VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 396 of 525
  • CVE-2026-17043LowAug 13, 2026
    risk 0.25cvss 3.8epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.

  • CVE-2026-67613MedAug 13, 2026
    risk 0.25cvss 4.9epss 0.01

    CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attackers can manipulate the reportFile parameter…

  • CVE-2026-7547MedJun 19, 2026
    risk 0.25cvss 4.9epss 0.01

    The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in versions up to and including 2.0.4. This is due to insufficient path sanitization in the render_logs_ui() function, which accepts a base64-encoded file name…

  • CVE-2026-41917MedMay 26, 2026
    risk 0.25cvss 4.9epss 0.01

    OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scripting that allows authenticated administrators to read arbitrary files by supplying an attacker-controlled filesystem path through the fsPath parameter with…

  • CVE-2026-41887MedMay 8, 2026
    risk 0.25cvss 4.9epss 0.00

    Flarum is open-source forum software. Prior to versions 1.8.16 and 2.0.0-rc.1, Flarum's patch for CVE-2023-27577 restricted the @import and data-uri() LESS features in the custom_less setting, but the same restriction was never applied to other settings registered as LESS config…

  • CVE-2026-6344MedMay 6, 2026
    risk 0.25cvss 4.9epss 0.01

    The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNotificationActions, which resolves attacker-supplied file-upload URLs into…

  • CVE-2026-1921MedMay 5, 2026
    risk 0.25cvss 4.9epss 0.01

    The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via the `fsReference` AJAX route. This is due to the `findSourceFile()` method normalizing user-supplied `ref` paths containing `../` directory traversal sequences…

  • CVE-2026-25525MedApr 20, 2026
    risk 0.25cvss 4.9epss 0.01

    Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the Dataflow module in OpenMage LTS uses a weak…

  • CVE-2026-39345MedApr 7, 2026
    risk 0.25cvss 4.9epss 0.00

    OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source fails to restrict email template file resolution to the intended plugins directory, allowing an authenticated actor who can influence the template path to read arbitrary…

  • CVE-2026-4222LowMar 16, 2026
    risk 0.25cvss 3.8epss 0.01

    A vulnerability was determined in SSCMS up to 7.4.0. This vulnerability affects the function PathUtils.RemoveParentPath of the file /api/admin/plugins/install/actions/download. This manipulation of the argument path causes path traversal. Remote exploitation of the attack is…

  • CVE-2026-4044LowMar 12, 2026
    risk 0.25cvss 3.8epss 0.01

    A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans.php of the component Delete Handler. Performing a manipulation of the argument files[] results in path traversal. Remote exploitation of the attack is…

  • CVE-2025-15589LowFeb 24, 2026
    risk 0.25cvss 3.8epss 0.01

    A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/controller/Template.php of the component Template Management Page. This manipulation of the argument temn/tp causes path traversal. It is possible to initiate…

  • CVE-2025-15187LowDec 29, 2025
    risk 0.25cvss 3.8epss 0.01

    A vulnerability was found in GreenCMS up to 2.3. This affects an unknown part of the file /DataController.class.php of the component File Handler. Performing a manipulation of the argument sqlFiles/zipFiles results in path traversal. The attack can be initiated remotely. The…

  • CVE-2025-67819MedDec 12, 2025
    risk 0.25cvss 4.9epss 0.01

    An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer logic, an attacker who can call the GetFile method while a shard is in the "Pause file activity" state and the FileReplicationService is reachable can read…

  • CVE-2025-67742LowDec 11, 2025
    risk 0.25cvss 3.8epss 0.01

    In JetBrains TeamCity before 2025.11 path traversal was possible via file upload

  • CVE-2025-8081MedAug 12, 2025
    risk 0.25cvss 4.9epss 0.01

    The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via the Import_Images::import() function due to insufficient controls on the filename specified. This makes it possible for authenticated attackers, with…

  • CVE-2025-27566LowMay 19, 2025
    risk 0.25cvss 3.8epss 0.00

    Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited,…

  • CVE-2025-1973MedMar 22, 2025
    risk 0.25cvss 4.9epss 0.01

    The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the…

  • CVE-2025-27397LowMar 11, 2025
    risk 0.25cvss 3.8epss 0.00

    A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly limit user controlled paths to which logs are written and from where they are read. This could allow an authenticated highly-privileged remote…

  • CVE-2024-13791MedFeb 14, 2025
    risk 0.25cvss 4.9epss 0.01

    Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary…