← Back
CWE-22

9,572 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,572)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fortinet
1Fortiwlm
Jun 17, 2026
Mar 2, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an authenticated attacker to retrieve arbitra...Show more
Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.Show less
1Qt
1Qt
Jun 17, 2026
Mar 2, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.
1Finastra
1Ssr Pages
Jun 17, 2026
Mar 1, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path traversal issue can occur when providing untrusted input to the `svg` property as an argument to the `b...Show more
ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path traversal issue can occur when providing untrusted input to the `svg` property as an argument to the `build(MessagePageOptions)` function. While there is no known workaround at this time, there is a patch in version 0.1.4.Show less
1Neo4j
1Awesome Procedures
Jun 17, 2026
Mar 1, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1...Show more
A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.Show less
1Max 3000
1Maxsite Cms
Jun 17, 2026
Feb 28, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters.
1Qrcp Project
1Qrcp
Jun 17, 2026
Feb 28, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
qrcp through 0.8.4, in receive mode, allows ../ Directory Traversal via the file name specified by the uploader.
1Bold Themes
1Cost Calculator
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.6) to perform path traversal and local PHP file inclusion on Windows Web Servers vi...Show more
The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.6) to perform path traversal and local PHP file inclusion on Windows Web Servers via the Cost Calculator post's LayoutShow less
1Wpeverest
1Contact Form
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to download arbitrary files from the web server via a path traversal attack
1Xerte
1Xerte
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via download.php.
1Xerte
1Xerte
Jun 17, 2026
Feb 24, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a lang...Show more
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the 'mediapath' variable.Show less
1Zte
2Zxhn F477 Firmware
Zxhn F677 Firmware
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path...Show more
There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path to access and modify the system path contents without authorization, which will cause information leak and affect device operation.Show less
1Ibm
1Sterling External Authentication Server
Jun 17, 2026
Feb 24, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import invalid data which co...Show more
IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import invalid data which could be used for an attack. IBM X-Force ID: 220144.Show less
1Webank
1Wecube
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Directory Traversal vulnerability exists in WeBankPartners wecube-platform 3.2.1 via the file variable in PluginPackageController.java.
1Processwire
1Processwire
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.
1Openmrs
1Openmrs
Jun 17, 2026
Feb 22, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OpenMRS is a patient-based medical record system focusing on giving providers a free customizable electronic medical record system. Affected versions are subject to arbitrary file exfiltration due to failure to sanitize...Show more
OpenMRS is a patient-based medical record system focusing on giving providers a free customizable electronic medical record system. Affected versions are subject to arbitrary file exfiltration due to failure to sanitize request when satisfying GET requests for `/images` & `/initfilter/scripts`. This can allow an attacker to access any file on a system running OpenMRS that is accessible to the user id OpenMRS is running under. Affected implementations should update to the latest patch version of OpenMRS Core for the minor version they use. These are: 2.1.5, 2.2.1, 2.3.5, 2.4.5 and 2.5.3. As a general rule, this vulnerability is already mitigated by Tomcat's URL normalization in Tomcat 7.0.28+. Users on older versions of Tomcat should consider upgrading their Tomcat instance as well as their OpenMRS instance.Show less
1Pimcore
1Pimcore
Jun 17, 2026
Feb 22, 2022
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2.
1Hcltech
1Hcl Sametime
Jun 17, 2026
Feb 21, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
"Sametime Android potential path traversal vulnerability when using File class"
1Hcltech
1Hcl Sametime
Jun 17, 2026
Feb 21, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
"Sametime Android PathTraversal Vulnerability"
1Sygnoos
1Popup Builder
Jun 17, 2026
Feb 21, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of...Show more
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHARShow less
1Awful Salmonella Tar Project
1Awful Salmonella Tar
Jun 17, 2026
Feb 18, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only list directories (not read files). This occurs because the safe-path? Scheme predicate is not used...Show more
A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only list directories (not read files). This occurs because the safe-path? Scheme predicate is not used for directories.Show less