← Back
CWE-35

172 CVEs • Abstraction: Variant

Path Traversal: '.../...//'

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

JSON object

Loading...

CVEs (172)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Mar 25, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce allows Path Traversal.This issue affects File Uploader for WooCommerce: from n/a through <= 1.0.4.
-
-
Jun 17, 2026
Mar 13, 2026
N/A· v4
5.0 MEDIUM· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue affects Squeeze: from n/a through <= 1.7.7.
1Microsoft
1Aci Confidential Containers
Jun 17, 2026
Mar 5, 2026
N/A· v4
6.7 MEDIUM· v3
N/A· v2
'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
-
-
Jun 17, 2026
Feb 20, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in primersoftware Primer MyData for Woocommerce primer-mydata allows Path Traversal.This issue affects Primer MyData for Woocommerce: from n/a through <= 4.2.8.
1Rocketsoftware
1Trufusion Enterprise
Jun 17, 2026
Feb 17, 2026
9.4 CRITICAL· v4
9.9 CRITICAL· v3
N/A· v2
Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDire...Show more
Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDirectory parameter, which allows path traversal sequences to be included. This allows writing files to arbitrary local filesystem locations and may subsequently lead to remote code execution.Show less
-
-
Jun 17, 2026
Feb 10, 2026
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Vulnerability in GE Vernova Enervista UR Setup on Windows.This issue affects Enervista: 8.6 and previous versions.
1Broadcom
1Fabric Operating System
Jun 17, 2026
Feb 3, 2026
4.6 MEDIUM· v4
2.3 LOW· v3
N/A· v2
A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands “source, ping6, sleep, disown, wait to modify the path variables and move upwar...Show more
A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands “source, ping6, sleep, disown, wait to modify the path variables and move upwards in the directory structure or to traverse to different directories.Show less
1Broadcom
1Fabric Operating System
Jun 17, 2026
Feb 3, 2026
4.6 MEDIUM· v4
2.3 LOW· v3
N/A· v2
A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move upwards in the directory structure or to...Show more
A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move upwards in the directory structure or to traverse to different directories.Show less
-
-
Jun 17, 2026
Jan 26, 2026
8.8 HIGH· v4
N/A· v3
N/A· v2
The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a path traversal vulnerability, which allows an attacker to directly access files via simple GET reque...Show more
The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a path traversal vulnerability, which allows an attacker to directly access files via simple GET requests without prior authentication. Hence, it is possible to retrieve all files stored on the file system, including the SQLite database Database.sq3, containing badge information and the corresponding PIN codes. Additionally, when trying to access certain files, the web server crashes and becomes unreachable for about 60 seconds. This can be abused to continuously send the request and cause denial of service.Show less
-
-
Jun 17, 2026
Jan 8, 2026
N/A· v4
7.7 HIGH· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in beeteam368 VidMov vidmov allows Path Traversal.This issue affects VidMov: from n/a through <= 2.3.8.
-
-
Jun 17, 2026
Jan 7, 2026
N/A· v4
6.4 MEDIUM· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue affects Advanced Database Cleaner PRO: from n/a through 3.2.10.
1Parall
1Jspdf
Jul 20, 2026
Jan 5, 2026
9.2 CRITICAL· v4
7.5 HIGH· v3
N/A· v2
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibili...Show more
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsanitized paths to the loadFile method, a user can retrieve file contents of arbitrary files in the local file system the node process is running in. The file contents are included verbatim in the generated PDFs. Other affected methods are `addImage`, `html`, and `addFont`. Only the node.js builds of the library are affected, namely the `dist/jspdf.node.js` and `dist/jspdf.node.min.js` files. The vulnerability has been fixed in jsPDF@4.0.0. This version restricts file system access per default. This semver-major update does not introduce other breaking changes. Some workarounds areavailable. With recent node versions, jsPDF recommends using the `--permission` flag in production. The feature was introduced experimentally in v20.0.0 and is stable since v22.13.0/v23.5.0/v24.0.0. For older node versions, sanitize user-provided paths before passing them to jsPDF.Show less
-
-
Jun 17, 2026
Dec 31, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress pro-watermark allows Path Traversal.This issue affects Pro Bulk Watermark Plugin for WordPress: from n/a through <= 2.0.
1Microsoft
1Purview
Jun 17, 2026
Dec 18, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.
-
-
Jun 17, 2026
Dec 16, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in WordPress.org Health Check & Troubleshooting health-check allows Path Traversal.This issue affects Health Check & Troubleshooting: from n/a through <= 1.7.1.
-
-
Jun 17, 2026
Dec 10, 2025
5.1 MEDIUM· v4
5.7 MEDIUM· v3
N/A· v2
A Path Traversal vulnerability in usbmuxd allows local users to escalate to the service user.This issue affects usbmuxd: before 3ded00c9985a5108cfc7591a309f9a23d57a8cba.
1Metz Connect
3Ewio2 Bm Firmware
Ewio2 M Bm FirmwareEwio2 M Firmware
Jun 17, 2026
Nov 18, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in php resulting in a remote code execution.
1Axis
1Axis Os
Jun 17, 2026
Nov 11, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configure...Show more
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.Show less
-
-
Jun 17, 2026
Nov 6, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Path Traversal.This is...Show more
Path Traversal: '.../...//' vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Path Traversal.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.10.4.Show less
-
-
Jun 17, 2026
Nov 6, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File Inclusion.This issue affects Blanka - One Page WordPress Theme: from n/a through < 1.5.