
CVE-2026-22395 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Fiorello fiorello allows PHP Lo… https://www.cve.org/CVERecord?id=CVE-2026-22395
Post summary
The text announces a new PHP Remote File Inclusion (RFI) vulnerability (CVE‑2026‑22395) in Mikado‑Themes Fiorello with specific technical details, but no PoC, exploit code, or evidence of active exploitation.
