← Back
CWE-31

11 CVEs • Abstraction: Variant

Path Traversal: 'dir\..\..\filename'

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize 'dir\..\..\filename' (multiple internal backslash dot dot) sequences that can resolve to a location that is outside of that directory.

JSON object

Loading...

CVEs (11)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dzzoffice
1Dzzoffice
Jun 17, 2026
Aug 5, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.
1Moderncampus
1Omni Cms
Jun 17, 2026
Jun 13, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attacker to enumerate file system information via the dir parameter to listing.php or rss.php.
1Homebrew
1Jan
Jun 17, 2026
Jun 4, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
1Zkteco
1Zkbio Cvsecurity
Jun 17, 2026
May 30, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable...Show more
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4.1.Show less
1Zkteco
1Zkbio Cvsecurity
Jun 17, 2026
May 30, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.
1Ivanti
1Avalanche
Jun 17, 2026
Apr 19, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
-
-
Jun 17, 2026
Mar 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /.. for Directory Traversal, as demonstrated by reading /etc/shadow.
2Fedoraproject
Pgadmin
2Fedora
Pgadmin 4
Jun 17, 2026
Mar 7, 2024
N/A· v4
9.9 CRITICAL· v3
N/A· v2
pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize rem...Show more
pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an authenticated attacker can upload pickle objects, deserialize them, and gain code execution.Show less
1Langchain
1Langchain
Jun 17, 2026
Mar 4, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only fro...Show more
LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only from the hwchase17/langchain-hub GitHub repository. The outcome can be disclosure of an API key for a large language model online service, or remote code execution. (A patch is available as of release 0.1.29 of langchain-core.)Show less
1Webtrees
1Webtrees
Jun 17, 2026
Feb 28, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attacker (in this case, an administrator) can navigate beyond the intended directory (the 'media/' directo...Show more
Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attacker (in this case, an administrator) can navigate beyond the intended directory (the 'media/' directory) to access sensitive files in other parts of the application's file system.Show less
1Prestaworld
1Account Manager
Jun 17, 2026
Feb 27, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guest can download personal information without restriction by performing a path t...Show more
In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack.Show less