CWE-23
Relative Path Traversal
Description
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-139 · CAPEC-76
CVEs mapped to this weakness (489)
page 7 of 25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-5237 | Hig | 0.51 | 8.8 | 0.04 | Feb 5, 2020 | Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to… | ||
| CVE-2026-55100 | Hig | 0.50 | — | 0.00 | Jul 31, 2026 | hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query strings instead of using… | ||
| CVE-2026-14903 | Hig | 0.50 | 7.7 | 0.01 | Jul 14, 2026 | Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root. | ||
| CVE-2026-25707 | Hig | 0.50 | 8.8 | 0.00 | Jun 29, 2026 | A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation. | ||
| CVE-2025-54531 | Hig | 0.50 | 7.7 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows | ||
| CVE-2025-32017 | Hig | 0.50 | 8.8 | 0.01 | Apr 8, 2025 | Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is… | ||
| CVE-2024-47637 | Hig | 0.50 | 8.8 | 0.01 | Oct 16, 2024 | Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1. | ||
| CVE-2024-0520 | Hig | 0.50 | 8.8 | 0.02 | Jun 6, 2024 | A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS command ('Command Injection') within the `mlflow.data.http_dataset_source.py` module. Specifically, when loading a dataset from a… | ||
| CVE-2024-35186 | Hig | 0.50 | 8.8 | 0.01 | May 23, 2024 | gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files anywhere writable by the application. This vulnerability leads… | ||
| CVE-2022-1661 | Hig | 0.50 | 7.5 | 0.15 | Jun 2, 2022 | The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files. | ||
| CVE-2020-25150 | Hig | 0.50 | 7.6 | 0.02 | Apr 14, 2022 | A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker… | ||
| CVE-2021-43555 | Hig | 0.50 | 7.3 | 0.38 | Nov 19, 2021 | mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or… | ||
| CVE-2019-18338 | Hig | 0.50 | 7.7 | 0.03 | Dec 12, 2019 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains a directory traversal vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. An… | ||
| CVE-2026-18907 | Hig | 0.49 | 7.5 | 0.01 | Aug 5, 2026 | Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename. | ||
| CVE-2026-10073 | Hig | 0.49 | 7.5 | 0.00 | May 29, 2026 | DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to exploit Relative Path Traversal to download arbitrary system files. | ||
| CVE-2025-41271 | Hig | 0.49 | 7.5 | 0.00 | May 29, 2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to read arbitrary files from the device. | ||
| CVE-2026-8361 | Hig | 0.49 | 7.5 | 0.00 | May 27, 2026 | A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome | ||
| CVE-2026-43533 | Hig | 0.49 | 8.6 | 0.00 | May 5, 2026 | OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containing media tags to disclose arbitrary local… | ||
| CVE-2026-30345 | Hig | 0.49 | 7.5 | 0.00 | Mar 18, 2026 | A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitrary files outside the intended directories via supplying a crafted import. | ||
| CVE-2026-27202 | Hig | 0.49 | 7.5 | 0.01 | Feb 21, 2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been fixed at the time of publication. |
- risk 0.51cvss 8.8epss 0.04
Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to…
- risk 0.50cvss —epss 0.00
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query strings instead of using…
- risk 0.50cvss 7.7epss 0.01
Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.
- risk 0.50cvss 8.8epss 0.00
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
- risk 0.50cvss 7.7epss 0.00
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
- risk 0.50cvss 8.8epss 0.01
Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is…
- risk 0.50cvss 8.8epss 0.01
Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.
- risk 0.50cvss 8.8epss 0.02
A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS command ('Command Injection') within the `mlflow.data.http_dataset_source.py` module. Specifically, when loading a dataset from a…
- risk 0.50cvss 8.8epss 0.01
gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files anywhere writable by the application. This vulnerability leads…
- risk 0.50cvss 7.5epss 0.15
The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files.
- risk 0.50cvss 7.6epss 0.02
A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker…
- risk 0.50cvss 7.3epss 0.38
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or…
- risk 0.50cvss 7.7epss 0.03
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains a directory traversal vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. An…
- risk 0.49cvss 7.5epss 0.01
Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.
- risk 0.49cvss 7.5epss 0.00
DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to exploit Relative Path Traversal to download arbitrary system files.
- risk 0.49cvss 7.5epss 0.00
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to read arbitrary files from the device.
- risk 0.49cvss 7.5epss 0.00
A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome
- risk 0.49cvss 8.6epss 0.00
OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containing media tags to disclose arbitrary local…
- risk 0.49cvss 7.5epss 0.00
A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitrary files outside the intended directories via supplying a crafted import.
- risk 0.49cvss 7.5epss 0.01
GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been fixed at the time of publication.