VYPR

CWE-35

Path Traversal: '.../...//'

VariantIncomplete

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (180)

page 6 of 9
  • CVE-2025-20313MedSep 24, 2025
    risk 0.44cvss 6.7epss 0.00

    Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. These…

  • CVE-2025-24908MedApr 16, 2025
    risk 0.44cvss 6.8epss 0.00

    Overview   The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.…

  • CVE-2025-24907MedApr 16, 2025
    risk 0.44cvss 6.8epss 0.00

    Overview   The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.…

  • CVE-2025-26876MedFeb 25, 2025
    risk 0.44cvss 6.8epss 0.01

    Path Traversal: '.../...//' vulnerability in CodeManas Search with Typesense search-with-typesense allows Path Traversal.This issue affects Search with Typesense: from n/a through <= 2.0.8.

  • CVE-2023-41793MedMar 19, 2024
    risk 0.44cvss 6.7epss 0.00

    : Path Traversal vulnerability in Pandora FMS on all allows Path Traversal. This vulnerability allowed changing directories and creating files and downloading them outside the allowed directories. This issue affects Pandora FMS: from 700 through <776.

  • CVE-2024-49770HigNov 1, 2024
    risk 0.43cvss epss 0.01

    `oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. By default `oak` does not allow transferring of hidden files with `Context.send` API. However, prior to version 17.1.3, this can be bypassed by…

  • CVE-2020-5421MedSep 19, 2020
    risk 0.43cvss 6.5epss 0.11

    In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

  • CVE-2026-66695MedAug 6, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.

  • CVE-2026-49112HigJun 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.

  • CVE-2025-46256MedJan 7, 2026
    risk 0.42cvss 6.4epss 0.00

    Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue affects Advanced Database Cleaner PRO: from n/a through 3.2.10.

  • CVE-2025-68428HigJan 5, 2026
    risk 0.42cvss 7.5epss 0.02

    jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsanitized paths to the loadFile method, a user…

  • CVE-2025-28973MedDec 31, 2025
    risk 0.42cvss 6.5epss 0.00

    Path Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress pro-watermark allows Path Traversal.This issue affects Pro Bulk Watermark Plugin for WordPress: from n/a through <= 2.0.

  • CVE-2025-5454MedNov 11, 2025
    risk 0.42cvss 6.4epss 0.00

    An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications,…

  • CVE-2025-8051MedOct 20, 2025
    risk 0.42cvss 6.5epss 0.00

    Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal.  The vulnerability could allow a user to access files hosted on the server. This issue affects Flipper: 3.1.2.

  • CVE-2025-43907MedOct 7, 2025
    risk 0.42cvss 6.5epss 0.00

    Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version 8.3.1.0, LTS2024 release versions 7.13.1.0 through 7.13.1.30, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain a…

  • CVE-2025-53561MedAug 20, 2025
    risk 0.42cvss 6.5epss 0.00

    Path Traversal: '.../...//' vulnerability in miniOrange Prevent files / folders access prevent-file-access allows Path Traversal.This issue affects Prevent files / folders access: from n/a through <= 2.6.0.

  • CVE-2025-26355MedFeb 12, 2025
    risk 0.42cvss 6.5epss 0.01

    A CWE-35 "Path Traversal" in maxtime/api/database/database.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to delete sensitive files via crafted HTTP requests.

  • CVE-2025-26352MedFeb 12, 2025
    risk 0.42cvss 6.5epss 0.01

    A CWE-35 "Path Traversal" in the template deletion mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to delete sensitive files via crafted HTTP requests.

  • CVE-2024-56213MedDec 31, 2024
    risk 0.42cvss 6.5epss 0.01

    Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.7.

  • CVE-2024-54313MedDec 13, 2024
    risk 0.42cvss 6.5epss 0.01

    Path Traversal vulnerability in FULL. FULL Customer allows Path Traversal.This issue affects FULL Customer: from n/a through 3.1.25.