cleantalk
Vulnerabilities and Security Researches

Simple Retail Menus, CVE-2025-69387

CVE, Research URL

CVE-2025-69387

Application

Simple Retail Menus

Published on
Feb 20, 2026
Research Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in whatwouldjessedo Simple Retail Menus simple-retail-menus allows PHP Local File Inclusion.This issue affects Simple Retail Menus: from n/a through <= 4.2.1.
Affected versions
max 4.2.1.
Status
vulnerable