← Back
CWE-22

9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,540)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Ode
Nov 21, 2024
Mar 5, 2018
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directory traversal, resulting in the potential writing of files under unwanted locatio...Show more
The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directory traversal, resulting in the potential writing of files under unwanted locations, the overwriting of existing files or their deletion. This issue was addressed in Apache ODE 1.3.3 which was released in 2009, however the incorrect name CVE-2008-2370 was used on the advisory by mistake.Show less
13cx
13cx
Jun 17, 2026
Mar 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access to files on the server via path traversal.
1Imagely
1Nextgen Gallery
Jun 17, 2026
Mar 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured.
1Opensuse
1Cryptctl
Nov 21, 2024
Mar 1, 2018
N/A· v4
9.1 CRITICAL· v3
8.5 HIGH· v2
In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database.
2Opensuse
Suse
2Leap
Linux Enterprise Software Development Kit
Nov 21, 2024
Mar 1, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
1Sap
1Customer Relationship Management
Oct 31, 2025
Mar 1, 2018
N/A· v4
6.6 MEDIUM· v3
6.5 MEDIUM· v2
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to t...Show more
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.Show less
1Sap
1Business Application Software Integrated Solution
Nov 21, 2024
Mar 1, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker to exploit insufficient validation of path information provided by users, thus characters r...Show more
ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.Show less
1Blackcat Cms
1Blackcat Cms
Nov 21, 2024
Feb 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the dl parameter.
1Parallels
1Remote Application Server
Nov 21, 2024
Feb 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validation of the file path when requesting a resource under the "RASHTML5Gateway" directory. A r...Show more
In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validation of the file path when requesting a resource under the "RASHTML5Gateway" directory. A remote, unauthenticated attacker could exploit this weakness to read arbitrary files from the vulnerable system using path traversal sequences.Show less
1Joomlaworks
1K2
Jun 17, 2026
Feb 28, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=connector&cmd=file&target=l1_../configurati...Show more
The K2 component 2.8.0 for Joomla! has Incorrect Access Control with directory traversal, allowing an attacker to download arbitrary files, as demonstrated by a view=media&task=connector&cmd=file&target=l1_../configuration.php&download=1 request. The specific pathname ../configuration.php should be base64 encoded for a valid attack. NOTE: the vendor disputes this issue because only files under the media-manager path can be downloaded, and the documentation indicates that sensitive information does not belong there. Nonetheless, 2.8.1 has additional blocking of .php downloadsShow less
1Axxonsoft
1Next
Jun 17, 2026
Feb 27, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
AxxonSoft Axxon Next has Directory Traversal via an initial /css//..%2f substring in a URI.
1Wondercms
1Wondercms
Jun 17, 2026
Feb 27, 2018
N/A· v4
4.9 MEDIUM· v3
5.5 MEDIUM· v2
In index.php in WonderCMS before 2.4.1, remote attackers can delete arbitrary files via directory traversal.
2Debian
Unbit
2Debian Linux
Uwsgi
Jun 17, 2026
Feb 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
1Foxitsoftware
1Mobilepdf
Nov 21, 2024
Feb 26, 2018
N/A· v4
5.5 MEDIUM· v3
3.3 LOW· v2
A Directory Traversal issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs by abusing the URL + escape character during a Wi-Fi transfer, which could be exploited by attackers to bypass intende...Show more
A Directory Traversal issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs by abusing the URL + escape character during a Wi-Fi transfer, which could be exploited by attackers to bypass intended restrictions on local application files.Show less
1Blueriver
1Muracms
Jun 17, 2026
Feb 26, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Blue River Mura CMS before v7.0.7029 supports inline function calls with an [m] tag and [/m] end tag, without proper restrictions on file types or pathnames, which allows remote attackers to execute arbitrary code via an...Show more
Blue River Mura CMS before v7.0.7029 supports inline function calls with an [m] tag and [/m] end tag, without proper restrictions on file types or pathnames, which allows remote attackers to execute arbitrary code via an [m]$.dspinclude("../pathname/executable.jpeg")[/m] approach, where executable.jpeg contains ColdFusion Markup Language code. This can be exploited in conjunction with a CKFinder feature that allows file upload.Show less
1Zzcms
1Zzcms
Jun 17, 2026
Feb 24, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase.class.php or 3/ucenter_api/code/friend.php.
1Leptonica
1Leptonica
Jun 17, 2026
Feb 23, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function does not block '/' characters in the gplot rootname argument, potentially leading to path traversal and arbitrary file overwrite.
1Leptonica
1Leptonica
Nov 21, 2024
Feb 23, 2018
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging ac...Show more
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.Show less
1Eq 3
1Homematic Ccu2 Firmware
Jun 17, 2026
Feb 22, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to write arbitrary files to the device's filesystem....Show more
Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to write arbitrary files to the device's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.Show less
1Eq 3
1Homematic Central Control Unit Ccu2 Firmware
Jun 17, 2026
Feb 22, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to read the first line of an arbitrary file on the CCU2's filesystem. This vulnera...Show more
Directory Traversal / Arbitrary File Read in User.getLanguage method in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers to read the first line of an arbitrary file on the CCU2's filesystem. This vulnerability can be exploited by unauthenticated attackers with access to the web interface.Show less