CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,576 vulnerabilities with CWE-22
CVE-2026-54403 HIGH
Ubiquiti INC UniFi OS Server - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 8.6
CVE-2026-9145 MEDIUM
Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value'
CVSS 6.5
CVE-2026-13369 HIGH
Ninja Forms - File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read via File Upload Field 'files[].data.file_path' Parameter
CVSS 7.5
CVE-2026-13251 HIGH
Perfmatters <= 2.6.4 - Unauthenticated Arbitrary File Read via 's' Parameter
CVSS 7.5
CVE-2026-14439 CRITICAL
Altium Git Service - Authenticated Path Traversal to Remote Code Execution
CVE-2026-58451 MEDIUM
Horde IMP < 7.0.1 Path Traversal via Compose.php img src
CVSS 6.5
CVE-2026-49119 HIGH
Gradio < 6.16.0 Path Traversal via FileExplorer.preprocess()
CVSS 7.5
CVE-2026-5051 MEDIUM
Audit Log Plugin Directory Guard Bypass via Legacy path Option
CVSS 4.4
CVE-2026-20191 HIGH
Cisco Catalyst Center Arbitrary File Read Vulnerability
CVSS 7.5
CVE-2026-53906 HIGH
Mycomplianceoffice Mco < 25.3.3.1 - Path Traversal
CVSS 8.2
CVE-2026-56377 LOW
ImageMagick - Policy Bypass via Incorrect Path Validation
CVSS 3.3
CVE-2026-56233 HIGH
Capgo - SSRF and Privilege Escalation via Path Traversal in Builder Upload Proxy
CVSS 8.3
CVE-2026-52868 HIGH
OFFIS DCMTK Toolkit Path Traversal
CVSS 8.2
CVE-2026-50003 CRITICAL
OFFIS DCMTK Toolkit Path Traversal
CVSS 9.8
CVE-2026-11595 MEDIUM
IBM WebSphere Application Server is affected by a Path Traversal vulnerability
CVSS 4.3
CVE-2026-58372 HIGH
SeaweedFS < 4.34 - Cross-Bucket Object Deletion via DeleteObjects Request-Body Keys
CVSS 8.1
CVE-2026-58173 MEDIUM
Vibe-Trading < 0.1.10 - Path Traversal via Persistent Memory Type
CVSS 6.5
CVE-2026-58171 MEDIUM
Vibe-Trading < 0.1.10 - Path Traversal via Swarm Run Identifier
CVSS 4.2
CVE-2026-58170 HIGH
Vibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging Live Trading Mandates
CVSS 8.3
CVE-2026-58166 CRITICAL
OpenBMB ChatDev - Unauthenticated Path Traversal in Upload Handler Allows Arbitrary File Write and Delete
CVSS 9.1
CVE-2026-48314 MEDIUM
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CVSS 6.5
CVE-2026-48313 CRITICAL
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CVSS 9.3
CVE-2026-48282 CRITICAL KEV
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
CVSS 10.0
CVE-2026-58015 MEDIUM
Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive
CVSS 5.9
CVE-2026-57079 MEDIUM
Net::BitTorrent versions through 2.0.1 for Perl write files outside the download directory via path traversal in peer-supplied metadata
CVSS 5.3
Details
Vulnerabilities 9,576
Exploit Likelihood High