VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 15 of 520
  • CVE-2026-30283CriMar 31, 2026
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

  • CVE-2026-30278CriMar 31, 2026
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

  • CVE-2026-4619CriMar 27, 2026
    risk 0.64cvss 9.8epss 0.00

    Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.

  • CVE-2019-25471CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.01

    FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the ft2.php endpoint. Attackers can upload ZIP files containing PHP shells, use the unzip functionality to extract them into…

  • CVE-2025-70231CriMar 5, 2026
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verification codes in /goform/formLogin, it enters /goform/getAuthCode but fails to filter the value of the FILECODE parameter, resulting in a path traversal…

  • CVE-2026-2743CriMar 5, 2026
    risk 0.64cvss 9.8epss 0.01

    Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 and before

  • CVE-2026-2749CriFeb 27, 2026
    risk 0.64cvss 9.9epss 0.00

    Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7.

  • CVE-2026-21659CriFeb 27, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthenticated attacker to execute arbitrary code on the affected device, leading to full system compromise. …

  • CVE-2026-2251CriFeb 27, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to…

  • CVE-2025-50857CriFeb 26, 2026
    risk 0.64cvss 9.8epss 0.02

    ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attackers to execute arbitrary code via a crafted file upload

  • CVE-2026-25785CriFeb 25, 2026
    risk 0.64cvss 9.8epss 0.01

    Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacker to tamper with arbitrary files and execute arbitrary code on the affected system.

  • CVE-2025-69874CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.

  • CVE-2026-0963CriJan 30, 2026
    risk 0.64cvss 9.9epss 0.01

    An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.

  • CVE-2025-14301CriJan 14, 2026
    risk 0.64cvss 9.8epss 0.01

    The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is due to the `process_table_bulk_actions()` function processing user-supplied file paths without authentication checks, nonce…

  • CVE-2022-50796CriDec 30, 2025
    risk 0.64cvss 9.8epss 0.02

    SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to the system with www-data permissions,…

  • CVE-2025-66262CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.01

    Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Tar extraction with -C / allow arbitrary file overwrite…

  • CVE-2025-54347CriNov 24, 2025
    risk 0.64cvss 9.9epss 0.01

    A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to write arbitrary files under certain conditions.

  • CVE-2025-11366CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.01

    N-central < 2025.4 is vulnerable to authentication bypass via path traversal

  • CVE-2025-12493CriNov 4, 2025
    risk 0.64cvss 9.8epss 0.01

    The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the 'load_template' function. This makes it…

  • CVE-2025-12422CriOct 28, 2025
    risk 0.64cvss 9.8epss 0.00

    Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.