VYPR

CWE-23

Relative Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-139 · CAPEC-76

CVEs mapped to this weakness (525)

page 5 of 27
  • CVE-2017-13996HigOct 5, 2017
    risk 0.57cvss 8.8epss 0.03

    A Relative Path Traversal issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web user interface fails to prevent access to critical files that non administrative users should not have access to, which could allow an attacker to create or modify files or execute…

  • CVE-2023-45858HigSep 14, 2026
    risk 0.56cvss 8.6epss 0.01

    A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.

  • CVE-2026-67367HigSep 8, 2026
    risk 0.56cvss 8.6epss 0.01

    A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT…

  • CVE-2026-8100HigJun 18, 2026
    risk 0.56cvss —epss 0.01

    Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions. This issue is due to improper handling of URL-encoded paths during request processing. In certain scenarios, an authenticated…

  • CVE-2026-29201HigMay 8, 2026
    risk 0.56cvss 8.6epss 0.00

    Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relative file path is passed.

  • CVE-2024-49253HigOct 16, 2024
    risk 0.56cvss 8.6epss 0.01

    Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal.This issue affects Analyse Uploads: from n/a through <= 0.5.

  • CVE-2022-38205HigDec 29, 2022
    risk 0.56cvss 8.6epss 0.02

    In some non-default installations of Esri Portal for ArcGIS versions 10.9.1 and below, a directory traversal issue may allow a remote, unauthenticated attacker to traverse the file system and lead to the disclosure of sensitive data (not customer-published content).

  • CVE-2020-4039HigApr 30, 2021
    risk 0.56cvss 8.6epss 0.01

    SUSI.AI is an intelligent Open Source personal assistant. SUSI.AI Server before version d27ed0f has a directory traversal vulnerability due to insufficient input validation. Any admin config and file readable by the app can be retrieved by the attacker. Furthermore, some files…

  • CVE-2026-16053HigAug 11, 2026
    risk 0.55cvss 8.5epss 0.01

    Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.

  • CVE-2026-23734CriMay 20, 2026
    risk 0.55cvss —epss 0.20

    XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify=false, leading to Path…

  • CVE-2026-41948CriMay 18, 2026
    risk 0.55cvss 9.4epss 0.14

    Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant…

  • CVE-2025-54317HigJul 20, 2025
    risk 0.55cvss 8.4epss 0.01

    An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vulnerability when creating a Layout Template, which can lead to remote code execution (RCE).

  • CVE-2025-33112HigJun 10, 2025
    risk 0.55cvss 8.4epss 0.00

    IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.

  • CVE-2022-23854HigDec 23, 2022
    risk 0.55cvss 7.5epss 0.46

    AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.

  • CVE-2020-7861HigApr 22, 2021
    risk 0.55cvss 8.4epss 0.01

    AnySupport (Remote support solution) before 2019.3.21.0 allows directory traversing because of swprintf function to copy file from a management PC to a client PC. This can be lead to arbitrary file execution.

  • CVE-2025-47788CriMay 15, 2025
    risk 0.54cvss —epss 0.00

    Atheos is a self-hosted browser-based cloud IDE. Prior to v602, similar to GHSA-rgjm-6p59-537v/CVE-2025-22152, the `$target` parameter in `/controller.php` was not properly validated, which could allow an attacker to execute arbitrary files on the server via path traversal. v602…

  • CVE-2026-82768HigSep 14, 2026
    risk 0.53cvss 8.1epss 0.00

    Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.

  • CVE-2026-82765HigSep 14, 2026
    risk 0.53cvss 8.1epss 0.00

    Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.

  • CVE-2026-5966HigApr 20, 2026
    risk 0.53cvss 8.1epss 0.00

    ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system.

  • CVE-2026-4415HigMar 30, 2026
    risk 0.53cvss 8.1epss 0.01

    Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or…