VYPR

CWE-23

Relative Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-139 · CAPEC-76

CVEs mapped to this weakness (525)

page 15 of 27
  • CVE-2026-47287MedJun 9, 2026
    risk 0.42cvss 6.5epss 0.01

    Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.

  • CVE-2026-8073HigMay 19, 2026
    risk 0.42cvss 7.5epss 0.01

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in the 'downloadZIP' function in all versions up to, and including, 6.0.6. This…

  • CVE-2026-20081MedApr 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials. These vulnerabilities…

  • CVE-2026-20078MedApr 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials. These vulnerabilities…

  • CVE-2026-27489HigApr 1, 2026
    risk 0.42cvss 7.5epss 0.01

    Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version…

  • CVE-2026-31831HigMar 30, 2026
    risk 0.42cvss 7.5epss 0.02

    Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem.…

  • CVE-2025-70952HigMar 25, 2026
    risk 0.42cvss 7.5epss 0.01

    pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.

  • CVE-2025-58467MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the…

  • CVE-2026-25121HigFeb 4, 2026
    risk 0.42cvss 7.5epss 0.00

    apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, a path traversal vulnerability was discovered in apko's dirFS filesystem abstraction. An attacker who can supply a malicious APK package (e.g., via a…

  • CVE-2025-13771MedNov 28, 2025
    risk 0.42cvss 6.5epss 0.00

    WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

  • CVE-2025-10249MedOct 9, 2025
    risk 0.42cvss 6.5epss 0.00

    The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in all versions up to, and including, 6.7.37. This makes it possible for authenticated attackers, with…

  • CVE-2025-60020MedSep 24, 2025
    risk 0.42cvss 6.4epss 0.00

    nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in packet data.

  • CVE-2025-25048MedSep 4, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files to the system due to improper neutralization of sequences that can resolve to a restricted directory.

  • CVE-2025-55748HigSep 3, 2025
    risk 0.42cvss 7.5epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are accessible through jsx and sx endpoints. It's possible to access and read configuration files by using…

  • CVE-2021-4459MedAug 27, 2025
    risk 0.42cvss 6.5epss 0.01

    An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices.

  • CVE-2025-51052MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'file_get_contents()' function call in '/api_vedo/template'.

  • CVE-2025-48957HigJun 2, 2025
    risk 0.42cvss 7.5epss 0.01

    AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions 3.4.4 through 3.5.12 may lead to information disclosure, such as API keys for LLM providers, account passwords, and other sensitive data. The vulnerability has…

  • CVE-2025-30207HigMay 13, 2025
    risk 0.42cvss 7.5epss 0.01

    Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby setups that use PHP's built-in server. Such setups are commonly only used during local development. Sites that use other server software (such…

  • CVE-2025-27610HigMar 10, 2025
    risk 0.42cvss 7.5epss 0.01

    Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack::Static` can serve files under the specified `root:` even if `urls:` are provided, which may expose other files under the specified `root:` unexpectedly. The…

  • CVE-2024-56340MedFeb 28, 2025
    risk 0.42cvss 6.5epss 0.01

    IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.