CWE-23
Relative Path Traversal
Description
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-139 · CAPEC-76
CVEs mapped to this weakness (489)
page 12 of 25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-17518 | Hig | 0.46 | 7.5 | 0.50 | Jan 5, 2021 | Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to… | ||
| CVE-2020-7376 | Hig | 0.46 | 7.1 | 0.01 | Aug 24, 2020 | The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesystem when the module is run on a… | ||
| CVE-2020-12010 | Hig | 0.46 | 7.1 | 0.01 | May 8, 2020 | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow an authenticated user to use a specially crafted file to delete files outside the application’s control. | ||
| CVE-2026-21082 | Med | 0.45 | — | 0.00 | Aug 10, 2026 | Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. | ||
| CVE-2026-14476 | Hig | 0.45 | 8.0 | 0.01 | Jul 7, 2026 | A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root.… | ||
| CVE-2026-50016 | Hig | 0.45 | 8.8 | 0.00 | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses that alias as a filesystem path when linking dependency nodes. As a result, a… | ||
| CVE-2026-8209 | Med | 0.45 | — | 0.00 | May 9, 2026 | Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction results in deletion of the file and a DOS condition. Successful exploitation requires Teacher or higher… | ||
| CVE-2026-33435 | Hig | 0.45 | 8.0 | 0.01 | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable… | ||
| CVE-2024-43399 | Hig | 0.45 | 8.0 | 0.01 | Aug 19, 2024 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the extraction of .a extension… | ||
| CVE-2024-2461 | — | Med | 0.45 | — | 0.01 | Jun 11, 2024 | If exploited an attacker could traverse the file system to access files or directories that would otherwise be inaccessible | |
| CVE-2024-1485 | Hig | 0.45 | 8.0 | 0.01 | Feb 14, 2024 | A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup… | ||
| CVE-2026-39814 | Med | 0.44 | 6.7 | 0.00 | Apr 14, 2026 | A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unauthorized code or commands via <insert… | ||
| CVE-2025-58456 | Med | 0.44 | 6.8 | 0.01 | Oct 23, 2025 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read arbitrary files on the target machine. | ||
| CVE-2024-48892 | Med | 0.44 | 6.8 | 0.00 | Aug 12, 2025 | A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack. | ||
| CVE-2023-0745 | Med | 0.44 | 6.7 | 0.01 | Feb 9, 2023 | The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path traversal characters. This vulnerability is associated with program files… | ||
| CVE-2021-36376 | Hig | 0.44 | 7.8 | 0.00 | Jul 13, 2021 | dandavison delta before 0.8.3 on Windows resolves an executable's pathname as a relative path from the current directory. | ||
| CVE-2020-8865 | Med | 0.44 | 6.3 | 0.07 | Mar 23, 2020 | This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exists within edit.php. When parsing the params[template]… | ||
| CVE-2026-54910 | Hig | 0.43 | 7.7 | 0.00 | Jul 20, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without… | ||
| CVE-2025-59341 | Hig | 0.43 | — | 0.02 | Sep 17, 2025 | esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion (LFI) issue was identified in the esm.sh service URL handling. An attacker could craft a request that causes the server to read and return files from the host… | ||
| CVE-2024-49062 | Med | 0.43 | 6.5 | 0.03 | Dec 12, 2024 | Microsoft SharePoint Information Disclosure Vulnerability |
- risk 0.46cvss 7.5epss 0.50
Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to…
- risk 0.46cvss 7.1epss 0.01
The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesystem when the module is run on a…
- risk 0.46cvss 7.1epss 0.01
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow an authenticated user to use a specially crafted file to delete files outside the application’s control.
- risk 0.45cvss —epss 0.00
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
- risk 0.45cvss 8.0epss 0.01
A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root.…
- risk 0.45cvss 8.8epss 0.00
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses that alias as a filesystem path when linking dependency nodes. As a result, a…
- risk 0.45cvss —epss 0.00
Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction results in deletion of the file and a DOS condition. Successful exploitation requires Teacher or higher…
- risk 0.45cvss 8.0epss 0.01
Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable…
- risk 0.45cvss 8.0epss 0.01
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the extraction of .a extension…
- risk 0.45cvss —epss 0.01
If exploited an attacker could traverse the file system to access files or directories that would otherwise be inaccessible
- risk 0.45cvss 8.0epss 0.01
A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup…
- risk 0.44cvss 6.7epss 0.00
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unauthorized code or commands via <insert…
- risk 0.44cvss 6.8epss 0.01
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and read arbitrary files on the target machine.
- risk 0.44cvss 6.8epss 0.00
A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all versions may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack.
- risk 0.44cvss 6.7epss 0.01
The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path traversal characters. This vulnerability is associated with program files…
- risk 0.44cvss 7.8epss 0.00
dandavison delta before 0.8.3 on Windows resolves an executable's pathname as a relative path from the current directory.
- risk 0.44cvss 6.3epss 0.07
This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exists within edit.php. When parsing the params[template]…
- risk 0.43cvss 7.7epss 0.00
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without…
- risk 0.43cvss —epss 0.02
esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion (LFI) issue was identified in the esm.sh service URL handling. An attacker could craft a request that causes the server to read and return files from the host…
- risk 0.43cvss 6.5epss 0.03
Microsoft SharePoint Information Disclosure Vulnerability