Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.1

Great Lotus: Malicious Files Can Be Loaded from Local Computer

CVE-2026-22418
Summary

A security issue in Great Lotus can allow an attacker to load files from your own computer into the website. This can be used to steal sensitive information or take control of the website. To stay safe, update to the latest version of Great Lotus.

Original title
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Great Lotus great-lotus allows PHP Local File Inclusion.This is...
Original description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Great Lotus great-lotus allows PHP Local File Inclusion.This issue affects Great Lotus: from n/a through <= 1.3.1.
Vulnerability type
CWE-98 Improper Control of Filename for Include
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026