VYPR

CWE-23

Relative Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-139 · CAPEC-76

CVEs mapped to this weakness (489)

page 21 of 25
  • CVE-2022-20862MedJul 6, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary files on the underlying…

  • CVE-2021-29488MedMay 7, 2021
    risk 0.28cvss 4.3epss 0.01

    SABnzbd is an open source binary newsreader. A vulnerability was discovered in SABnzbd that could trick the `filesystem.renamer()` function into writing downloaded files outside the configured Download Folder via malicious PAR2 files. A patch was released as part of SABnzbd…

  • CVE-2021-27515MedFeb 22, 2021
    risk 0.28cvss 5.3epss 0.02

    url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.

  • CVE-2018-12476MedJan 27, 2020
    risk 0.28cvss 4.3epss 0.01

    Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user if a malicious service is executed. This issue affects:…

  • CVE-2019-11822MedJun 30, 2019
    risk 0.28cvss 4.3epss 0.01

    Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter.

  • CVE-2018-13299MedApr 1, 2019
    risk 0.28cvss 4.3epss 0.01

    Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter.

  • CVE-2025-66386MedNov 28, 2025
    risk 0.27cvss 4.1epss 0.00

    app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.

  • CVE-2025-58752MedSep 8, 2025
    risk 0.27cvss 5.3epss 0.01

    Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or…

  • CVE-2025-55202MedAug 29, 2025
    risk 0.27cvss 5.3epss 0.00

    Opencast is a free, open-source platform to support the management of educational audio and video content. In version 18.0 and versions before 17.7, the protections against path traversal attacks in the UI config module are insufficient, still partially allowing for attacks in…

  • CVE-2024-37138MedJun 26, 2024
    risk 0.27cvss 4.1epss 0.00

    Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC contain a relative path traversal vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the application sending over an unauthorized…

  • CVE-2026-10720MedJun 19, 2026
    risk 0.26cvss epss 0.00

    Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluster members) or join token can manipulate files in an imported remote cluster…

  • CVE-2025-60023MedOct 23, 2025
    risk 0.26cvss 4.0epss 0.00

    A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and delete arbitrary directories on the target machine.

  • CVE-2025-59776MedOct 23, 2025
    risk 0.26cvss 4.0epss 0.00

    A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and create arbitrary directories on the target machine.

  • CVE-2014-8883medAug 31, 2020
    risk 0.26cvss epss 0.01

    All versions of the static file server module nhouston are vulnerable to directory traversal. An attacker can provide input such as `../` to read files outside of the served directory. ## Recommendation It is recommended that a different module be used, as we have been unable…

  • CVE-2026-29101MedMar 19, 2026
    risk 0.25cvss 4.9epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a Denial-of-Service (DoS) vulnerability exists in SuiteCRM modules. Versions 7.15.1 and 8.9.3 patch the issue.

  • CVE-2026-29098MedMar 19, 2026
    risk 0.25cvss 4.9epss 0.00

    SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the `action_exportCustom` function in `modules/ModuleBuilder/controller.php` fails to properly neutralize path traversal sequences in the…

  • CVE-2024-13791MedFeb 14, 2025
    risk 0.25cvss 4.9epss 0.01

    Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary…

  • CVE-2023-1045LowFeb 26, 2023
    risk 0.25cvss 3.8epss 0.01

    A vulnerability was found in MuYuCMS 2.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin.php/accessory/filesdel.html. The manipulation of the argument filedelur leads to relative path traversal. The attack may be…

  • CVE-2022-2922MedSep 30, 2022
    risk 0.25cvss 4.9epss 0.01

    Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.

  • CVE-2022-2106LowJun 27, 2022
    risk 0.25cvss 3.8epss 0.01

    Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-level users to perform path traversal attacks and specify arbitrary files.