← Back
CWE-35

181 CVEs • Abstraction: Variant

Path Traversal: '.../...//'

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

JSON object

Loading...

CVEs (181)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Aug 30, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress allows Path Traversal.This issue affects Pro Bulk Watermark Plugin for WordPress: from n/a through 2.0.
-
-
Jun 17, 2026
Aug 28, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Favethemes Houzez allows PHP Local File Inclusion.This issue affects Houzez: from n/a before 4.1.4.
-
-
Jun 17, 2026
Aug 27, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in Printeers Printeers Print & Ship allows Path Traversal.This issue affects Printeers Print & Ship: from n/a through 1.17.0.
-
-
Jun 17, 2026
Aug 20, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in miniOrange Prevent files / folders access prevent-file-access allows Path Traversal.This issue affects Prevent files / folders access: from n/a through <= 2.6.0.
-
-
Jun 17, 2026
Aug 14, 2025
N/A· v4
4.2 MEDIUM· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Path Traversal.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.8.
2Dtsearch
Rarlab
2Dtsearch
Winrar
Aug 11, 2026
Aug 8, 2025
8.4 HIGH· v4
8.8 HIGH· v3
N/A· v2
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered b...Show more
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.Show less
1Checkpoint
2Mobile Access
Remote Access Vpn
Jun 17, 2026
Aug 6, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of...Show more
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.Show less
-
-
Jun 17, 2026
Aug 5, 2025
9.3 CRITICAL· v4
N/A· v3
N/A· v2
DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability
1Splunk
2Splunk
Splunk Cloud Platform
Jun 17, 2026
Jul 7, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.107, 9.3.2408.117, and 9.2.2406.121, a low-privileged user that does not hold the "admin" or "power" S...Show more
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.107, 9.3.2408.117, and 9.2.2406.121, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through the `User Interface - Views` configuration page that could potentially lead to a denial of service (DoS).The user could cause the DoS by exploiting a path traversal vulnerability that allows for deletion of arbitrary files within a Splunk directory. The vulnerability requires the low-privileged user to phish the administrator-level victim by tricking them into initiating a request within their browser. The low-privileged user should not be able to exploit the vulnerability at will.Show less
-
-
Jun 17, 2026
Jul 4, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in VaultDweller Leyka leyka allows PHP Local File Inclusion.This issue affects Leyka: from n/a through <= 3.32.1.
-
-
Jun 17, 2026
Jun 27, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in Creanncy Davenport - Versatile Blog and Magazine WordPress Theme davenport allows PHP Local File Inclusion.This issue affects Davenport - Versatile Blog and Magazine WordPress...Show more
Path Traversal: '.../...//' vulnerability in Creanncy Davenport - Versatile Blog and Magazine WordPress Theme davenport allows PHP Local File Inclusion.This issue affects Davenport - Versatile Blog and Magazine WordPress Theme: from n/a through <= 1.3.Show less
-
-
Jun 17, 2026
Jun 27, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
Path Traversal vulnerability in TMRW-studio Katerio - Magazine allows PHP Local File Inclusion. This issue affects Katerio - Magazine: from n/a through 1.5.1.
-
-
Jun 17, 2026
Jun 17, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in yannisraft Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery aeroscroll-gallery allows Path Traversal.This issue affects Aeroscroll Gallery – I...Show more
Path Traversal: '.../...//' vulnerability in yannisraft Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery aeroscroll-gallery allows Path Traversal.This issue affects Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery: from n/a through <= 1.0.13.Show less
1Microsoft
2365 Apps
Office Long Term Servicing Channel
Jun 17, 2026
Jun 10, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.
1Cyberdata
1011209 Sip Emergency Intercom Firmware
Jun 17, 2026
Jun 9, 2025
9.3 CRITICAL· v4
8.8 HIGH· v3
N/A· v2
CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.
1Qodeinteractive
1Grill And Chow
Jun 17, 2026
Jun 9, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in Mikado-Themes Grill and Chow grillandchow allows PHP Local File Inclusion.This issue affects Grill and Chow: from n/a through <= 1.6.
1Qodeinteractive
1Grandprix
Jun 17, 2026
Jun 9, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issue affects GrandPrix: from n/a through <= 1.6.
1Qodeinteractive
1Mediclinic
Jun 17, 2026
Jun 9, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in Mikado-Themes MediClinic mediclinic allows PHP Local File Inclusion.This issue affects MediClinic: from n/a through <= 2.1.
-
-
Jun 17, 2026
Jun 9, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
Path Traversal: '.../...//' vulnerability in Frenify Arlo arlo allows PHP Local File Inclusion.This issue affects Arlo: from n/a through <= 6.0.3.
-
-
Jun 17, 2026
Jun 5, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allows authenticated users to read arbitrary files outside the Joomla root directory. The flaw is caused...Show more
A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allows authenticated users to read arbitrary files outside the Joomla root directory. The flaw is caused by insufficient sanitization of user-supplied input in file path parameters, allowing attackers to exploit directory traversal sequences (e.g., ../) to access sensitive filesShow less