VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 463 of 520
  • CVE-2026-65921HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.01

    A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.

  • CVE-2026-66397HigJul 27, 2026
    risk 0.00cvss —epss 0.00

    phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by exploiting insufficient sanitization in Image::delete(). Attackers can delete the database.php…

  • CVE-2026-66476MedJul 27, 2026
    risk 0.00cvss 4.9epss 0.00

    Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.

  • CVE-2026-66050HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.01

    NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item…

  • CVE-2026-65436MedJul 27, 2026
    risk 0.00cvss 6.8epss 0.00

    Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.

  • CVE-2026-65878HigJul 27, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.

  • CVE-2026-17514MedJul 27, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes path traversal. The attack requires local access. The exploit has been publicly disclosed and may be…

  • CVE-2026-40000LowJul 27, 2026
    risk 0.00cvss 1.8epss 0.00

    The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path),…

  • CVE-2026-65765MedJul 27, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download actions lead to path traversal vulnerabilities.

  • CVE-2026-14955MedJul 25, 2026
    risk 0.00cvss 6.5epss 0.01

    The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the 'thwcfe_legacy_file' parameter. This makes it possible for authenticated attackers, with subscriber-level access and…

  • CVE-2026-66004MedJul 24, 2026
    risk 0.00cvss 5.3epss 0.00

    BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files by injecting traversal sequences in API response include keys. Attackers performing MITM attacks or prompt injection can…

  • CVE-2026-15420MedJul 24, 2026
    risk 0.00cvss 4.3epss 0.01

    The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with…

  • CVE-2026-16767MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.01

    A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the component ZIP Handler. Performing a manipulation of the argument entryName results in path traversal. It is possible to initiate the…

  • CVE-2026-65694HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.03

    Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single…

  • CVE-2026-15687LowJul 23, 2026
    risk 0.00cvss 2.4epss 0.00

    A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod when enableTarCompressing is false.

  • CVE-2026-65702HigJul 23, 2026
    risk 0.00cvss 8.6epss 0.01

    Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary filesystem locations and read conversation metadata from…

  • CVE-2026-65701CriJul 23, 2026
    risk 0.00cvss 9.1epss 0.01

    SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the…

  • CVE-2026-65700CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.02

    h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The…

  • CVE-2026-65695MedJul 23, 2026
    risk 0.00cvss 6.8epss 0.00

    Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read arbitrary .docx files or create and overwrite .docx files outside the intended working directory. Attackers…

  • CVE-2026-65690HigJul 23, 2026
    risk 0.00cvss 8.8epss 0.01

    Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this…