CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,572 vulnerabilities with CWE-22
CVE-2026-65689 CRITICAL
Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via Database Download
CVSS 9.8
CVE-2026-65688 CRITICAL
Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via Font Processing
CVSS 9.8
CVE-2026-65687 CRITICAL
Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via SVG Processing
CVSS 9.8
CVE-2026-65607 MEDIUM
SiYuan before v3.7.2 Path Traversal via /export/temp/
CVSS 6.5
CVE-2026-59555 CRITICAL
WordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion vulnerability
CVSS 10.0
CVE-2026-59542 HIGH
WordPress Kali Forms plugin <= 2.4.18 - Arbitrary File Deletion vulnerability
CVSS 7.7
CVE-2026-57716 MEDIUM
WordPress Broadcast Live Video plugin <= 7.2.4 - Arbitrary File Deletion vulnerability
CVSS 5.3
CVE-2026-57696 HIGH
WordPress Picture Gallery plugin <= 1.6.5 - Arbitrary File Deletion vulnerability
CVSS 7.1
CVE-2026-65754 HIGH
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension
CVSS 7.5
CVE-2026-65713 MEDIUM
Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension
CVSS 6.5
CVE-2026-65712 MEDIUM
Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension
CVSS 6.2
CVE-2026-65431 CRITICAL
Joomla Extension - regularlabs.com - Zipslip in GeoIP extension
CVSS 9.8
CVE-2026-64872 MEDIUM
Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension
CVSS 6.5
CVE-2026-16078 MEDIUM
WCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read via 'type' Parameter
CVSS 6.5
CVE-2026-15786 MEDIUM
WP Encryption <= 7.8.6.6 - Authenticated (Administrator+) Arbitrary File Write via 'imploded' Parameter
CVSS 4.4
CVE-2026-15074 HIGH
@fastify/static vulnerable to route guard bypass via path traversal
CVSS 7.5
CVE-2026-16653 MEDIUM
boazsegev facil.io Public Folder http.c http_sendfile2 path traversal
CVSS 5.3
CVE-2026-14985 HIGH
Analog WAY Picturall Quad Compact Mark II < 3.5.9 - Privilege Escalation
CVSS 7.8
CVE-2026-13186 HIGH
AppDataStorageProvider Path Traversal Deserialization Vulnerability in Telerik UI for ASP.NET AJAX
CVSS 8.1
CVE-2026-65600 HIGH
Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex
CVE-2026-44192 MEDIUM
Ansible-lightspeed: ansible lightspeed mcp server: remote code execution and data exfiltration via path traversal
CVSS 6.6
CVE-2026-56844 HIGH
Veeam Backup And Replication - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-47731 CRITICAL
NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)
CVSS 9.1
CVE-2026-30633 HIGH
knowns 0.11.4 - Path Traversal via get_doc and update_doc Tools
CVSS 7.5
CVE-2026-50757 HIGH
next-ai-draw-io 0.4.13 - Remote Code Execution via Path Traversal in MCP Server
CVSS 7.8
Details
Vulnerabilities 9,572
Exploit Likelihood High