Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.1
Little Birdies: Malicious Files Can Be Loaded from Local System
CVE-2026-28129
Summary
A security issue in Little Birdies allows attackers to load files from the local system, potentially exposing sensitive data. This affects versions 1.3.16 and earlier of the software. To protect your site, update to a fixed version of Little Birdies as soon as possible.
Original title
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Little Birdies little-birdies allows PHP Local File Inclusion.Th...
Original description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Little Birdies little-birdies allows PHP Local File Inclusion.This issue affects Little Birdies: from n/a through <= 1.3.16.
nvd CVSS3.1
8.1
Vulnerability type
CWE-98
Improper Control of Filename for Include
Published: 5 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026