← Back
CWE-22

9,483 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,483)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
2Identity Services Engine
Identity Services Engine Passive Identity Connector
Jun 22, 2026
Jun 17, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker m...Show more
A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.Show less
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
7.7 HIGH· v3
N/A· v2
Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.6 HIGH· v3
N/A· v2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Path Traversal. This issue affects JobCareer: from n/a through 7.3.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
1Apache
1Apache Airflow Providers Sftp
Jun 17, 2026
Jun 17, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via c...Show more
A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is required — the attack surface is any deployment downloading directories from an untrusted SFTP server. Upgrade `apache-airflow-providers-sftp` to 5.8.1 or later.Show less
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. Th...Show more
Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames during extraction, allowing a malicious archive to perform path traversal and write arbitrary files to the host filesystem. The subtitle extraction process downloads a ZIP archive and extracts its entries. The destination file path is constructed by concatenating the raw archive entry name (extracted.name) directly to the temporary directory path. If a malicious ZIP archive containing directory traversal sequences is processed, it escapes the temporary directory boundaries. The application then writes the extracted payload anywhere on the host filesystem subject to the application's current write permissions. This issue has been fixed in version 2.5.0.Show less
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-store repositories through an unauthenticated endpoint, which leads to arb...Show more
Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-store repositories through an unauthenticated endpoint, which leads to arbitrary file read through app-store logo symlinks. The path guard checks only the lexical path before Node reads the file, so a Git app store that contains metadata/logo.jpg as a symbolic link can cause Runtipi to read and return the symlink target. Because the endpoint is public and the symlink target may point outside the cloned repository, this can expose local files from the Runtipi container such as /data/.env, /data/state/seed, logs, or application files. This can disclose JWT secrets, service credentials, local configuration, and operational logs depending on the instance. The issue has been fixed in version 4.10.0.Show less
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.6 HIGH· v3
N/A· v2
Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Subscriber Arbitrary File Download in Woocommerce Book Price <= 1.3 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026 could allow an attacker to write arbitrary files on the server.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
8.6 HIGH· v3
N/A· v2
Unauthenticated Arbitrary File Deletion in Car Zone <= 3.7 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Arbitrary File Download in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
7.7 HIGH· v3
N/A· v2
Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.
-
-
Jun 17, 2026
Jun 17, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue affects Conversational Forms for ChatBot: f...Show more
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue affects Conversational Forms for ChatBot: from n/a through 1.1.8.Show less
1Langchain
1Langgraph Sdk
Jun 26, 2026
Jun 17, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitiz...Show more
LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource operations. Without sanitization of those values, identifiers that contain characters with special meaning in URL paths could cause the resulting request to address a different resource (and potentially a different resource type) than the SDK method's call site indicates. In deployments where the SDK receives identifier values that originate from untrusted sources, this could result in unintended access, modification, or deletion of resources beyond the calling user's authorization scope. This issue is most consequential in deployments that forward end-user-supplied values directly into SDK identifier parameters without first validating them against an expected format (such as a UUID), and rely on URL-prefix-based authorization at an upstream layer (reverse proxy, edge gateway, WAF), where the authorization decision is made on the SDK call's intended path rather than on the final delivered request path. The issue has been fixed in version 0.3.15.Show less
-
-
Jun 17, 2026
Jun 16, 2026
9.3 CRITICAL· v4
N/A· v3
N/A· v2
FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in backend/http/public.go whic...Show more
FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in backend/http/public.go which joins user-controlled fromPath and toPath body fields with the trusted d.share.Path BEFORE the downstream sanitizer runs. Because filepath.Join collapses .. segments during the join, the sanitizer in resourcePatchHandler never sees the traversal and the move/copy/rename operates on a path outside the shared directory. The same root-cause pattern was patched for the bulk DELETE endpoint as CVE-2026-44542 (GHSA-fwj3-42wh-8673), but the PATCH handler with the identical pattern was not updated. A public share link with AllowModify=true is sufficient to exploit this. Anyone holding such a link can move, copy, or rename arbitrary files within the share owner's source root. This issue has been fixed in versions 1.3.3-stable and 1.4.2-beta.Show less
-
-
Jun 17, 2026
Jun 16, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admi...Show more
The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function, which uses strpos() to check that a stored media URL starts with the expected prefix but fails to sanitize path traversal sequences in the remaining relative path before passing it to unlink(). This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the affected site's server which may make remote code execution possible.Show less
-
-
Jun 17, 2026
Jun 15, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.