CWE-22
9,572 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,572)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an authenticated attacker to retrieve arbitra...Show more |
Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory. |
ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path traversal issue can occur when providing untrusted input to the `svg` property as an argument to the `b...Show more |
A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1...Show more |
Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters. |
qrcp through 0.8.4, in receive mode, allows ../ Directory Traversal via the file name specified by the uploader. |
1Bold Themes 1Cost Calculator Jun 17, 2026 Feb 28, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ in versions <= 1.6) to perform path traversal and local PHP file inclusion on Windows Web Servers vi...Show more |
The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to download arbitrary files from the web server via a path traversal attack |
A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via download.php. |
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a lang...Show more |
1Zte 2Zxhn F477 Firmware Zxhn F677 FirmwareJun 17, 2026 Feb 24, 2022 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of user modified destination path, an attacker with specific permissions could modify the FTP access path...Show more |
1Ibm 1Sterling External Authentication Server Jun 17, 2026 Feb 24, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import invalid data which co...Show more |
A Directory Traversal vulnerability exists in WeBankPartners wecube-platform 3.2.1 via the file variable in PluginPackageController.java. |
A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php. |
OpenMRS is a patient-based medical record system focusing on giving providers a free customizable electronic medical record system. Affected versions are subject to arbitrary file exfiltration due to failure to sanitize...Show more |
Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2. |
"Sametime Android potential path traversal vulnerability when using File class" |
"Sametime Android PathTraversal Vulnerability" |
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of...Show more |
1Awful Salmonella Tar Project 1Awful Salmonella Tar Jun 17, 2026 Feb 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only list directories (not read files). This occurs because the safe-path? Scheme predicate is not used...Show more |