VYPR

CWE-35

Path Traversal: '.../...//'

VariantIncomplete

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (180)

page 4 of 9
  • CVE-2020-26073HigNov 18, 2024
    risk 0.50cvss 7.5epss 0.12

    A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within…

  • CVE-2024-36991HigJul 1, 2024
    risk 0.50cvss 7.5epss 0.13

    In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.

  • CVE-2026-69109HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the…

  • CVE-2026-25397HigMar 25, 2026
    risk 0.49cvss 7.5epss 0.00

    Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce allows Path Traversal.This issue affects File Uploader for WooCommerce: from n/a through <= 1.0.4.

  • CVE-2025-48317HigSep 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Path Traversal: '.../...//' vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay woocommerce-payment-gateway-for-saferpay allows Path Traversal.This issue affects WooCommerce Payment Gateway for Saferpay: from n/a through <= 0.4.9.

  • CVE-2025-52805HigJul 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Path Traversal: '.../...//' vulnerability in VaultDweller Leyka leyka allows PHP Local File Inclusion.This issue affects Leyka: from n/a through <= 3.32.1.

  • CVE-2025-49451HigJun 17, 2025
    risk 0.49cvss 7.5epss 0.00

    Path Traversal: '.../...//' vulnerability in yannisraft Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo Gallery aeroscroll-gallery allows Path Traversal.This issue affects Aeroscroll Gallery – Infinite Scroll Image Gallery & Post Grid with Photo…

  • CVE-2025-39492HigMay 16, 2025
    risk 0.49cvss 7.5epss 0.00

    Path Traversal vulnerability in WHMPress WHMpress allows Relative Path Traversal. This issue affects WHMpress: from 6.2 through revision.

  • CVE-2025-47636HigMay 7, 2025
    risk 0.49cvss 7.5epss 0.01

    Path Traversal: '.../...//' vulnerability in Fernando Briano List category posts list-category-posts allows PHP Local File Inclusion.This issue affects List category posts: from n/a through <= 0.91.0.

  • CVE-2025-32585HigApr 11, 2025
    risk 0.49cvss 7.5epss 0.01

    Path Traversal: '.../...//' vulnerability in Trusty Plugins Shop Products Filter trusty-woo-products-filter allows PHP Local File Inclusion.This issue affects Shop Products Filter: from n/a through <= 1.2.

  • CVE-2025-30834HigApr 1, 2025
    risk 0.49cvss 7.5epss 0.01

    Path Traversal: '.../...//' vulnerability in Bit Apps Bit Assist bit-assist allows Path Traversal.This issue affects Bit Assist: from n/a through <= 1.5.4.

  • CVE-2025-26935HigFeb 25, 2025
    risk 0.49cvss 7.5epss 0.01

    Path Traversal: '.../...//' vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local File Inclusion.This issue affects WP Job Portal: from n/a through <= 2.2.8.

  • CVE-2025-22786HigJan 15, 2025
    risk 0.49cvss 7.5epss 0.01

    Path Traversal: '.../...//' vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows PHP Local File Inclusion.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.2.6.

  • CVE-2024-21575HigDec 12, 2024
    risk 0.49cvss 8.6epss 0.01

    ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing arbitrary files to the file system which…

  • CVE-2024-52498HigNov 28, 2024
    risk 0.49cvss 7.5epss 0.01

    Path Traversal: '.../...//' vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows PHP Local File Inclusion.This issue affects SP Blog Designer: from n/a through <= 1.0.0.

  • CVE-2024-50054HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.

  • CVE-2024-51582HigNov 4, 2024
    risk 0.49cvss 7.5epss 0.01

    Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9.

  • CVE-2024-45248HigOct 6, 2024
    risk 0.49cvss 7.5epss 0.01

    Multi-DNC – CWE-35: Path Traversal: '.../...//'

  • CVE-2024-47324HigOct 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Path Traversal: '.../...//' vulnerability in Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin wp-timelines.This issue affects WP Timeline – Vertical and Horizontal timeline plugin: from n/a through <= 3.6.7.

  • CVE-2024-0113HigAug 12, 2024
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information…