CVE-2025-26757: Full Services Full Customer
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FULL SERVICES FULL Customer full-customer allows PHP Local File Inclusion.This issue affects FULL Customer: from n/a through <= 3.1.26.
Affected products
- Full Services Full Customer: up to and including 3.1.26
Published 2025-02-22. Last modified 2026-06-17.