CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,572 vulnerabilities with CWE-22
CVE-2026-45623 HIGH
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
CVSS 7.5
CVE-2026-66397 HIGH
phpMyFAQ before 4.1.6 Path Traversal via category image deletion
CVE-2026-66476 MEDIUM
WordPress Easy Digital Downloads plugin <= 3.6.9 - Arbitrary File Deletion vulnerability
CVSS 4.9
CVE-2026-66050 HIGH
NitroShare Desktop 0.3.4 Path Traversal via LAN File Transfer Server
CVSS 7.5
CVE-2026-65436 MEDIUM
WordPress Kirki plugin <= 6.0.13 - Arbitrary File Deletion vulnerability
CVSS 6.8
CVE-2026-65878 HIGH
Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1
CVE-2026-17514 MEDIUM
ZJONSSON node-unzipper extract.js Extract path traversal
CVSS 5.3
CVE-2026-40000 LOW
ZTE Blade A75 Pro 5G File Manager - Path Traversal File Read
CVSS 1.8
CVE-2026-65765 MEDIUM
Phoca Commander for Joomla 1.0.0-6.1.1 - Path Traversal
CVE-2026-14955 MEDIUM
Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter
CVSS 6.5
CVE-2026-66007 MEDIUM
Datasets Path Traversal via Unsanitized file_name Metadata
CVSS 6.5
CVE-2026-66004 MEDIUM
ahujasid blender-mcp - BlenderMCP Path Traversal via download_polyhaven_asset API
CVSS 5.3
CVE-2026-15420 MEDIUM
Nexter Blocks <= 5.0.0 - Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion via 'plus_name' Parameter
CVSS 4.3
CVE-2026-16767 MEDIUM
Ne-Lexa php-zip ZIP ZipFile.php extractTo path traversal
CVSS 6.5
CVE-2026-65694 HIGH
Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController
CVSS 7.5
CVE-2026-47669 CRITICAL
DbGate < 7.1.9 archive/unzip - Zip Slip to Remote Code Execution
CVE-2026-15687 LOW
Kubernetes Java Client copyDirectoryFromPod - Path Traversal
CVSS 2.4
CVE-2026-65920 MEDIUM
Diffusers Path Traversal via weight_map Arbitrary File Read
CVSS 4.3
CVE-2026-65919 HIGH
Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload
CVSS 7.5
CVE-2026-65702 HIGH
Vanna 2.0.2 Path Traversal via FileSystemConversationStore
CVSS 8.6
CVE-2026-65701 CRITICAL
SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route
CVSS 9.1
CVE-2026-65700 CRITICAL
h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API
CVSS 9.8
CVE-2026-65698 MEDIUM
Void 1.3.4 Path Traversal via AI Agent File-Reading Tools
CVSS 5.3
CVE-2026-65695 MEDIUM
Office-Word-MCP-Server 1.1.11 Path Traversal via document tools
CVSS 6.8
CVE-2026-65690 HIGH
Bold Reports Standalone Report Designer 14.1.12 Path Traversal RCE via File Upload
CVSS 8.8
Details
Vulnerabilities 9,572
Exploit Likelihood High