VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 41 of 520
  • CVE-2018-15745HigAug 30, 2018
    risk 0.60cvss 7.5epss 0.98

    Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.

  • CVE-2018-8780CriApr 3, 2018
    risk 0.60cvss 9.1epss 0.10

    In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed.

  • CVE-2017-1000028HigJul 17, 2017
    risk 0.60cvss 7.5epss 0.99

    Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.

  • CVE-2016-6601HigJan 23, 2017
    risk 0.60cvss 7.5epss 0.97

    Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.

  • CVE-2016-1000112CriOct 6, 2016
    risk 0.60cvss 9.1epss 0.09

    Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin

  • CVE-2009-0244HigJan 21, 2009
    risk 0.60cvss 8.8epss 0.30

    Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and…

  • CVE-2026-80424CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.

  • CVE-2026-81939CriSep 4, 2026
    risk 0.59cvss 9.1epss 0.01

    A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.

  • CVE-2026-77086CriAug 21, 2026
    risk 0.59cvss 9.1epss 0.01

    SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write arbitrary files to any location…

  • CVE-2026-52610CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.01

    An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate" parameter in conjuction…

  • CVE-2026-42162CriAug 17, 2026
    risk 0.59cvss 9.1epss 0.00

    Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated.

  • CVE-2026-19725CriAug 16, 2026
    risk 0.59cvss 9.1epss 0.00

    The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to create a log file in any existing…

  • CVE-2026-14524CriAug 16, 2026
    risk 0.59cvss 9.1epss 0.01

    The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete…

  • CVE-2026-14484CriAug 15, 2026
    risk 0.59cvss 9.1epss 0.01

    The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function in all versions up to, and including, 1.0.4. This makes it possible for…

  • CVE-2026-72569CriAug 10, 2026
    risk 0.59cvss 9.1epss 0.01

    A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option.

  • CVE-2026-53976CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.02

    OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an…

  • CVE-2026-17556CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.01

    A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, and…

  • CVE-2026-58072CriAug 4, 2026
    risk 0.59cvss —epss 0.00

    A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.

  • CVE-2026-12701CriJul 20, 2026
    risk 0.59cvss 9.0epss 0.01

    A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated administrator can craft a…

  • CVE-2026-15265CriJul 14, 2026
    risk 0.59cvss 9.1epss 0.01

    A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution.