CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (9,904)
page 438 of 496| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65919 | Hig | 0.00 | 7.5 | 0.02 | Jul 23, 2026 | Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. Attackers can supply absolute paths or… | ||
| CVE-2026-65702 | Hig | 0.00 | 8.6 | 0.00 | Jul 23, 2026 | Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary filesystem locations and read conversation metadata from… | ||
| CVE-2026-65701 | Cri | 0.00 | 9.1 | 0.01 | Jul 23, 2026 | SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the… | ||
| CVE-2026-65700 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The… | ||
| CVE-2026-65695 | Med | 0.00 | 6.8 | 0.00 | Jul 23, 2026 | Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read arbitrary .docx files or create and overwrite .docx files outside the intended working directory. Attackers… | ||
| CVE-2026-65690 | Hig | 0.00 | 8.8 | 0.01 | Jul 23, 2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this… | ||
| CVE-2026-65689 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can… | ||
| CVE-2026-65688 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can… | ||
| CVE-2026-65687 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can… | ||
| CVE-2026-65607 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serve.go). Unlike the main export branch, this branch joins the raw, percent-decoded request path with util.TempDir and serves the… | ||
| CVE-2026-59555 | Cri | 0.00 | 10.0 | 0.00 | Jul 23, 2026 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | ||
| CVE-2026-59542 | Hig | 0.00 | 7.7 | 0.00 | Jul 23, 2026 | Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions. | ||
| CVE-2026-57716 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions. | ||
| CVE-2026-57696 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. | ||
| CVE-2026-65754 | Hig | 0.00 | 7.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory. | ||
| CVE-2026-65713 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories. | ||
| CVE-2026-65712 | Med | 0.00 | 6.2 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata. | ||
| CVE-2026-65431 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions. | ||
| CVE-2026-64872 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory. | ||
| CVE-2026-16078 | Med | 0.00 | 6.5 | 0.01 | Jul 23, 2026 | The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access… |
- risk 0.00cvss 7.5epss 0.02
Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. Attackers can supply absolute paths or…
- risk 0.00cvss 8.6epss 0.00
Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary filesystem locations and read conversation metadata from…
- risk 0.00cvss 9.1epss 0.01
SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the…
- risk 0.00cvss 9.8epss 0.01
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The…
- risk 0.00cvss 6.8epss 0.00
Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read arbitrary .docx files or create and overwrite .docx files outside the intended working directory. Attackers…
- risk 0.00cvss 8.8epss 0.01
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this…
- risk 0.00cvss 9.8epss 0.01
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…
- risk 0.00cvss 9.8epss 0.01
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…
- risk 0.00cvss 9.8epss 0.01
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…
- risk 0.00cvss 6.5epss 0.00
SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serve.go). Unlike the main export branch, this branch joins the raw, percent-decoded request path with util.TempDir and serves the…
- risk 0.00cvss 10.0epss 0.00
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
- risk 0.00cvss 7.7epss 0.00
Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
- risk 0.00cvss 7.1epss 0.00
Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
- risk 0.00cvss 7.5epss 0.00
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.
- risk 0.00cvss 6.5epss 0.00
Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories.
- risk 0.00cvss 6.2epss 0.00
Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata.
- risk 0.00cvss 9.8epss 0.00
Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.
- risk 0.00cvss 6.5epss 0.00
Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory.
- risk 0.00cvss 6.5epss 0.01
The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access…