← Back
CWE-22

9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,540)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vonets
1Vap11g 300 Firmware
Jun 17, 2026
Sep 26, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a directory traversal.
1Advancedfilemanager
1Advanced File Manager
Jun 17, 2026
Sep 26, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This makes it possible for authenticated attacke...Show more
The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.Show less
-
-
Jun 17, 2026
Sep 25, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted .inv3 file.
1Scriptcase
1Scriptcase
Jun 17, 2026
Sep 25, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended re...Show more
Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “subpage” parameter), which allows unauthenticated remote users to bypass SecurityManager's intended restrictions and list and/or read a parent directory via a “/...” or directly into a path used in the POST parameter “field_file” by a web application.Show less
1Concretecms
1Concrete Cms
Jun 17, 2026
Sep 25, 2024
5.1 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color.  A rogue admin could add malicious code to the Thumbnails/Add-Type. The Concrete CMS Security Team gave...Show more
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color.  A rogue admin could add malicious code to the Thumbnails/Add-Type. The Concrete CMS Security Team gave this a CVSS v4 score of 5.1 with vector https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks,  Alexey Solovyev for reporting. (CNA updated this risk rank on 17 Jan 2025 by lowering the AC based on CVSS 4.0 documentation that access privileges should not be considered for AC).Show less
1Cs Cart
1Cs Cart Multivendor
Jun 17, 2026
Sep 25, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a new add-on.
1Cs Cart
1Cs Cart Multivendor
Jun 17, 2026
Sep 25, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on.
1Exthemes
1Wooevents
Jun 17, 2026
Sep 24, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in the inc/barcode.php file in all versions up to, and including, 4.1.2....Show more
The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in the inc/barcode.php file in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to overwrite arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).Show less
-
-
Jun 17, 2026
Sep 23, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Product Carousel Slider & Grid Ultimate for WooCommerce woo-product-carousel-slider-and-grid-...Show more
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Product Carousel Slider & Grid Ultimate for WooCommerce woo-product-carousel-slider-and-grid-ultimate.This issue affects Product Carousel Slider & Grid Ultimate for WooCommerce: from n/a through <= 1.9.10.Show less
1Wpmet
1Elementskit
Jun 17, 2026
Sep 23, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit Pro allows PHP Local File Inclusion.This issue affects ElementsKit Pro: from n/a through 3.6.0.
1Moxa
1Mxview One
Jun 17, 2026
Sep 21, 2024
6.0 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to the disclosure of sensitive information,...Show more
The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to the disclosure of sensitive information, such as configuration files and JWT signing secrets.Show less
1Enms
1Enms
Jun 17, 2026
Sep 20, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.
1Enms
1Enms
Jun 17, 2026
Sep 20, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.
1Enms
1Enms
Jun 17, 2026
Sep 20, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.
1Enms
1Enms
Jun 17, 2026
Sep 20, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.
1Enms
1Enms
Jun 17, 2026
Sep 20, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.
1Enms
1Enms
Jun 17, 2026
Sep 20, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.
1Oretnom23
1Simple Forum/discussion System
Jun 17, 2026
Sep 20, 2024
5.3 MEDIUM· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument page leads to pa...Show more
A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument page leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.Show less
2Ergophone
Yealink
2Sip T28p Firmware
Tiptel Ip 286 Firmware
Jul 5, 2026
Sep 19, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
1Ivanti
1Endpoint Manager Cloud Services Appliance
Jun 17, 2026
Sep 19, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.