← Vulnerability feed

Vulnerability record · CVE-2026-3826 · published 11 March 2026

CVE-2026-3826: Wellchoose organization portal system php remote file inclusion vulnerability

Wellchoose · Organization Portal System

IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

9.3 CVSS 4.0 Critical EPSS 0.86% · top 43.1% CWE-98 · PHP remote file inclusion
9.3CVSS 4.0 base score
0.86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-3826 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2025-8913Wellchoose organization portal system php remote file inclusion vulnerabilityOrganization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arb…EPSS 0.63%8.7CVE-2025-8912Wellchoose organization portal system path traversal vulnerabilityOrganization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit …EPSS 0.58%7.1CVE-2025-8914Wellchoose organization portal system sql injection vulnerabilityOrganization Portal System developed by WellChoose has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary S…EPSS 0.39%7.1CVE-2025-8909Wellchoose organization portal system path traversal vulnerabilityOrganization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to …EPSS 0.65%5.3CVE-2025-8911Wellchoose organization portal system cross-site scripting vulnerabilityOrganization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to e…EPSS 0.35%5.3CVE-2025-8910Wellchoose organization portal system cross-site scripting vulnerabilityOrganization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to e…EPSS 0.35%5.1CVE-2026-3824Wellchoose organization portal system open redirect vulnerabilityIFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL that tricks users into visit…EPSS 0.33%5.1CVE-2026-3825Wellchoose organization portal system cross-site scripting vulnerabilityIFTOP developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attackers to execute arbitrary JavaSc…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2026-3826), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.