CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,572 vulnerabilities with CWE-22
CVE-2026-45623
HIGH
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
CVSS 7.5
CVE-2026-66397
HIGH
phpMyFAQ before 4.1.6 Path Traversal via category image deletion
CVE-2026-66476
MEDIUM
WordPress Easy Digital Downloads plugin <= 3.6.9 - Arbitrary File Deletion vulnerability
CVSS 4.9
CVE-2026-66050
HIGH
NitroShare Desktop 0.3.4 Path Traversal via LAN File Transfer Server
CVSS 7.5
CVE-2026-65436
MEDIUM
WordPress Kirki plugin <= 6.0.13 - Arbitrary File Deletion vulnerability
CVSS 6.8
CVE-2026-65878
HIGH
Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1
CVE-2026-17514
MEDIUM
ZJONSSON node-unzipper extract.js Extract path traversal
CVSS 5.3
CVE-2026-40000
LOW
ZTE Blade A75 Pro 5G File Manager - Path Traversal File Read
CVSS 1.8
CVE-2026-65765
MEDIUM
Phoca Commander for Joomla 1.0.0-6.1.1 - Path Traversal
CVE-2026-14955
MEDIUM
Checkout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter
CVSS 6.5
CVE-2026-66007
MEDIUM
Datasets Path Traversal via Unsanitized file_name Metadata
CVSS 6.5
CVE-2026-66004
MEDIUM
ahujasid blender-mcp - BlenderMCP Path Traversal via download_polyhaven_asset API
CVSS 5.3
CVE-2026-15420
MEDIUM
Nexter Blocks <= 5.0.0 - Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion via 'plus_name' Parameter
CVSS 4.3
CVE-2026-16767
MEDIUM
Ne-Lexa php-zip ZIP ZipFile.php extractTo path traversal
CVSS 6.5
CVE-2026-65694
HIGH
Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController
CVSS 7.5
CVE-2026-47669
CRITICAL
DbGate < 7.1.9 archive/unzip - Zip Slip to Remote Code Execution
CVE-2026-15687
LOW
Kubernetes Java Client copyDirectoryFromPod - Path Traversal
CVSS 2.4
CVE-2026-65920
MEDIUM
Diffusers Path Traversal via weight_map Arbitrary File Read
CVSS 4.3
CVE-2026-65919
HIGH
Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload
CVSS 7.5
CVE-2026-65702
HIGH
Vanna 2.0.2 Path Traversal via FileSystemConversationStore
CVSS 8.6
CVE-2026-65701
CRITICAL
SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route
CVSS 9.1
CVE-2026-65700
CRITICAL
h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API
CVSS 9.8
CVE-2026-65698
MEDIUM
Void 1.3.4 Path Traversal via AI Agent File-Reading Tools
CVSS 5.3
CVE-2026-65695
MEDIUM
Office-Word-MCP-Server 1.1.11 Path Traversal via document tools
CVSS 6.8
CVE-2026-65690
HIGH
Bold Reports Standalone Report Designer 14.1.12 Path Traversal RCE via File Upload
CVSS 8.8
Details
Vulnerabilities
9,572
Exploit Likelihood
High