CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 464 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65689 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can… | ||
| CVE-2026-65688 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can… | ||
| CVE-2026-65687 | Cri | 0.00 | 9.8 | 0.01 | Jul 23, 2026 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can… | ||
| CVE-2026-65607 | Med | 0.00 | 6.5 | 0.01 | Jul 23, 2026 | SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serve.go). Unlike the main export branch, this branch joins the raw, percent-decoded request path with util.TempDir and serves the… | ||
| CVE-2026-59555 | Cri | 0.00 | 10.0 | 0.01 | Jul 23, 2026 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | ||
| CVE-2026-59542 | Hig | 0.00 | 7.7 | 0.00 | Jul 23, 2026 | Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions. | ||
| CVE-2026-57716 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions. | ||
| CVE-2026-57696 | Hig | 0.00 | 7.1 | 0.00 | Jul 23, 2026 | Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. | ||
| CVE-2026-65754 | Hig | 0.00 | 7.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory. | ||
| CVE-2026-65713 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories. | ||
| CVE-2026-65712 | Med | 0.00 | 6.2 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata. | ||
| CVE-2026-65431 | Cri | 0.00 | 9.8 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions. | ||
| CVE-2026-64872 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory. | ||
| CVE-2026-16078 | Med | 0.00 | 6.5 | 0.01 | Jul 23, 2026 | The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access… | ||
| CVE-2026-15786 | Med | 0.00 | 4.4 | 0.00 | Jul 23, 2026 | The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for… | ||
| CVE-2026-16653 | Med | 0.00 | 5.3 | 0.01 | Jul 23, 2026 | A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. Performing a manipulation results in path traversal. Remote exploitation of the attack is… | ||
| CVE-2026-14985 | Hig | 0.00 | 7.8 | 0.00 | Jul 22, 2026 | The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script. | ||
| CVE-2026-56844 | Hig | 0.00 | — | 0.00 | Jul 22, 2026 | A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system. | ||
| CVE-2026-30633 | Hig | 0.00 | 7.5 | 0.01 | Jul 21, 2026 | Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools. | ||
| CVE-2026-50757 | Hig | 0.00 | 7.8 | 0.01 | Jul 21, 2026 | Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server |
- risk 0.00cvss 9.8epss 0.01
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…
- risk 0.00cvss 9.8epss 0.01
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…
- risk 0.00cvss 9.8epss 0.01
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…
- risk 0.00cvss 6.5epss 0.01
SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serve.go). Unlike the main export branch, this branch joins the raw, percent-decoded request path with util.TempDir and serves the…
- risk 0.00cvss 10.0epss 0.01
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
- risk 0.00cvss 7.7epss 0.00
Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
- risk 0.00cvss 7.1epss 0.00
Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
- risk 0.00cvss 7.5epss 0.00
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.
- risk 0.00cvss 6.5epss 0.00
Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories.
- risk 0.00cvss 6.2epss 0.00
Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata.
- risk 0.00cvss 9.8epss 0.00
Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.
- risk 0.00cvss 6.5epss 0.00
Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory.
- risk 0.00cvss 6.5epss 0.01
The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access…
- risk 0.00cvss 4.4epss 0.00
The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for…
- risk 0.00cvss 5.3epss 0.01
A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. Performing a manipulation results in path traversal. Remote exploitation of the attack is…
- risk 0.00cvss 7.8epss 0.00
The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script.
- risk 0.00cvss —epss 0.00
A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.
- risk 0.00cvss 7.5epss 0.01
Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools.
- risk 0.00cvss 7.8epss 0.01
Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server