
CVE-2026-28057 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Mandala mandala allows PHP Local Fil… https://www.cve.org/CVERecord?id=CVE-2026-28057
Post summary
The statement announces the new CVE-2026-28057, describing it as a PHP Remote File Inclusion vulnerability affecting ThemeREX Mandala, and provides a link to the official CVE record.
