← Back
CWE-22

9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,540)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Coreftp
1Core Ftp
Jun 17, 2026
Mar 22, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to deter...Show more
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.Show less
1Cisco
4Ip Conference Phone 8832 Firmware
Ip Phone 8800 FirmwareIp Phone 8821 Ex Firmware+1 more
Jun 17, 2026
Mar 22, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem....Show more
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem. The vulnerability is due to insufficient input validation and file-level permissions. An attacker could exploit this vulnerability by uploading invalid files to an affected device. A successful exploit could allow the attacker to write files in arbitrary locations on the filesystem. This vulnerability affects Cisco IP Phone 8800 Series products running a SIP Software release prior to 11.0(5) for Wireless IP Phone 8821 and 8821-EX; and 12.5(1)SR1 for the IP Conference Phone 8832 and the rest of the IP Phone 8800 Series.Show less
1Coreftp
1Core Ftp
Jun 17, 2026
Mar 22, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file exi...Show more
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.Show less
1Vanillaforums
1Vanilla
Jun 17, 2026
Mar 21, 2019
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a require call using a crafted type value, leading to Directory Traversal with File Inclusion. An...Show more
In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a require call using a crafted type value, leading to Directory Traversal with File Inclusion. An attacker can leverage this vulnerability to execute code under the context of the web server.Show less
1Blogengine
1Blogengine.net
Jun 17, 2026
Mar 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially...Show more
An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially untrusted location on the local filesystem. This is especially dangerous if an authenticated user uploads a PostView.ascx file using the file manager utility, which is currently allowed. This results in remote code execution for an authenticated user.Show less
1Gl Inet
1Gl Ar300m Lite Firmware
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impact via directory traversal sequences.
1Gl Inet
1Gl Ar300m Lite Firmware
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.
1Zeit
1Serve
Jun 17, 2026
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server.
1Localhost Now Project
1Localhost Now
Jun 17, 2026
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitrary files on the remote server.
1Apache
1Karaf
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources director...Show more
Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources directories. However, it doesn't do any validation on the paths in the zip file. This means that a malicious user could craft a .kar file with ".." directory names and break out of the directories to write arbitrary content to the filesystem. This is the "Zip-slip" vulnerability - https://snyk.io/research/zip-slip-vulnerability. This vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf releases prior 4.2.3 is impacted.Show less
1Car Rental Script Project
1Car Rental Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall Car Rental Script 2.0.8 has directory traversal via a direct request for a listing of an image directory such as an images/ directory.
1Basic B2b Script Project
1Basic B2b Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall Basic B2B Script 2.0.9 has has directory traversal via a direct request for a listing of an image directory such as an uploads/ directory.
1Entrepreneur Job Portal Script Project
1Entrepreneur Job Portal Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.
1Chartered Accountant \
1 Auditor Website Project
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.
1Advance B2b Script Project
1Advance B2b Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall Advance B2B Script 2.1.4 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.
1Website Seller Script Project
1Website Seller Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such as a .png file.
1Advance Crowdfunding Script Project
1Advance Crowdfunding Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
PHP Scripts Mall Advance Crowdfunding Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
1Charity Donation Script Project
1Charity Donation Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
1Charity Foundation Script Project
1Charity Foundation Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHP Scripts Mall Charity Foundation Script 1 through 3 allows directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
1Consumer Reviews Script Project
1Consumer Reviews Script
Nov 21, 2024
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.