CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,572 vulnerabilities with CWE-22
CVE-2026-54910 HIGH
FileBrowser Quantum < 1.4.3-beta - Authenticated Path Traversal File Read
CVSS 7.7
CVE-2026-52349 HIGH
MenyooSP < 729aa48 - Local Code Execution via Directory Traversal in File Management
CVSS 7.8
CVE-2026-12701 CRITICAL
Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport
CVSS 9.0
CVE-2026-63739 HIGH
SurrealDB before 3.1.5 Arbitrary File Read via DEFINE ANALYZER
CVSS 7.7
CVE-2026-12898 MEDIUM
All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary Log File Write
CVSS 6.5
CVE-2026-16219 MEDIUM
Croogo CMS Admin File Manager FileManager.php isEditable path traversal
CVSS 6.3
CVE-2026-15631 HIGH
@fastify/http-proxy vulnerable to prefix escape via WebSocket path traversal
CVSS 8.7
CVE-2026-16088 MEDIUM
halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversal
CVSS 4.7
CVE-2026-47871 HIGH
VMware Avi Load Balancer Directory Traversal Vulnerability
CVSS 8.8
CVE-2026-48049 MEDIUM
@hapi/inert: Static-file confinement bypass via sibling-prefix path
CVSS 5.3
CVE-2026-8859 CRITICAL
Path Traversal in APIRequest Component via Content-Disposition Header
CVSS 9.9
CVE-2026-7872 HIGH
IBM Langflow OSS 1.0.0-1.10.0 - File Read and JWT Token Forgery
CVSS 7.5
CVE-2026-7667 HIGH
IBM Langflow OSS 1.0.0-1.10.0 - Content-Disposition File Write
CVSS 8.8
CVE-2026-50163 HIGH
oras-go: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution in `oras-go` tar extraction
CVSS 7.1
CVE-2026-45309 HIGH
AsyncSSH < 2.23.0 - AuthorizedKeysFile Username Path Traversal
CVSS 7.5
CVE-2026-15343 HIGH
GitHub Enterprise Server < 3.22 - Dependabot Path Traversal
CVE-2026-15457 MEDIUM
Themeum Kirki <= 6.0.13 - Authenticated Path Traversal Directory Deletion
CVSS 4.9
CVE-2026-15160 MEDIUM
Ninja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated (Subscriber+) XLS Write via Path Traversal
CVSS 4.3
CVE-2026-62229 HIGH
OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching
CVSS 8.8
CVE-2026-39359 HIGH
Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name
CVSS 7.5
CVE-2026-44177 HIGH
Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup
CVE-2026-44023 HIGH
Docling Core has unsafe remote filename resolution
CVSS 8.6
CVE-2026-55629 HIGH
Whistle: Path traversal
CVE-2026-53535 MEDIUM
Activepieces: Arbitrary file write in git-sync via path traversal and symlinks
CVE-2026-46338 MEDIUM
PyMdown Extensions: Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path
CVSS 4.3
Details
Vulnerabilities 9,572
Exploit Likelihood High