VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 296 of 525
  • CVE-2022-23166MedMay 12, 2022
    risk 0.40cvss 6.1epss 0.01

    Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" path. in the "Insert/Edit Embedded Media" window Choose Type : iFrame and File/URL : [here is the LFI] Solution: Update to…

  • CVE-2021-43988MedApr 20, 2022
    risk 0.40cvss 6.1epss 0.01

    The affected product is vulnerable to a network-based attack by threat actors utilizing crafted naming conventions of files to gain unauthorized access rights.

  • CVE-2022-28544MedApr 11, 2022
    risk 0.40cvss 6.2epss 0.01

    Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.

  • CVE-2021-27473MedMar 23, 2022
    risk 0.40cvss 6.1epss 0.01

    Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extraction. This type of vulnerability is also commonly referred to as a Zip Slip. A local, authenticated attacker can create a…

  • CVE-2021-20133MedDec 30, 2021
    risk 0.40cvss 6.1epss 0.02

    Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set the "message of the day" banner to any file on the system, allowing them to read all or some of…

  • CVE-2021-37731MedSep 7, 2021
    risk 0.40cvss 6.2epss 0.00

    A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.12, 8.3.0.16. Aruba has released patches for Aruba SD-WAN Software and Gateways and…

  • CVE-2020-15858MedAug 21, 2020
    risk 0.40cvss 6.2epss 0.01

    Some devices of Thales DIS (formerly Gemalto, formerly Cinterion) allow Directory Traversal by physically proximate attackers. The directory path access check of the internal flash file system can be circumvented. This flash file system can store application-specific data and…

  • CVE-2020-12827HigJun 17, 2020
    risk 0.40cvss 7.2epss 0.03

    MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.

  • CVE-2019-12477MedJun 7, 2019
    risk 0.40cvss 5.5epss 0.13

    Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI.

  • CVE-2019-6799MedJan 26, 2019
    risk 0.40cvss 5.9epss 0.15

    An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the…

  • CVE-2018-16059MedSep 7, 2018
    risk 0.40cvss 5.3epss 0.30

    Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.

  • CVE-2018-15140MedAug 13, 2018
    risk 0.40cvss 6.5epss 0.17

    Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to read arbitrary files via the "docid" parameter when the mode is set to get.

  • CVE-2018-6660MedApr 2, 2018
    risk 0.40cvss 6.2epss 0.02

    Directory Traversal vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows administrators to use Windows alternate data streams, which could be used to bypass the file extensions, via not properly validating the path when exporting a particular…

  • CVE-2015-5471MedJan 12, 2016
    risk 0.40cvss 5.3epss 0.32

    Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter.

  • CVE-2026-106560HigOct 7, 2026
    risk 0.39cvss 7.1epss 0.00

    Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper repository path validation in a scaffolder backend module. An authenticated user who can execute…

  • CVE-2026-106103HigOct 6, 2026
    risk 0.39cvss 7.1epss 0.00

    Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the…

  • CVE-2026-101044HigSep 27, 2026
    risk 0.39cvss 7.1epss 0.00

    pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, does not validate dependency alias/name paths taken from a lockfile before using them in install-time filesystem joins. When a user installs a project with…

  • CVE-2026-77253HigSep 22, 2026
    risk 0.39cvss 7.1epss 0.00

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence attachment upload tools accept arbitrary local filesystem paths and send the selected bytes to Atlassian. In HTTP or multi-user deployments,…

  • CVE-2026-61647HigSep 21, 2026
    risk 0.39cvss —epss 0.00

    NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through 2.0.2 contain a path traversal vulnerability in the `POST /batch-to-vault` endpoint, also exposed through…

  • CVE-2026-63445HigSep 18, 2026
    risk 0.39cvss —epss 0.01

    Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoints used with the file-system database bind the request-controlled project query parameter into the resource Query structure without validating it against…