CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,572 vulnerabilities with CWE-22
CVE-2026-57961
LOW
phpMyFAQ - Authenticated Path Traversal in PDF Export via concatenatePaths Function
CVSS 2.7
CVE-2026-54468
MEDIUM
Dell Unisphere For PowerMax - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 6.5
CVE-2026-40005
CRITICAL
Apache IoTDB: Path Traversal in Pipe File Transfer Receiver
CVSS 9.1
CVE-2026-13347
HIGH
Hide My WP Lite <= 1.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'he_wrapper_js' Parameter
CVSS 7.5
CVE-2026-15331
MEDIUM
zhayujie CowAgent Skill Installation service.py _add_package path traversal
CVSS 5.4
CVE-2026-15326
LOW
halo-dev halo Theme Installation ThemeUtils.java ThemeUtils.unzipThemeTo path traversal
CVSS 3.8
CVE-2026-54760
CRITICAL
Langroid SQLChatAgent < 0.65.1 - PostgreSQL File Read Blocklist Bypass
CVE-2026-50181
HIGH
Langroid: Path traversal in the file tools allows read/write outside configured current directory
CVSS 7.1
CVE-2026-50180
HIGH
Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
CVE-2026-59832
HIGH
SiYuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db
CVSS 7.7
CVE-2026-39245
MEDIUM
decompress < 4.2.2 - Path Traversal and Arbitrary File Write via Flawed Path Containment Check
CVSS 6.2
CVE-2026-59149
MEDIUM
Mockoon: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
CVSS 6.5
CVE-2026-13492
HIGH
UsersWP <= 1.2.65 - Authenticated (Subscriber+) Arbitrary File Deletion via File Upload Field
CVSS 8.8
CVE-2026-59221
HIGH
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
CVSS 7.7
CVE-2026-15204
MEDIUM
TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal
CVSS 5.3
CVE-2026-14372
HIGH
Bit Form <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion via '_old' Parameter
CVSS 7.1
CVE-2026-47826
CRITICAL
blobs.yaml Path Traversal Allows File Writes
CVSS 9.1
CVE-2026-15138
MEDIUM
tumf mcp-text-editor text_editor.py _validate_file_path path traversal
CVSS 6.3
CVE-2026-55878
HIGH
Symfony: Path Traversal in symfony/ux-toolkit Allows Arbitrary File Write and Read via Crafted Recipe Manifest
CVSS 7.8
CVE-2026-44024
CRITICAL
Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
CVSS 9.8
CVE-2026-58192
HIGH
Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-plugin
CVSS 8.6
CVE-2026-54591
HIGH
AsyncSSH: SCP Path Traversal to Arbitrary File Write
CVSS 8.1
CVE-2026-54590
MEDIUM
AsyncSSH AuthorizedKeysFile username substitution bypass through ~ and environment expansion
CVSS 5.9
CVE-2026-59948
HIGH
Composer: Arbitrary file write outside vendor via malicious transitive package name
CVSS 7.0
CVE-2026-59946
MEDIUM
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
CVSS 6.1
Details
Vulnerabilities
9,572
Exploit Likelihood
High