file-disclosure 8
- XXE Injection via Envelope Import Leads to Arbitrary File Read | Foldmark
- Local File Inclusion via Template Router | CostThis
- Local File Inclusion via Double URL Encoding | Mirage
- SSRF Blocklist Bypass – Internal File Disclosure via Localhost Filtering Evasion | CutCorner
- XXE Injection – Arbitrary File Disclosure via XML Import | Holloway
- Server-Side Template Injection Leading to Remote Code Execution | Outbox
- XInclude Injection to Arbitrary File Read | Tanuki
- Local File Inclusion (LFI) to Sensitive File Disclosure | Mapleton