VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 355 of 525
  • CVE-2015-2007MedJan 3, 2016
    risk 0.33cvss 5.0epss 0.01

    Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.5 Patch 6 allows remote authenticated users to read arbitrary files via a crafted URL.

  • CVE-2026-13224MedSep 30, 2026
    risk 0.32cvss 4.9epss 0.00

    A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request.

  • CVE-2026-17602MedSep 25, 2026
    risk 0.32cvss 4.9epss 0.01

    The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.7.42 via the 'file_name' parameter parameter. This makes it possible for authenticated attackers, with…

  • CVE-2026-15095MedSep 22, 2026
    risk 0.32cvss 4.9epss 0.01

    The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.6.43 via the 'provider' parameter. This makes it possible for authenticated…

  • CVE-2026-16777MedSep 18, 2026
    risk 0.32cvss 4.9epss 0.01

    The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter parameter. This makes it possible for authenticated attackers,…

  • CVE-2026-54585MedSep 17, 2026
    risk 0.32cvss —epss 0.01

    mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malicious or malformed package manifest could…

  • CVE-2026-76434MedSep 16, 2026
    risk 0.32cvss 4.9epss 0.00

    A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read arbitrary files from the affected system. To exploit this vulnerability, the attacker must have…

  • CVE-2026-76432MedSep 16, 2026
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability exists because the affected software does…

  • CVE-2026-76431MedSep 16, 2026
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploit this vulnerability, the attacker must…

  • CVE-2026-55828MedSep 15, 2026
    risk 0.32cvss —epss 0.00

    qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A crafted tar archive can use a symlink chain…

  • CVE-2026-18386MedSep 10, 2026
    risk 0.32cvss 4.9epss 0.01

    The WP BackItUp Community Edition plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.0 via the 'backup_file' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to…

  • CVE-2026-19729MedSep 9, 2026
    risk 0.32cvss 4.9epss 0.00

    A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary…

  • CVE-2026-78624MedSep 8, 2026
    risk 0.32cvss 4.9epss 0.00

    The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.

  • CVE-2026-74235MedSep 4, 2026
    risk 0.32cvss 4.9epss 0.01

    GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_ and appends their values directly to the base configuration…

  • CVE-2026-79653MedAug 27, 2026
    risk 0.32cvss —epss 0.00

    In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage with config key enable.attachment.store.to.file.system, the attacker can manipulate the filename upon upload and can essentially cause arbitrary file path…

  • CVE-2026-81028MedAug 26, 2026
    risk 0.32cvss 4.9epss 0.01

    ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundaries. The configuration loader in server/WebApi.cpp builds each root with File::absolutePath("", item, true); because the…

  • CVE-2026-71932MedAug 24, 2026
    risk 0.32cvss 4.9epss 0.01

    Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger this vulnerability via crafted input containing path traversal…

  • CVE-2026-71492MedAug 20, 2026
    risk 0.32cvss —epss 0.00

    Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values into a Path without canonicalization or…

  • CVE-2026-73383MedAug 18, 2026
    risk 0.32cvss 4.9epss 0.00

    Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.

  • CVE-2026-17604MedAug 16, 2026
    risk 0.32cvss 4.9epss 0.01

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.1.1 via the 'data' parameter parameter. This makes it possible for authenticated attackers, with editor-level…