VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,485)

page 409 of 525
  • CVE-2023-25689LowMar 21, 2023
    risk 0.18cvss 2.7epss 0.01

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. …

  • CVE-2022-40199LowSep 27, 2022
    risk 0.18cvss 2.7epss 0.01

    Directory traversal vulnerability in EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p4 ) and EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote authenticated attacker with an administrative privilege to obtain the product's directory structure information.

  • CVE-2022-36168LowAug 26, 2022
    risk 0.18cvss 2.7epss 0.01

    A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:

  • CVE-2022-27657LowApr 12, 2022
    risk 0.18cvss 2.7epss 0.03

    A highly privileged remote attacker, can gain unauthorized access to display contents of restricted directories by exploiting insufficient validation of path information in SAP Focused Run (Simple Diagnostics Agent 1.0) - version 1.0.

  • CVE-2022-27844LowApr 11, 2022
    risk 0.18cvss 2.7epss 0.01

    Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.9.70

  • CVE-2021-28376LowJan 12, 2022
    risk 0.18cvss 2.7epss 0.01

    ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.

  • CVE-2020-35762LowJun 16, 2021
    risk 0.18cvss 2.7epss 0.01

    bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.

  • CVE-2021-20668LowMar 10, 2021
    risk 0.18cvss 2.7epss 0.01

    Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read an arbitrary path via a specially crafted URL.

  • CVE-2020-10459LowMar 12, 2020
    risk 0.18cvss 2.7epss 0.01

    Path Traversal in admin/assetmanager/assetmanager.php (vulnerable function saved in admin/assetmanager/functions.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to list the files that are stored on the webserver using a dot-dot-slash sequence (../) via the POST…

  • CVE-2020-10457LowMar 12, 2020
    risk 0.18cvss 2.7epss 0.01

    Path Traversal in admin/imagepaster/image-renaming.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to rename any file on the webserver using a dot-dot-slash sequence (../) via the POST parameter imgName (for the new name) and imgUrl (for the current file to be…

  • CVE-2019-9889LowMar 21, 2019
    risk 0.18cvss 2.7epss 0.02

    In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a require call using a crafted type value, leading to Directory Traversal with File Inclusion. An attacker can leverage this vulnerability to execute code…

  • CVE-2018-16237LowAug 30, 2018
    risk 0.18cvss 2.7epss 0.01

    An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI.

  • CVE-2016-1212LowJun 5, 2016
    risk 0.18cvss 2.7epss 0.02

    Directory traversal vulnerability in futomi MP Form Mail CGI Professional Edition 3.2.3 and earlier allows remote authenticated administrators to read arbitrary files via unspecified vectors.

  • CVE-2016-3972LowApr 18, 2016
    risk 0.18cvss 2.7epss 0.01

    Directory traversal vulnerability in the dotTailLogServlet in dotCMS before 3.5.1 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the fileName parameter.

  • CVE-2026-86071LowSep 16, 2026
    risk 0.17cvss 3.7epss 0.00

    Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/github/junrar/LocalFolderExtractor.java can create directories outside the intended extraction root when processing a crafted archive entry.…

  • CVE-2026-78886LowAug 25, 2026
    risk 0.17cvss 3.7epss 0.01

    A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/src/nest/journey/journey-public.controller.ts of the component Public Journey Photo Proxy. Performing a manipulation results in path traversal. The attack can…

  • CVE-2026-44996LowMay 11, 2026
    risk 0.17cvss 3.7epss 0.00

    OpenClaw before 2026.4.15 contains an arbitrary local file read vulnerability in the webchat audio embedding helper that fails to apply local media root containment checks. Attackers can influence agent or tool-produced ReplyPayload.mediaUrl parameters to resolve absolute local…

  • CVE-2026-7020LowApr 26, 2026
    risk 0.17cvss 3.7epss 0.01

    A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argument digest results in path traversal. The attack may be…

  • CVE-2026-30848LowMar 7, 2026
    risk 0.17cvss 3.7epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.8 and 9.5.0-alpha.8, the PagesRouter static file serving route is vulnerable to a path traversal attack that allows unauthenticated reading of files…

  • CVE-2023-52085LowDec 29, 2023
    risk 0.17cvss 3.3epss 0.30

    Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be included without further processing in the compilation of custom stylesheets via LESS. This had the potential…