VYPR

CWE-23

Relative Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-139 · CAPEC-76

CVEs mapped to this weakness (489)

page 16 of 25
  • CVE-2026-33733HigApr 22, 2026
    risk 0.40cvss 7.2epss 0.00

    EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled `name` and `scope` values and pass them into template path construction without normalization or traversal…

  • CVE-2026-25951HigFeb 9, 2026
    risk 0.40cvss 7.2epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an authenticated attacker with administrative privileges to bypass directory traversal protections. By using nested traversal…

  • CVE-2025-53082MedJul 29, 2025
    risk 0.40cvss 6.1epss 0.00

    An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.

  • CVE-2024-20310MedApr 3, 2024
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an authenticated user of the interface. This…

  • CVE-2024-22415HigJan 18, 2024
    risk 0.40cvss 7.3epss 0.00

    jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Server Protocol. Installations of jupyter-lsp running in environments without configured file system access control (on the operating…

  • CVE-2026-50181HigJul 10, 2026
    risk 0.39cvss 7.1epss 0.00

    Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat `curr_dir` as the intended working-directory boundary for file operations. However, the tools only change the…

  • CVE-2026-43616HigMay 4, 2026
    risk 0.39cvss 7.1epss 0.00

    Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to the filesystem by crafting malicious archive entries with relative traversal sequences or absolute paths. Attackers can exploit insufficient path normalization…

  • CVE-2026-28459HigMar 5, 2026
    risk 0.39cvss 7.1epss 0.00

    OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway clients to write transcript data to arbitrary locations on the host filesystem. Attackers can supply a sessionFile path outside the sessions directory to create…

  • CVE-2023-27993MedMay 3, 2023
    risk 0.39cvss 6.0epss 0.00

    A relative path traversal [CWE-23] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a privileged attacker to delete arbitrary directories from the underlying file system via crafted CLI commands.

  • CVE-2026-48681MedJun 4, 2026
    risk 0.38cvss 5.9epss 0.01

    OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

  • CVE-2025-59336MedSep 16, 2025
    risk 0.38cvss epss 0.00

    Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of service by overwriting Phoenix runtime files. Package names like ../../package are not properly filtered and pass the validity check of the rockspec…

  • CVE-2025-49466MedJun 5, 2025
    risk 0.38cvss 5.8epss 0.01

    aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the name of an attachment part,

  • CVE-2022-34836MedAug 24, 2022
    risk 0.38cvss 5.9epss 0.01

    Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries. An attacker who successfully exploit the vulnerability could access the Zenon runtime activities…

  • CVE-2018-18990MedFeb 5, 2019
    risk 0.38cvss 5.3epss 0.39

    LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process.

  • CVE-2026-62843MedJul 15, 2026
    risk 0.37cvss 6.8epss 0.00

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which turns a POSIX filename such as…

  • CVE-2025-24819MedApr 7, 2026
    risk 0.37cvss 5.7epss 0.00

    Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Software Manager application.

  • CVE-2025-59456MedSep 17, 2025
    risk 0.37cvss 5.5epss 0.12

    In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload

  • CVE-2024-25944MedMar 29, 2024
    risk 0.37cvss 5.7epss 0.01

    Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, to gain unauthorized access to the files stored on the server filesystem, with the privileges of the running…

  • CVE-2024-24942MedFeb 6, 2024
    risk 0.37cvss 5.3epss 0.32

    In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives

  • CVE-2023-23784MedFeb 16, 2023
    risk 0.37cvss 5.7epss 0.01

    A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to information disclosure via specially crafted web requests.