CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,142 vulnerabilities with CWE-22
CVE-2025-41428 MEDIUM
TimeWorks 10.0-10.3 - Unauthenticated Path Traversal
CVSS 5.3
CVE-2025-48387 HIGH
tar-fs <3.0.9, <2.1.3, <1.16.5 - Path Traversal
CVE-2025-27956 HIGH
WebLaudos 24.2 (04) - Path Traversal via id Parameter
CVSS 7.5
CVE-2025-48940 HIGH
MyBB < 1.8.39 - Local File Inclusion via Upgrade Component Parameter
CVSS 7.2
CVE-2025-37095 CRITICAL
HPE StoreOnce System < 4.3.11 - Path Traversal
CVSS 9.8
CVE-2025-37094 MEDIUM
HPE StoreOnce System < 4.3.11 - Path Traversal and Arbitrary File Deletion
CVSS 5.5
CVE-2025-48957 HIGH
AstrBot 3.4.4-3.5.12 - Path Traversal and Information Disclosure via Dashboard Feature
CVSS 7.5
CVE-2025-33004 MEDIUM
IBM Planning Analytics Local <2.1 - Privilege Escalation
CVSS 6.5
CVE-2025-5385 MEDIUM
JeeWMS < 2025-05-04 - Path Traversal via cgformTemplateController.do?doAdd
CVSS 6.3
CVE-2025-5381 LOW
Yifang CMS < 2.0.2 - Path Traversal via Admin Panel File Download
CVSS 2.7
CVE-2025-5380 MEDIUM
XueShengZhuSu <4d3f0ada - Path Traversal
CVSS 6.3
CVE-2025-4857 HIGH
Newsletters <= 4.9.9.9 - Authenticated Local File Inclusion via File Parameter
CVSS 7.2
CVE-2025-47952 CRITICAL
Traefik < 2.11.25 and < 3.4.1 - Path Traversal via URL-Encoded Path Bypass
CVSS 9.1
CVE-2025-5328 MEDIUM
chshcms mccms 2.7 - Path Traversal via Backups.php restore_del Function
CVSS 5.4
CVE-2025-48370 LOW
supabase/auth-js < 2.70.0 - Path Traversal via Invalid UUID Handling
CVE-2025-48744 MEDIUM
SIGB PMB < 8.0.1.2 - Local File Inclusion and Remote Code Execution
CVSS 6.4
CVE-2025-5161 MEDIUM
H3C SecCenter SMP-E1114P02 < 20250513 - Path Traversal via /safeEvent/download filename Parameter
CVSS 4.3
CVE-2025-5160 MEDIUM
H3C SecCenter SMP-E1114P02 < 20250513 - Path Traversal via Download Function Name Parameter
CVSS 4.3
CVE-2025-5159 MEDIUM
H3C SecCenter SMP-E1114P02 < 20250513 - Path Traversal via Download Name Parameter
CVSS 4.3
CVE-2025-5158 MEDIUM
H3C SecCenter SMP-E1114P02 < 20250513 - Path Traversal via downloadSoftware Filename Parameter
CVSS 4.3
CVE-2025-5157 MEDIUM
H3C SecCenter SMP-E1114P02 < 20250513 - Path Traversal via filePath Parameter in fileContent Function
CVSS 4.3
CVE-2025-48273 HIGH
WP Job Portal <2.3.2 - Path Traversal
CVSS 7.5
CVE-2025-47603 HIGH
Belingo belingoGeo <1.12.0 - Path Traversal
CVSS 7.5
CVE-2025-47535 HIGH
Opal Woo Custom Product Variation <1.2.0 - Path Traversal
CVSS 8.6
CVE-2025-47513 MEDIUM
James Laforge Infocob CRM Forms <2.4.0 - Path Traversal
CVSS 4.9
Details
Vulnerabilities 9,142
Exploit Likelihood High