VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (9,904)

page 437 of 496
  • CVE-2026-64731CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.

  • CVE-2026-43772HigJul 27, 2026
    risk 0.00cvss 8.2epss 0.00

    A path traversal issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to break out of its sandbox.

  • CVE-2026-43749HigJul 27, 2026
    risk 0.00cvss 7.8epss 0.00

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

  • CVE-2026-43723HigJul 27, 2026
    risk 0.00cvss 7.8epss 0.00

    A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root privileges.

  • CVE-2026-65921HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.00

    A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.

  • CVE-2026-66397HigJul 27, 2026
    risk 0.00cvss epss 0.00

    phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by exploiting insufficient sanitization in Image::delete(). Attackers can delete the database.php…

  • CVE-2026-66476MedJul 27, 2026
    risk 0.00cvss 4.9epss 0.00

    Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.

  • CVE-2026-66050HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.01

    NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item…

  • CVE-2026-65436MedJul 27, 2026
    risk 0.00cvss 6.8epss 0.00

    Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.

  • CVE-2026-65878HigJul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.

  • CVE-2026-17514MedJul 27, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes path traversal. The attack requires local access. The exploit has been publicly disclosed and may be…

  • CVE-2026-40000LowJul 27, 2026
    risk 0.00cvss 1.8epss 0.00

    The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path),…

  • CVE-2026-65765MedJul 27, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download actions lead to path traversal vulnerabilities.

  • CVE-2026-14955MedJul 25, 2026
    risk 0.00cvss 6.5epss 0.01

    The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and…

  • CVE-2026-66007MedJul 24, 2026
    risk 0.00cvss 6.5epss 0.01

    Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply crafted file_name values with…

  • CVE-2026-66004MedJul 24, 2026
    risk 0.00cvss 5.3epss 0.00

    BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files by injecting traversal sequences in API response include keys. Attackers performing MITM attacks or prompt injection can…

  • CVE-2026-15420MedJul 24, 2026
    risk 0.00cvss 4.3epss 0.01

    The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with…

  • CVE-2026-16767MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the component ZIP Handler. Performing a manipulation of the argument entryName results in path traversal. It is possible to initiate the…

  • CVE-2026-65694HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.02

    Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single…

  • CVE-2026-15687LowJul 23, 2026
    risk 0.00cvss 2.4epss 0.00

    A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod when enableTarCompressing is false.