Improper Control of Filename for Include/Require...
Moderate severity
Unreviewed
Published
Nov 21, 2025
to the GitHub Advisory Database
•
Updated Jan 20, 2026
Description
Published by the National Vulnerability Database
Nov 21, 2025
Published to the GitHub Advisory Database
Nov 21, 2025
Last updated
Jan 20, 2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MatrixAddons Easy Invoice easy-invoice allows PHP Local File Inclusion.This issue affects Easy Invoice: from n/a through <= 2.1.4.
References