VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 408 of 525
  • CVE-2026-3339LowMar 21, 2026
    risk 0.18cvss 2.7epss 0.00

    The Keep Backup Daily plugin for WordPress is vulnerable to Limited Path Traversal in all versions up to, and including, 2.1.1 via the `kbd_open_upload_dir` AJAX action. This is due to insufficient validation of the `kbd_path` parameter, which is only sanitized with…

  • CVE-2026-4285LowMar 17, 2026
    risk 0.18cvss 2.7epss 0.01

    A vulnerability was identified in taoofagi easegen-admin up to 8f87936ac774065b92fb20aab55b274a6ea76433. Impacted is the function recognizeMarkdown of the file yudao-module-digitalcourse/yudao-module-digitalcourse-biz/src/main/java/cn/iocoder/yudao/module/digitalcourse/util/Pdf2M…

  • CVE-2025-61653LowFeb 3, 2026
    risk 0.18cvss —epss 0.00

    Vulnerability in Wikimedia Foundation TextExtracts. This vulnerability is associated with program files includes/ApiQueryExtracts.Php. This issue affects TextExtracts: from * before 1.39.14, 1.43.4, 1.44.1.

  • CVE-2026-1588LowJan 29, 2026
    risk 0.18cvss 2.7epss 0.01

    A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshERP-boot/plugin/installByPath of the component com.gitee.starblues.integration.operator.DefaultPluginOperator. The manipulation of the argument path results in…

  • CVE-2025-13879LowDec 2, 2025
    risk 0.18cvss 2.7epss 0.01

    Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with administrator privileges to list directories other than those to which the have authorized access using the 'directory' parameter in…

  • CVE-2025-12923LowNov 10, 2025
    risk 0.18cvss 2.7epss 0.01

    A vulnerability was determined in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function resourceDownload of the file /dev-api/common/download. Executing manipulation of the argument path can lead to path traversal. The attack can be launched remotely. The…

  • CVE-2025-10723LowOct 24, 2025
    risk 0.18cvss 2.7epss 0.00

    The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to perform LFI attacks

  • CVE-2025-5381LowMay 31, 2025
    risk 0.18cvss 2.7epss 0.01

    A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2. Affected is the function downloadFile of the file /api/File/downloadFile of the component Admin Panel. The manipulation of the argument File leads to path traversal. It is possible to…

  • CVE-2025-32205LowApr 10, 2025
    risk 0.18cvss 2.7epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in piotnetdotcom Piotnet Forms piotnetforms.This issue affects Piotnet Forms: from n/a through <= 1.0.30.

  • CVE-2025-2716LowMar 24, 2025
    risk 0.18cvss 2.7epss 0.01

    A vulnerability classified as problematic was found in China Mobile P22g-CIac 1.0.00.488. This vulnerability affects unknown code of the component Samba Path Handler. The manipulation leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed…

  • CVE-2024-47266LowFeb 13, 2025
    risk 0.18cvss 2.7epss 0.00

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to…

  • CVE-2024-52054LowNov 21, 2024
    risk 0.18cvss 2.7epss 0.01

    Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an XML definition file anywhere on the file system.

  • CVE-2024-10672LowNov 12, 2024
    risk 0.18cvss 2.7epss 0.01

    The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the mpg_upsert_project_source_block() function in all versions up to, and including, 4.0.2. This makes it possible for…

  • CVE-2024-7551LowAug 6, 2024
    risk 0.18cvss 2.7epss 0.01

    A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown function of the file /admin-cp/theme/editor/default of the component Theme Editor. The manipulation leads to path traversal. It is possible to launch the attack…

  • CVE-2023-41825LowMay 3, 2024
    risk 0.18cvss 2.8epss 0.00

    A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files. 

  • CVE-2024-3034LowApr 27, 2024
    risk 0.18cvss 2.7epss 0.01

    The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to traverse…

  • CVE-2024-29196LowMar 26, 2024
    risk 0.18cvss 3.8epss 0.01

    phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. There is a Path Traversal vulnerability in Attachments that allows attackers with admin rights to upload malicious files to other locations of the web root. This vulnerability…

  • CVE-2024-24940LowFeb 6, 2024
    risk 0.18cvss 2.8epss 0.00

    In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives

  • CVE-2023-50785LowJan 25, 2024
    risk 0.18cvss 2.7epss 0.02

    Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.

  • CVE-2023-46122LowOct 23, 2023
    risk 0.18cvss 3.9epss 0.00

    sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, `IO.unzip` allows writing of arbitrary file. This would have potential to overwrite `/root/.ssh/authorized_keys`. Within sbt's main code, `IO.unzip` is used in `pullRemoteCache` task and…