VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (9,904)

page 438 of 496
  • CVE-2026-65919HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.02

    Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. Attackers can supply absolute paths or…

  • CVE-2026-65702HigJul 23, 2026
    risk 0.00cvss 8.6epss 0.00

    Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary filesystem locations and read conversation metadata from…

  • CVE-2026-65701CriJul 23, 2026
    risk 0.00cvss 9.1epss 0.01

    SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the…

  • CVE-2026-65700CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The…

  • CVE-2026-65695MedJul 23, 2026
    risk 0.00cvss 6.8epss 0.00

    Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read arbitrary .docx files or create and overwrite .docx files outside the intended working directory. Attackers…

  • CVE-2026-65690HigJul 23, 2026
    risk 0.00cvss 8.8epss 0.01

    Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this…

  • CVE-2026-65689CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…

  • CVE-2026-65688CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…

  • CVE-2026-65687CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…

  • CVE-2026-65607MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serve.go). Unlike the main export branch, this branch joins the raw, percent-decoded request path with util.TempDir and serves the…

  • CVE-2026-59555CriJul 23, 2026
    risk 0.00cvss 10.0epss 0.00

    Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.

  • CVE-2026-59542HigJul 23, 2026
    risk 0.00cvss 7.7epss 0.00

    Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.

  • CVE-2026-57716MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.

  • CVE-2026-57696HigJul 23, 2026
    risk 0.00cvss 7.1epss 0.00

    Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.

  • CVE-2026-65754HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.

  • CVE-2026-65713MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories.

  • CVE-2026-65712MedJul 23, 2026
    risk 0.00cvss 6.2epss 0.00

    Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata.

  • CVE-2026-65431CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.

  • CVE-2026-64872MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory.

  • CVE-2026-16078MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.01

    The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access…