CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,572 vulnerabilities with CWE-22
CVE-2026-57961 LOW
phpMyFAQ - Authenticated Path Traversal in PDF Export via concatenatePaths Function
CVSS 2.7
CVE-2026-54468 MEDIUM
Dell Unisphere For PowerMax - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 6.5
CVE-2026-40005 CRITICAL
Apache IoTDB: Path Traversal in Pipe File Transfer Receiver
CVSS 9.1
CVE-2026-13347 HIGH
Hide My WP Lite <= 1.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'he_wrapper_js' Parameter
CVSS 7.5
CVE-2026-15331 MEDIUM
zhayujie CowAgent Skill Installation service.py _add_package path traversal
CVSS 5.4
CVE-2026-15326 LOW
halo-dev halo Theme Installation ThemeUtils.java ThemeUtils.unzipThemeTo path traversal
CVSS 3.8
CVE-2026-54760 CRITICAL
Langroid SQLChatAgent < 0.65.1 - PostgreSQL File Read Blocklist Bypass
CVE-2026-50181 HIGH
Langroid: Path traversal in the file tools allows read/write outside configured current directory
CVSS 7.1
CVE-2026-50180 HIGH
Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
CVE-2026-59832 HIGH
SiYuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db
CVSS 7.7
CVE-2026-39245 MEDIUM
decompress < 4.2.2 - Path Traversal and Arbitrary File Write via Flawed Path Containment Check
CVSS 6.2
CVE-2026-59149 MEDIUM
Mockoon: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
CVSS 6.5
CVE-2026-13492 HIGH
UsersWP <= 1.2.65 - Authenticated (Subscriber+) Arbitrary File Deletion via File Upload Field
CVSS 8.8
CVE-2026-59221 HIGH
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
CVSS 7.7
CVE-2026-15204 MEDIUM
TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal
CVSS 5.3
CVE-2026-14372 HIGH
Bit Form <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion via '_old' Parameter
CVSS 7.1
CVE-2026-47826 CRITICAL
blobs.yaml Path Traversal Allows File Writes
CVSS 9.1
CVE-2026-15138 MEDIUM
tumf mcp-text-editor text_editor.py _validate_file_path path traversal
CVSS 6.3
CVE-2026-55878 HIGH
Symfony: Path Traversal in symfony/ux-toolkit Allows Arbitrary File Write and Read via Crafted Recipe Manifest
CVSS 7.8
CVE-2026-44024 CRITICAL
Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
CVSS 9.8
CVE-2026-58192 HIGH
Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-plugin
CVSS 8.6
CVE-2026-54591 HIGH
AsyncSSH: SCP Path Traversal to Arbitrary File Write
CVSS 8.1
CVE-2026-54590 MEDIUM
AsyncSSH AuthorizedKeysFile username substitution bypass through ~ and environment expansion
CVSS 5.9
CVE-2026-59948 HIGH
Composer: Arbitrary file write outside vendor via malicious transitive package name
CVSS 7.0
CVE-2026-59946 MEDIUM
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
CVSS 6.1
Details
Vulnerabilities 9,572
Exploit Likelihood High