VYPR

CWE-36

Absolute Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

This allows attackers to traverse the file system to access files or directories that are outside of the restricted directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-597

CVEs mapped to this weakness (136)

page 3 of 7
  • CVE-2026-1330HigJan 22, 2026
    risk 0.49cvss 7.5epss 0.01

    MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

  • CVE-2025-15227HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.00

    BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

  • CVE-2025-8912HigAug 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

  • CVE-2024-11978HigNov 29, 2024
    risk 0.49cvss 7.5epss 0.01

    DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

  • CVE-2024-8497HigSep 25, 2024
    risk 0.49cvss 7.5epss 0.01

    Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could allow an attacker obtain administrator credentials.

  • CVE-2024-28806HigJul 29, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Remote unauthenticated attackers can upload files at an arbitrary path.

  • CVE-2024-6250HigJun 27, 2024
    risk 0.49cvss 7.5epss 0.02

    An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The `sanitize_path` function with `allow_absolute_path=True` allows an attacker to access arbitrary files and directories on a Windows…

  • CVE-2021-1297HigFeb 4, 2021
    risk 0.49cvss 7.5epss 0.04

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files that should be…

  • CVE-2021-1296HigFeb 4, 2021
    risk 0.49cvss 7.5epss 0.04

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrite certain files that should be…

  • CVE-2023-32054HigJul 11, 2023
    risk 0.48cvss 7.3epss 0.01

    Volume Shadow Copy Elevation of Privilege Vulnerability

  • CVE-2025-68472HigJan 12, 2026
    risk 0.47cvss 8.1epss 0.20

    MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move them into MindsDB’s storage, exposing…

  • CVE-2025-9518HigSep 4, 2025
    risk 0.47cvss 7.2epss 0.01

    The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on the 'debug_path' parameter in all versions up to, and including, 1.2.22. This makes it possible for authenticated attackers, with Administrator-level access…

  • CVE-2024-48850HigMay 22, 2025
    risk 0.47cvss 7.2epss 0.00

    Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

  • CVE-2023-36786HigOct 10, 2023
    risk 0.47cvss 7.2epss 0.02

    Skype for Business Remote Code Execution Vulnerability

  • CVE-2025-13283HigNov 17, 2025
    risk 0.46cvss 7.1epss 0.00

    TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Copy and Paste vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated…

  • CVE-2025-46822HigMay 21, 2025
    risk 0.46cvss epss 0.04

    OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability…

  • CVE-2024-6854HigMar 20, 2025
    risk 0.46cvss 7.1epss 0.01

    In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an attacker to export a model to any file in the server's file structure, thereby overwriting it. This vulnerability can be exploited to overwrite any file on the…

  • CVE-2024-12644HigDec 16, 2024
    risk 0.46cvss 7.1epss 0.00

    The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use…

  • CVE-2017-7929HigMay 6, 2017
    risk 0.46cvss 7.1epss 0.02

    An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The absolute path traversal vulnerability has been identified, which may allow an attacker to traverse the file system to access restricted files or directories.

  • CVE-2024-45290HigOct 7, 2024
    risk 0.43cvss 7.7epss 0.01

    PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file which links media from external URLs. When opening the XLSX file, PhpSpreadsheet retrieves the image size and type by reading the file…