Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.1

AncoraThemes Gustavo gustavo lets attackers read local files

CVE-2026-22371
Summary

A vulnerability in Gustavo, a theme for a website platform, allows attackers to access and read sensitive files on the server. This could lead to unauthorized access to confidential information. Update to version 1.2.3 or later to fix the issue.

Original title
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Gustavo gustavo allows PHP Local File Inclusion.This issue affe...
Original description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Gustavo gustavo allows PHP Local File Inclusion.This issue affects Gustavo: from n/a through <= 1.2.2.
nvd CVSS3.1 8.1
Vulnerability type
CWE-98 Improper Control of Filename for Include
Published: 20 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026