Improper Control of Filename for Include/Require...
Critical severity
Unreviewed
Published
Jan 8, 2026
to the GitHub Advisory Database
•
Updated Jan 20, 2026
Description
Published by the National Vulnerability Database
Jan 8, 2026
Published to the GitHub Advisory Database
Jan 8, 2026
Last updated
Jan 20, 2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in THEMELOGI Navian navian allows PHP Local File Inclusion.This issue affects Navian: from n/a through <= 1.5.4.
References