← Back
CWE-552

507 CVEs • Abstraction: Base

Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

JSON object

Loading...

CVEs (507)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cmseasy
1Cmseasy
Jun 17, 2026
May 17, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read t...Show more
cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.Show less
1Contec
1Sv Cpt Mc310 Firmware
Jun 17, 2026
May 12, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php.
1Xxyopen
1Novel Plus
Jun 17, 2026
May 5, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
1Webtoprint
1Web To Print Shop\
Jun 17, 2026
Apr 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it i...Show more
The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_contents function and returning its content base64 encoded in the response. As a result, unauthenticated users could read arbitrary files on the web server (such as /etc/passwd, wp-config.php etc)Show less
1Kitesky
1Kitecms
Jun 17, 2026
Apr 21, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module.
1Samsung
1Accessibility
Jun 17, 2026
Apr 11, 2022
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to access the file with system privilege.
1Asana
1Desktop
Jun 17, 2026
Apr 9, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app into loading a malicious web page.
1Movie Seat Reservation Project
1Movie Seat Reservation
Jun 17, 2026
Apr 8, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home.
174cms
174cms
Jun 17, 2026
Mar 28, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.
1Navercorp
1Whale
Jun 17, 2026
Mar 17, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could access to local HWP files. When the HWP files were opened, the replaced script could read the files.
1Cuppacms
1Cuppacms
Jun 17, 2026
Mar 15, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.
1Secomea
1Gatemanager
Jun 17, 2026
Mar 4, 2022
N/A· v4
8.7 HIGH· v3
8.5 HIGH· v2
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.
1Keep
1Archeevo
Jun 17, 2026
Mar 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local files.
1Horizontcms Project
1Horizontcms
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/.
1Drogon
1Drogon
Jun 17, 2026
Feb 21, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using HttpFile::save() method may enable attackers to write files to arbitrary locations outside the designate...Show more
This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using HttpFile::save() method may enable attackers to write files to arbitrary locations outside the designated target folder.Show less
1Cesanta
1Mongoose
Jun 17, 2026
Feb 18, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target...Show more
This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Feb 9, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg a...Show more
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg and xwiki.properties) through XWiki#invokeServletAndReturnAsString as `$xwiki.invokeServletAndReturnAsString("/WEB-INF/xwiki.cfg")`. This issue has been patched in XWiki versions 12.10.9, 13.4.3 and 13.7-rc-1. Users are advised to update. The only workaround is to limit SCRIPT right.Show less
1Mahara
1Mahara
Jun 17, 2026
Feb 9, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names n...Show more
In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected.)Show less
1Seur Oficial Project
1Seur Oficial
Jun 17, 2026
Feb 7, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction aft...Show more
The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL and a password than an administrator can see in the plugin settings page.Show less
1Taogogo
1Taocms
Jun 17, 2026
Feb 4, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column.