VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 139 of 520
  • CVE-2025-25652HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    In Eptura Archibus 2024.03.01.109, the "Run script" and "Server File" components of the "Database Update Wizard" are vulnerable to directory traversal.

  • CVE-2025-66744HigJan 9, 2026
    risk 0.49cvss 7.5epss 0.02

    In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system

  • CVE-2026-0669HigJan 7, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wikimedia Foundation MediaWiki - CSS extension allows Path Traversal.This issue affects MediaWiki - CSS extension: 1.44, 1.43, 1.39.

  • CVE-2025-67160HigJan 2, 2026
    risk 0.49cvss 7.5epss 0.01

    An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory traversal.

  • CVE-2025-59384HigJan 2, 2026
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qfiling 3.13.1 and later

  • CVE-2022-50792HigDec 30, 2025
    risk 0.49cvss 7.5epss 0.02

    SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attackers can exploit the vulnerability by manipulating the 'file' GET parameter to disclose arbitrary…

  • CVE-2025-61557HigDec 30, 2025
    risk 0.49cvss 7.5epss 0.01

    nixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal.

  • CVE-2024-25183HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.01

    givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.

  • CVE-2025-67254HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.02

    NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.

  • CVE-2025-15227HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.01

    BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

  • CVE-2025-15225HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.01

    WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to read arbitrary system files.

  • CVE-2019-25258HigDec 24, 2025
    risk 0.49cvss 7.5epss 0.01

    LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files through unverified 'suffix' and 'fileVersion' parameters. Attackers can exploit directory traversal techniques in /thumbnail and…

  • CVE-2023-53962HigDec 22, 2025
    risk 0.49cvss 7.5epss 0.01

    SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit the vulnerability by sending crafted multipart form-data…

  • CVE-2025-11540HigDec 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files within the projector.

  • CVE-2025-67442HigDec 19, 2025
    risk 0.49cvss 7.6epss 0.01

    EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export lab files. This interface lacks effective input validation and filtering when processing file path parameters submitted by users.

  • CVE-2025-66905HigDec 19, 2025
    risk 0.49cvss 7.5epss 0.01

    The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from…

  • CVE-2025-67174HigDec 17, 2025
    risk 0.49cvss 7.5epss 0.01

    A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_language_file and default_page_language_file in the admin.php component

  • CVE-2025-67171HigDec 17, 2025
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.

  • CVE-2024-58312HigDec 11, 2025
    risk 0.49cvss 7.5epss 0.01

    xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like using encoded path traversal…

  • CVE-2020-36893HigDec 10, 2025
    risk 0.49cvss 7.5epss 0.02

    Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter to view sensitive configuration files like…