VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 464 of 520
  • CVE-2026-65689CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…

  • CVE-2026-65688CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…

  • CVE-2026-65687CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can…

  • CVE-2026-65607MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.01

    SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serve.go). Unlike the main export branch, this branch joins the raw, percent-decoded request path with util.TempDir and serves the…

  • CVE-2026-59555CriJul 23, 2026
    risk 0.00cvss 10.0epss 0.01

    Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.

  • CVE-2026-59542HigJul 23, 2026
    risk 0.00cvss 7.7epss 0.00

    Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.

  • CVE-2026-57716MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.

  • CVE-2026-57696HigJul 23, 2026
    risk 0.00cvss 7.1epss 0.00

    Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.

  • CVE-2026-65754HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.

  • CVE-2026-65713MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories.

  • CVE-2026-65712MedJul 23, 2026
    risk 0.00cvss 6.2epss 0.00

    Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata.

  • CVE-2026-65431CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.

  • CVE-2026-64872MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory.

  • CVE-2026-16078MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.01

    The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access…

  • CVE-2026-15786MedJul 23, 2026
    risk 0.00cvss 4.4epss 0.00

    The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for…

  • CVE-2026-16653MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.01

    A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. Performing a manipulation results in path traversal. Remote exploitation of the attack is…

  • CVE-2026-14985HigJul 22, 2026
    risk 0.00cvss 7.8epss 0.00

    The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script.

  • CVE-2026-56844HigJul 22, 2026
    risk 0.00cvss —epss 0.00

    A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.

  • CVE-2026-30633HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.01

    Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools.

  • CVE-2026-50757HigJul 21, 2026
    risk 0.00cvss 7.8epss 0.01

    Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server