← Back
CWE-22

9,563 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,563)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Swoole
1Swoole Php Framework
Jun 17, 2026
Dec 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.
1Librenms
1Librenms
Jun 17, 2026
Dec 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.
1Thinkupapp
1Thinkup
Jun 17, 2026
Dec 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ThinkUp 2.0-beta.10 is affected by a path manipulation vulnerability in Smarty.class.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
1Linecorp
1Armeria
Jun 17, 2026
Dec 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (en...Show more
Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (encoded `/`), such as `/files/..%2Fsecrets.txt`, bypassing Armeria's path validation logic. Armeria 1.13.4 or above contains the hardened path validation logic that handles `%2F` properly. This vulnerability can be worked around by inserting a decorator that performs an additional validation on the request path.Show less
1Sun
1Ehrd
Jun 17, 2026
Dec 1, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path traversal attacks without authentication, access restricted paths and download system files.
1Nodebb
1Nodebb
Jun 17, 2026
Nov 29, 2021
N/A· v4
5.0 MEDIUM· v3
4.0 MEDIUM· v2
Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected `languages/` directory. The vulnerabilit...Show more
Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected `languages/` directory. The vulnerability has been patched as of v1.18.5. Users are advised to upgrade as soon as possible.Show less
1Linuxfoundation
1Backstage
Jun 17, 2026
Nov 29, 2021
N/A· v4
8.5 HIGH· v3
5.5 MEDIUM· v2
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a malicious actor with write access to a registered scaffolder template is able to manipulate the tem...Show more
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a malicious actor with write access to a registered scaffolder template is able to manipulate the template in a way that writes files to arbitrary paths on the scaffolder-backend host instance. This vulnerability can in some situation also be exploited through user input when executing a template, meaning you do not need write access to the templates. This method will not allow the attacker to control the contents of the injected file however, unless the template is also crafted in a specific way that gives control of the file contents. This vulnerability is fixed in version `0.15.14` of the `@backstage/plugin-scaffolder-backend`. This attack is mitigated by restricting access and requiring reviews when registering or modifying scaffolder templates.Show less
1Tripexpress Project
1Tripexpress
Jun 17, 2026
Nov 29, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability.
1S3scanner Project
1S3scanner
Jun 17, 2026
Nov 29, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
S3Scanner before 2.0.2 allows Directory Traversal via a crafted bucket, as demonstrated by a <Key>../ substring in a ListBucketResult element.
1Basercms
1Basercms
Jun 17, 2026
Nov 26, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
BaserCMS is an open source content management system with a focus on Japanese language support. In affected versions users with upload privilege may upload crafted zip files capable of path traversal on the host operatin...Show more
BaserCMS is an open source content management system with a focus on Japanese language support. In affected versions users with upload privilege may upload crafted zip files capable of path traversal on the host operating system. This is a vulnerability that needs to be addressed when the management system is used by an unspecified number of users. If you are eligible, please update to the new version as soon as possible.Show less
1Glpi Project
1Barcode
Jun 17, 2026
Nov 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal vulnerability. This issue was patched in...Show more
Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal vulnerability. This issue was patched in version 2.6.1. As a workaround, delete the `front/send.php` file.Show less
1Aimstack
1Aim
Jun 17, 2026
Nov 23, 2021
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (...Show more
Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on file system including application source code or configuration and critical system files. The vulnerability issue is resolved in Aim v3.1.0.Show less
2Fedoraproject
Matrix
2Fedora
Synapse
Jun 17, 2026
Nov 23, 2021
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an ar...Show more
Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory. No authentication is required for the affected endpoint. The last 2 directories and file name of the path are chosen randomly by Synapse and cannot be controlled by an attacker, which limits the impact. Homeservers with the media repository disabled are unaffected. Homeservers with a federation whitelist are also unaffected, since Synapse will check the remote hostname, including the trailing `../`s, against the whitelist. Server administrators should upgrade to 1.47.1 or later. Server administrators using a reverse proxy could, at the expense of losing media functionality, may block the certain endpoints as a workaround. Alternatively, non-containerized deployments can be adapted to use the hardened systemd config.Show less
1Imagestowebp Project
1Images To Webp
Jun 17, 2026
Nov 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue
1Huawei
1Harmonyos
Jun 17, 2026
Nov 23, 2021
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
There is a Improper Access Control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause media files which can be reads and writes in non-distributed directories on any device on the...Show more
There is a Improper Access Control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause media files which can be reads and writes in non-distributed directories on any device on the network..Show less
1Hancom
1Anysign4pc
Jun 17, 2026
Nov 22, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
1Wipro
1Holmes
Jun 17, 2026
Nov 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary files via absolute path traversal in the SearchString JSON field in /home/download POST data.
1Open Xchange
1Ox App Suite
Jun 17, 2026
Nov 22, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.
1Myscada
1Mydesigner
Jun 17, 2026
Nov 19, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to...Show more
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or overwrite existing files, resulting in remote code execution.Show less
1Greenplum
1Greenplum
Jun 17, 2026
Nov 19, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In versions of Greenplum database prior to 5.28.6 and 6.14.0, greenplum database contains a file path traversal vulnerability leading to information disclosure from the file system. A malicious user can read/write inform...Show more
In versions of Greenplum database prior to 5.28.6 and 6.14.0, greenplum database contains a file path traversal vulnerability leading to information disclosure from the file system. A malicious user can read/write information from the file system using this vulnerability.Show less