PoC Index

CVE-2025-48157

HIGH 8.1EPSS 2.7%

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Michele Giorgi Formality formality allows PHP Local File Inclusion.This issue affects Formality: from n/a through <= 1.5.9.

CVSS v3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.73% chance of exploitation in the next 30 days, 85th percentile
Nuclei
critical · CWE-98
Published
2025-08-20
Updated
2026-04-28

Nuclei templates (1)

References

Related