
CVE-2026-28088 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Aqualots aqualots allows PHP Local F… https://www.cve.org/CVERecord?id=CVE-2026-28088
Post summary
The text announces CVE-2026-28088, describing it as an improper filename control that allows PHP remote file inclusion in the ThemeREX Aqualots theme, but provides no evidence of exploitation or patch availability.
