VYPR

CWE-23

Relative Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-139 · CAPEC-76

CVEs mapped to this weakness (489)

page 23 of 25
  • CVE-2012-5972Jan 17, 2013
    risk 0.03cvss epss 0.05

    Directory traversal vulnerability in the web server in SpecView 2.5 build 853 and earlier allows remote attackers to read arbitrary files via a ... (dot dot dot) in a URI.

  • CVE-2026-18192MedJul 29, 2026
    risk 0.00cvss 6.5epss 0.00

    VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

  • CVE-2026-63303MedJul 28, 2026
    risk 0.00cvss epss 0.00

    A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this…

  • CVE-2026-15802HigJul 22, 2026
    risk 0.00cvss 8.1epss 0.01

    The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with…

  • CVE-2026-51026MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.01

    Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.

  • CVE-2026-15415MedJul 17, 2026
    risk 0.00cvss 5.5epss 0.00

    AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical diagnostics, drug discovery, and agricultural research. Improper limitation of a pathname to a…

  • CVE-2026-56196HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.

  • CVE-2026-50454HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50426MedJul 14, 2026
    risk 0.00cvss 6.8epss 0.00

    Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.

  • CVE-2026-50663HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.

  • CVE-2026-40400HigJul 14, 2026
    risk 0.00cvss 8.0epss 0.01

    Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

  • CVE-2026-55474MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to traverse outside the intended directory…

  • CVE-2026-59792CriJul 10, 2026
    risk 0.00cvss 9.6epss 0.00

    In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible

  • CVE-2026-59832HigJul 9, 2026
    risk 0.00cvss 7.7epss 0.00

    SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath containment or sensitive-path checks,…

  • CVE-2026-59149MedJul 9, 2026
    risk 0.00cvss 6.5epss 0.00

    Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confined by getSafeFilePath in packages/commons-server/src/libs/server/server.ts with resolvedPath.startsWith(staticBaseDir). That prefix test has no…

  • CVE-2026-61343HigJul 9, 2026
    risk 0.00cvss 7.2epss 0.01

    LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code. Fixed in 5.1.0.

  • CVE-2026-8650MedJul 8, 2026
    risk 0.00cvss 4.5epss 0.00

    Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

  • CVE-2026-57871HigJul 7, 2026
    risk 0.00cvss epss 0.00

    Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. This issue affects MicroRealEstate: through 1.0.0-alpha3.

  • CVE-2025-53829HigJul 6, 2026
    risk 0.00cvss 8.0epss 0.00

    ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with administrative privileges can exploit a path traversal vulnerability in the system to execute arbitrary code. Upgrade ownCloud 10 to version 10.15.3 or…

  • CVE-2026-58522MedJul 3, 2026
    risk 0.00cvss 6.8epss 0.00

    Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.