VYPR

CWE-36

Absolute Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

This allows attackers to traverse the file system to access files or directories that are outside of the restricted directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-597

CVEs mapped to this weakness (146)

page 6 of 8
  • CVE-2025-8213HigJul 31, 2025
    risk 0.40cvss 7.2epss 0.01

    The NinjaScanner – Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'nscan_ajax_quarantine' and 'nscan_quarantine_select' functions in all versions up to, and including, 3.2.5. This makes it…

  • CVE-2025-4799HigJun 11, 2025
    risk 0.40cvss 7.2epss 0.01

    The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it possible for authenticated attackers, with Administrator-level…

  • CVE-2024-13945MedMay 23, 2025
    risk 0.39cvss 6.0epss 0.00

    Stored Absolute Path Traversal vulnerabilities in ASPECT could expose sensitive data if administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.

  • CVE-2026-47630MedAug 18, 2026
    risk 0.36cvss 5.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution.

  • CVE-2023-5022MedSep 17, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepath leads to absolute path traversal. The…

  • CVE-2021-34711MedOct 6, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any file on the device file system. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by providing crafted…

  • CVE-2026-13346MedJul 29, 2026
    risk 0.35cvss 6.5epss 0.00

    pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a malicious package index to succeed,…

  • CVE-2026-57211MedJul 10, 2026
    risk 0.35cvss 6.5epss 0.01

    RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management…

  • CVE-2026-53698MedJun 10, 2026
    risk 0.35cvss 6.5epss 0.00

    Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.

  • CVE-2024-10047MedMar 20, 2025
    risk 0.35cvss 5.3epss 0.01

    parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on a Windows system by sending a specially crafted HTTP request to the /open_file endpoint.

  • CVE-2026-10075MedMay 29, 2026
    risk 0.34cvss 5.3epss 0.00

    DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path Traversal vulnerability.

  • CVE-2026-7217MedApr 28, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read_docx/read_xlsx/read_pptx/list_xlsx_sheets/read_pdf of the file packages/mcp-office/src/index.ts of the component Document File Handler. Such manipulation of…

  • CVE-2024-6097MedFeb 12, 2025
    risk 0.34cvss 5.3epss 0.01

    In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.

  • CVE-2024-45291MedOct 7, 2024
    risk 0.34cvss 6.3epss 0.01

    PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images from arbitrary paths. When embedding images has been enabled in HTML writer with `$writer->setEmbedImages(true);` those files…

  • CVE-2023-5390MedJan 31, 2024
    risk 0.34cvss 5.3epss 0.01

    An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC. This exploit could be used to read files from the controller that may expose limited information from the device.…

  • CVE-2023-5115MedDec 18, 2023
    risk 0.34cvss 6.3epss 0.01

    An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.

  • CVE-2025-53392MedJun 28, 2025
    risk 0.33cvss 5.0epss 0.02

    In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators…

  • CVE-2026-6418MedMay 5, 2026
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application allows administrative users to configure a source path for account data synchronization. Due to a lack of proper path validation and sanitization, an…

  • CVE-2025-14253MedDec 8, 2025
    risk 0.32cvss 4.9epss 0.00

    Vitals ESP developed by Galaxy Software Services has an Arbitrary File Read vulnerability, allowing privileged remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

  • CVE-2025-9516MedSep 4, 2025
    risk 0.32cvss 4.9epss 0.00

    The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to view the contents of files…