← Back
CWE-22

9,486 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,486)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1The Ghost
1Ar Web Content Manager
Apr 23, 2026
Sep 16, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the a paramet...Show more
Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the a parameter.Show less
1Wiccle
1Iwiccle
Apr 23, 2026
Sep 16, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple directory traversal vulnerabilities in iWiccle 1.01, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the show parameter to the admin module, reachable...Show more
Multiple directory traversal vulnerabilities in iWiccle 1.01, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the show parameter to the admin module, reachable through index.php; or (2) the module parameter to index.php.Show less
1Dimofinf
1Infinity Script
Apr 23, 2026
Sep 16, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the options[style_dir] parameter to the de...Show more
Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the options[style_dir] parameter to the default URI.Show less
1Anantasoft
1Gazelle Cms
Apr 23, 2026
Sep 11, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the customizetemplate parameter in a direct request to admin/settemplate.php.
1Anantasoft
1Gazelle Cms
Apr 23, 2026
Sep 11, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in index.php in Anantasoft Gazelle CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.
1Ultrize
1Timesheet
Apr 23, 2026
Sep 10, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter.
1Curveriderhq
1Elgg
Apr 23, 2026
Sep 10, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the js parameter. NOTE: some of these details are ob...Show more
Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the js parameter. NOTE: some of these details are obtained from third party information.Show less
1Ipmotor
1Quarkmail
Apr 23, 2026
Sep 9, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in get_message.cgi in QuarkMail allows remote attackers to read arbitrary files via a .. (dot dot) in the tf parameter.
1Visavi
1Wap Motor
Apr 23, 2026
Sep 9, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the image parameter.
1Xoops
1Uploader
Apr 23, 2026
Sep 8, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a downloadfile action to index.php.
1Celina Jorge
1Facil Cms
Apr 23, 2026
Sep 8, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) change_lang parameter to index.php or (2) modload parameter to modules.php.
1Sinecms
1Sinecms
Apr 23, 2026
Sep 4, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in mods/Integrated/index.php in SineCMS 2.3.5 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the sine[config][ind...Show more
Directory traversal vulnerability in mods/Integrated/index.php in SineCMS 2.3.5 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the sine[config][index_main] parameter.Show less
1Rein Velt
1Vedit
Apr 23, 2026
Sep 3, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in debugger/debug_php.php in Ve-EDIT 0.1.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _GET[filename] parameter.
1Jvitals
1Com Agora
Apr 23, 2026
Sep 3, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to th...Show more
Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, reachable through index.php.Show less
1Vmware
1Studio
Apr 23, 2026
Sep 2, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in a support component in the web interface in VMware Studio 2.0 public beta before build 1017-185256 allows remote attackers to upload files to arbitrary locations via unspecified vecto...Show more
Directory traversal vulnerability in a support component in the web interface in VMware Studio 2.0 public beta before build 1017-185256 allows remote attackers to upload files to arbitrary locations via unspecified vectors.Show less
1Cpanel
1Cpanel
Apr 23, 2026
Sep 1, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Absolute path traversal vulnerability in the Disk Usage module (frontend/x/diskusage/index.html) in cPanel 11.18.3 allows remote attackers to list arbitrary directories via the showtree parameter.
1Kyoceramita
1Scanner File Utility
Apr 23, 2026
Aug 28, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
Directory traversal vulnerability in the Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to upload files to arbitrary locations via a .. (dot dot) in a request.
1Unica
1Affinium Campaign
Apr 23, 2026
Aug 26, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple directory traversal vulnerabilities in Unica Affinium Campaign 7.2.1.0.55 allow remote attackers to (1) create arbitrary directories or files via a .. (dot dot) in the folder name in the new folder functionality...Show more
Multiple directory traversal vulnerabilities in Unica Affinium Campaign 7.2.1.0.55 allow remote attackers to (1) create arbitrary directories or files via a .. (dot dot) in the folder name in the new folder functionality or (2) list arbitrary files via a crafted request to Campaign/CampaignListener.Show less
1Pligg
1Pligg Cms
Apr 23, 2026
Aug 26, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a .. (dot dot) in the $tb_url variable in trackback.php, or (2) include a...Show more
Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a .. (dot dot) in the $tb_url variable in trackback.php, or (2) include arbitrary files via a .. (dot dot) in the template parameter to settemplate.php.Show less
1Hirschelectronics
1Velocity Security Management System
Apr 23, 2026
Aug 26, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.