
CVE-2026-27997 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Maxify maxify allows PHP Local File … https://www.cve.org/CVERecord?id=CVE-2026-27997
Post summary
The message provides a CVE announcement for CVE-2026-27997, describing a PHP remote file inclusion flaw in ThemeREX Maxify, but offers no PoC, exploit code, active exploitation evidence, or patch information.
