Vulnerability type
CWE-98 Improper Control of Filename for Include
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026