Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.1
GoTravel: Unsecured File Inclusion Exposes Local Files
CVE-2026-22427
Summary
The GoTravel website allows hackers to access and view local files on the server by exploiting a security flaw in the way it includes PHP files. This could potentially allow unauthorized access to sensitive information. To fix this, update GoTravel to version 2.2 or later.
Original title
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes GoTravel gotravel allows PHP Local File Inclusion.This issue a...
Original description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes GoTravel gotravel allows PHP Local File Inclusion.This issue affects GoTravel: from n/a through <= 2.1.
Vulnerability type
CWE-98
Improper Control of Filename for Include
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026