VYPR

CWE-23

Relative Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-139 · CAPEC-76

CVEs mapped to this weakness (489)

page 14 of 25
  • CVE-2025-13771MedNov 28, 2025
    risk 0.42cvss 6.5epss 0.00

    WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

  • CVE-2025-10249MedOct 9, 2025
    risk 0.42cvss 6.5epss 0.00

    The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in all versions up to, and including, 6.7.37. This makes it possible for authenticated attackers, with…

  • CVE-2025-60020MedSep 24, 2025
    risk 0.42cvss 6.4epss 0.00

    nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in packet data.

  • CVE-2025-25048MedSep 4, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files to the system due to improper neutralization of sequences that can resolve to a restricted directory.

  • CVE-2025-55748HigSep 3, 2025
    risk 0.42cvss 7.5epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are accessible through jsx and sx endpoints. It's possible to access and read configuration files by using…

  • CVE-2021-4459MedAug 27, 2025
    risk 0.42cvss 6.5epss 0.01

    An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices.

  • CVE-2025-51052MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'file_get_contents()' function call in '/api_vedo/template'.

  • CVE-2025-48957HigJun 2, 2025
    risk 0.42cvss 7.5epss 0.01

    AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions 3.4.4 through 3.5.12 may lead to information disclosure, such as API keys for LLM providers, account passwords, and other sensitive data. The vulnerability has…

  • CVE-2025-30207HigMay 13, 2025
    risk 0.42cvss 7.5epss 0.01

    Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby setups that use PHP's built-in server. Such setups are commonly only used during local development. Sites that use other server software (such…

  • CVE-2025-27610HigMar 10, 2025
    risk 0.42cvss 7.5epss 0.01

    Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack::Static` can serve files under the specified `root:` even if `urls:` are provided, which may expose other files under the specified `root:` unexpectedly. The…

  • CVE-2024-56340MedFeb 28, 2025
    risk 0.42cvss 6.5epss 0.01

    IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.

  • CVE-2025-1588MedFeb 23, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage-nurse.php. The manipulation of the argument profilepic leads to path traversal: '../filedir'. The attack can…

  • CVE-2024-12645MedDec 16, 2024
    risk 0.42cvss 6.5epss 0.00

    The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could…

  • CVE-2024-45816MedSep 17, 2024
    risk 0.42cvss 6.5epss 0.01

    Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass…

  • CVE-2024-36362MedMay 29, 2024
    risk 0.42cvss 6.5epss 0.01

    In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible

  • CVE-2024-22096MedFeb 2, 2024
    risk 0.42cvss 6.5epss 0.01

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to the filename when using a specific command, allowing them to read arbitrary files from the system.

  • CVE-2024-22421HigJan 19, 2024
    risk 0.42cvss 7.6epss 0.01

    JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an…

  • CVE-2023-46119HigOct 25, 2023
    risk 0.42cvss 7.5epss 0.01

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server crashes when uploading a file without extension. This vulnerability has been patched in versions 5.5.6 and 6.3.1.

  • CVE-2023-4914HigSep 12, 2023
    risk 0.42cvss 7.5epss 0.01

    Relative Path Traversal in GitHub repository cecilapp/cecil prior to 7.47.1.

  • CVE-2023-37288MedJul 10, 2023
    risk 0.42cvss 6.5epss 0.01

    SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.