CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 472 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-49991 | Hig | 0.00 | 8.6 | 0.00 | Jun 26, 2026 | RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write arbitrary objects into other users'… | ||
| CVE-2026-57321 | Hig | 0.00 | 7.1 | 0.00 | Jun 26, 2026 | Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions. | ||
| CVE-2026-56066 | Med | 0.00 | 5.8 | 0.00 | Jun 26, 2026 | Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions. | ||
| CVE-2026-13426 | Med | 0.00 | 5.4 | 0.00 | Jun 26, 2026 | The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal… | ||
| CVE-2025-64152 | Cri | 0.00 | 9.1 | 0.01 | Jun 26, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.6 and 2.0.7, which fixes the issue. | ||
| CVE-2025-55017 | Cri | 0.00 | 9.1 | 0.01 | Jun 26, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6. Users are recommended to upgrade to version 1.3.6 and 2.0.6, which fixes the issue. | ||
| CVE-2026-57872 | Hig | 0.00 | 7.5 | 0.01 | Jun 26, 2026 | An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient validation of user-supplied file path input before the requested file is accessed by the CGI… | ||
| CVE-2026-56445 | Cri | 0.00 | 9.1 | 0.01 | Jun 25, 2026 | The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths. | ||
| CVE-2026-55667 | Hig | 0.00 | 8.2 | 0.00 | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.16, a scoped, non-admin File Browser user holding only the Create permission can delete arbitrary files outside their scope… | ||
| CVE-2026-54250 | Med | 0.00 | 5.8 | 0.00 | Jun 25, 2026 | K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a path traversal vulnerability exists in K3s's etcd snapshot decompression functionality. Zip files containing archive members with maliciously crafted names can… | ||
| CVE-2026-50548 | Cri | 0.00 | 9.8 | 0.01 | Jun 25, 2026 | Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working directory. A flaw was identified in how the agent could modify the working_directory… | ||
| CVE-2026-55439 | Med | 0.00 | 5.5 | 0.01 | Jun 25, 2026 | Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download endpoint allows authenticated administrators to read arbitrary files from the server filesystem. The backup download endpoint (GET… | ||
| CVE-2026-45233 | Hig | 0.00 | 8.1 | 0.01 | Jun 25, 2026 | HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to relocate arbitrary files by supplying directory traversal sequences in the oldfile parameter at the admin autosave endpoint. Attackers can pass unsanitized… | ||
| CVE-2026-48944 | Med | 0.00 | 6.5 | 0.00 | Jun 25, 2026 | The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::copy()`. `JPath::clean` does NOT strip `..`, and there is no allow-list of source paths. An Author can therefore copy… | ||
| CVE-2026-56122 | Hig | 0.00 | 7.5 | 0.01 | Jun 25, 2026 | Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by sending HTTP GET requests with dot-dot-slash sequences that are not sanitized when serving static files from the configured webroot.… | ||
| CVE-2026-56054 | Hig | 0.00 | 7.7 | 0.00 | Jun 25, 2026 | Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions. | ||
| CVE-2026-49506 | Hig | 0.00 | 7.2 | 0.01 | Jun 25, 2026 | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code… | ||
| CVE-2026-8662 | Low | 0.00 | 3.3 | 0.00 | Jun 25, 2026 | Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is limited to file corruption as content cannot be controlled… | ||
| CVE-2026-54223 | Hig | 0.00 | — | 0.01 | Jun 18, 2026 | UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any file on the application’s server that application has privileges to, what results in Remote Code Execution. Because vendor contact attempts were… | ||
| CVE-2026-54193 | Hig | 0.00 | 7.7 | 0.00 | Jun 17, 2026 | Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions. |
- risk 0.00cvss 8.6epss 0.00
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal vulnerability in the Snowball auto-extract feature to write arbitrary objects into other users'…
- risk 0.00cvss 7.1epss 0.00
Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.
- risk 0.00cvss 5.8epss 0.00
Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.
- risk 0.00cvss 5.4epss 0.00
The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal…
- risk 0.00cvss 9.1epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.6 and 2.0.7, which fixes the issue.
- risk 0.00cvss 9.1epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6. Users are recommended to upgrade to version 1.3.6 and 2.0.6, which fixes the issue.
- risk 0.00cvss 7.5epss 0.01
An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient validation of user-supplied file path input before the requested file is accessed by the CGI…
- risk 0.00cvss 9.1epss 0.01
The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.
- risk 0.00cvss 8.2epss 0.00
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.16, a scoped, non-admin File Browser user holding only the Create permission can delete arbitrary files outside their scope…
- risk 0.00cvss 5.8epss 0.00
K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a path traversal vulnerability exists in K3s's etcd snapshot decompression functionality. Zip files containing archive members with maliciously crafted names can…
- risk 0.00cvss 9.8epss 0.01
Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working directory. A flaw was identified in how the agent could modify the working_directory…
- risk 0.00cvss 5.5epss 0.01
Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download endpoint allows authenticated administrators to read arbitrary files from the server filesystem. The backup download endpoint (GET…
- risk 0.00cvss 8.1epss 0.01
HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to relocate arbitrary files by supplying directory traversal sequences in the oldfile parameter at the admin autosave endpoint. Attackers can pass unsanitized…
- risk 0.00cvss 6.5epss 0.00
The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::copy()`. `JPath::clean` does NOT strip `..`, and there is no allow-list of source paths. An Author can therefore copy…
- risk 0.00cvss 7.5epss 0.01
Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by sending HTTP GET requests with dot-dot-slash sequences that are not sanitized when serving static files from the configured webroot.…
- risk 0.00cvss 7.7epss 0.00
Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
- risk 0.00cvss 7.2epss 0.01
Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code…
- risk 0.00cvss 3.3epss 0.00
Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is limited to file corruption as content cannot be controlled…
- risk 0.00cvss —epss 0.01
UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any file on the application’s server that application has privileges to, what results in Remote Code Execution. Because vendor contact attempts were…
- risk 0.00cvss 7.7epss 0.00
Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.