Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.1
Aora: Malicious Files Can Be Accessed from Local System
CVE-2026-27381
Summary
Aora, a software used for online marketplaces, has a security flaw that allows attackers to access files on the same system. This means that if an attacker can exploit this issue, they may be able to read sensitive information or take control of the system. To protect yourself, update Aora to a version higher than 1.3.15.
Original title
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Aora aora allows PHP Local File Inclusion.This issue affects Aora: f...
Original description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Aora aora allows PHP Local File Inclusion.This issue affects Aora: from n/a through <= 1.3.15.
nvd CVSS3.1
8.1
Vulnerability type
CWE-98
Improper Control of Filename for Include
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026