CWE-23
Relative Path Traversal
Description
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-139 · CAPEC-76
CVEs mapped to this weakness (489)
page 23 of 25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2012-5972 | 0.03 | — | 0.05 | Jan 17, 2013 | Directory traversal vulnerability in the web server in SpecView 2.5 build 853 and earlier allows remote attackers to read arbitrary files via a ... (dot dot dot) in a URI. | |||
| CVE-2026-18192 | Med | 0.00 | 6.5 | 0.00 | Jul 29, 2026 | VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files. | ||
| CVE-2026-63303 | Med | 0.00 | — | 0.00 | Jul 28, 2026 | A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this… | ||
| CVE-2026-15802 | Hig | 0.00 | 8.1 | 0.01 | Jul 22, 2026 | The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with… | ||
| CVE-2026-51026 | Med | 0.00 | 6.5 | 0.01 | Jul 20, 2026 | Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request. | ||
| CVE-2026-15415 | Med | 0.00 | 5.5 | 0.00 | Jul 17, 2026 | AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical diagnostics, drug discovery, and agricultural research. Improper limitation of a pathname to a… | ||
| CVE-2026-56196 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network. | ||
| CVE-2026-50454 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50426 | Med | 0.00 | 6.8 | 0.00 | Jul 14, 2026 | Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network. | ||
| CVE-2026-50663 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-40400 | Hig | 0.00 | 8.0 | 0.01 | Jul 14, 2026 | Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. | ||
| CVE-2026-55474 | Med | 0.00 | 6.5 | 0.00 | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to traverse outside the intended directory… | ||
| CVE-2026-59792 | Cri | 0.00 | 9.6 | 0.00 | Jul 10, 2026 | In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible | ||
| CVE-2026-59832 | Hig | 0.00 | 7.7 | 0.00 | Jul 9, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath containment or sensitive-path checks,… | ||
| CVE-2026-59149 | Med | 0.00 | 6.5 | 0.00 | Jul 9, 2026 | Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confined by getSafeFilePath in packages/commons-server/src/libs/server/server.ts with resolvedPath.startsWith(staticBaseDir). That prefix test has no… | ||
| CVE-2026-61343 | Hig | 0.00 | 7.2 | 0.01 | Jul 9, 2026 | LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code. Fixed in 5.1.0. | ||
| CVE-2026-8650 | Med | 0.00 | 4.5 | 0.00 | Jul 8, 2026 | Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | ||
| CVE-2026-57871 | Hig | 0.00 | — | 0.00 | Jul 7, 2026 | Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. This issue affects MicroRealEstate: through 1.0.0-alpha3. | ||
| CVE-2025-53829 | Hig | 0.00 | 8.0 | 0.00 | Jul 6, 2026 | ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with administrative privileges can exploit a path traversal vulnerability in the system to execute arbitrary code. Upgrade ownCloud 10 to version 10.15.3 or… | ||
| CVE-2026-58522 | Med | 0.00 | 6.8 | 0.00 | Jul 3, 2026 | Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. |
- CVE-2012-5972Jan 17, 2013risk 0.03cvss —epss 0.05
Directory traversal vulnerability in the web server in SpecView 2.5 build 853 and earlier allows remote attackers to read arbitrary files via a ... (dot dot dot) in a URI.
- risk 0.00cvss 6.5epss 0.00
VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.
- risk 0.00cvss —epss 0.00
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this…
- risk 0.00cvss 8.1epss 0.01
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with…
- risk 0.00cvss 6.5epss 0.01
Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.
- risk 0.00cvss 5.5epss 0.00
AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical diagnostics, drug discovery, and agricultural research. Improper limitation of a pathname to a…
- risk 0.00cvss 8.8epss 0.01
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
- risk 0.00cvss 7.8epss 0.00
Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 6.8epss 0.00
Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
- risk 0.00cvss 8.8epss 0.01
Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.0epss 0.01
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
- risk 0.00cvss 6.5epss 0.00
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to traverse outside the intended directory…
- risk 0.00cvss 9.6epss 0.00
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
- risk 0.00cvss 7.7epss 0.00
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath containment or sensitive-path checks,…
- risk 0.00cvss 6.5epss 0.00
Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confined by getSafeFilePath in packages/commons-server/src/libs/server/server.ts with resolvedPath.startsWith(staticBaseDir). That prefix test has no…
- risk 0.00cvss 7.2epss 0.01
LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code. Fixed in 5.1.0.
- risk 0.00cvss 4.5epss 0.00
Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
- risk 0.00cvss —epss 0.00
Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. This issue affects MicroRealEstate: through 1.0.0-alpha3.
- risk 0.00cvss 8.0epss 0.00
ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with administrative privileges can exploit a path traversal vulnerability in the system to execute arbitrary code. Upgrade ownCloud 10 to version 10.15.3 or…
- risk 0.00cvss 6.8epss 0.00
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.