VYPR

CWE-35

Path Traversal: '.../...//'

VariantIncomplete

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (188)

page 8 of 10
  • CVE-2022-46826MedDec 8, 2022
    risk 0.40cvss 6.2epss 0.00

    In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a path traversal vulnerability.

  • CVE-2023-43802HigOct 18, 2023
    risk 0.39cvss 7.1epss 0.00

    Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload` which handles request with the `filename` parameter. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the…

  • CVE-2025-0858MedFeb 5, 2025
    risk 0.38cvss —epss 0.00

    A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does not properly prevent path traversal and could lead to information disclosure.

  • CVE-2024-7608MedAug 27, 2024
    risk 0.38cvss 5.9epss 0.00

    An authenticated user can access the restricted files from NX, EX, FX, AX, IVX and CMS using path traversal.

  • CVE-2025-66004MedDec 10, 2025
    risk 0.37cvss 5.7epss 0.00

    A Path Traversal vulnerability in usbmuxd allows local users to escalate to the service user.This issue affects usbmuxd: before 3ded00c9985a5108cfc7591a309f9a23d57a8cba.

  • CVE-2024-5481MedJun 7, 2024
    risk 0.37cvss 6.8epss 0.01

    The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.8.23 via the esc_dir function. This makes it possible for authenticated attackers to cut and paste (copy) the contents of…

  • CVE-2024-2654MedApr 9, 2024
    risk 0.37cvss 6.8epss 0.01

    The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup function. This makes it possible for authenticated attackers, with administrator access and above, to read the contents of arbitrary…

  • CVE-2025-27445MedJun 5, 2025
    risk 0.35cvss 5.4epss 0.00

    A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allows authenticated users to read arbitrary files outside the Joomla root directory. The flaw is caused by insufficient sanitization of user-supplied input in file…

  • CVE-2025-32950MedApr 22, 2025
    risk 0.35cvss 6.5epss 0.01

    Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, attackers could manipulate the FileRef parameter to access files on the system where the Jmix application is deployed, provided the…

  • CVE-2025-30966MedApr 15, 2025
    risk 0.35cvss 5.4epss 0.00

    Path Traversal vulnerability in NotFound WPJobBoard allows Path Traversal. This issue affects WPJobBoard: from n/a through n/a.

  • CVE-2024-10857MedNov 26, 2024
    risk 0.35cvss 6.5epss 0.01

    The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9 via the handle_downloads() function due to insufficient file path validation/sanitization. This makes it possible for authenticated…

  • CVE-2021-1132MedNov 18, 2024
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the API subsystem and in the web-management interface of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to access sensitive data. This vulnerability exists because the web-management interface and certain…

  • CVE-2023-5800MedFeb 5, 2024
    risk 0.35cvss 5.4epss 0.01

    Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or…

  • CVE-2026-21092MedSep 9, 2026
    risk 0.34cvss 5.3epss 0.00

    Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.

  • CVE-2025-69325MedFeb 20, 2026
    risk 0.34cvss 5.3epss 0.00

    Path Traversal: '.../...//' vulnerability in primersoftware Primer MyData for Woocommerce primer-mydata allows Path Traversal.This issue affects Primer MyData for Woocommerce: from n/a through <= 4.2.8.

  • CVE-2025-48081MedAug 27, 2025
    risk 0.34cvss 5.3epss 0.00

    Path Traversal: '.../...//' vulnerability in Printeers Printeers Print & Ship allows Path Traversal.This issue affects Printeers Print & Ship: from n/a through 1.17.0.

  • CVE-2025-46441MedMay 19, 2025
    risk 0.34cvss 5.3epss 0.00

    Path Traversal: '.../...//' vulnerability in ctltwp Section Widget section-widget allows Path Traversal.This issue affects Section Widget: from n/a through <= 3.3.1.

  • CVE-2026-32415MedMar 13, 2026
    risk 0.33cvss 5.0epss 0.00

    Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue affects Squeeze: from n/a through <= 1.7.7.

  • CVE-2024-52885MedAug 6, 2025
    risk 0.33cvss 5.0epss 0.00

    The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access…

  • CVE-2023-43801MedOct 18, 2023
    risk 0.33cvss 6.1epss 0.00

    Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way it handles plugin names supplied as user input. A user who has the ability to perform HTTP requests to the localhost interface, or…