VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (9,904)

page 439 of 496
  • CVE-2026-15786MedJul 23, 2026
    risk 0.00cvss 4.4epss 0.00

    The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for…

  • CVE-2026-16653MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. Performing a manipulation results in path traversal. Remote exploitation of the attack is…

  • CVE-2026-14985HigJul 22, 2026
    risk 0.00cvss 7.8epss 0.00

    The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script.

  • CVE-2026-56844HigJul 22, 2026
    risk 0.00cvss epss 0.00

    A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.

  • CVE-2026-30633HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.01

    Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools.

  • CVE-2026-50757HigJul 21, 2026
    risk 0.00cvss 7.8epss 0.00

    Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server

  • CVE-2026-30632HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.01

    Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.

  • CVE-2026-15791HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.

  • CVE-2026-15789HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.

  • CVE-2026-15724HigJul 21, 2026
    risk 0.00cvss 8.7epss 0.00

    In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether…

  • CVE-2026-64824HigJul 21, 2026
    risk 0.00cvss 8.4epss 0.01

    Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired…

  • CVE-2026-13693MedJul 21, 2026
    risk 0.00cvss 5.9epss 0.00

    The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a notification email, allowing unauthenticated attackers to read arbitrary server files such as the WordPress configuration file.

  • CVE-2026-53594MedJul 20, 2026
    risk 0.00cvss 4.9epss 0.00

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Logs` feature uses the bundled `rap2hpoutre/laravel-log-viewer` override to decrypt a user-supplied file identifier and then pass the resolved path to Laravel's…

  • CVE-2026-60027HigJul 20, 2026
    risk 0.00cvss epss 0.00

    Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed…

  • CVE-2026-46555HigJul 20, 2026
    risk 0.00cvss 7.7epss 0.00

    WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the…

  • CVE-2026-32820HigJul 20, 2026
    risk 0.00cvss 7.5epss 0.01

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the documentation and static markdown renderer…

  • CVE-2026-27823HigJul 20, 2026
    risk 0.00cvss epss 0.01

    A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior…

  • CVE-2026-52349HigJul 20, 2026
    risk 0.00cvss 7.8epss 0.00

    Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary code via the Spooner file management, VehicleSpawner save/folder/rename functionality, WeaponOptions save/folder/rename…

  • CVE-2026-63739HigJul 20, 2026
    risk 0.00cvss 7.7epss 0.00

    SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or OWNER roles to read files accessible to the SurrealDB process. Attackers can specify arbitrary file paths in the mapper filter and…

  • CVE-2026-12898MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations outside its intended storage…