CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,572 vulnerabilities with CWE-22
CVE-2026-26396 HIGH
OpenBMB XAgent <= 1.0.0 - Path Traversal and Sensitive Information Disclosure via filename Parameter in file() Function
CVSS 7.5
CVE-2026-61505 MEDIUM
Rejetto HFS < 3.2.1 Limited File Disclosure via Path Traversal in lang Parameter
CVSS 5.3
CVE-2026-57815 HIGH
WordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerability
CVSS 7.5
CVE-2026-57709 HIGH
WordPress Membership For WooCommerce plugin <= 3.1.0 - Arbitrary File Deletion vulnerability
CVSS 8.6
CVE-2026-57401 CRITICAL
WordPress SureDash plugin <= 1.8.0 - Arbitrary File Deletion vulnerability
CVSS 9.9
CVE-2026-57389 HIGH
WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability
CVSS 8.6
CVE-2026-13014 CRITICAL
Thales CERT Suspicious <= 1.3.4 - Unauthenticated Remote Code Execution
CVE-2026-15527 MEDIUM
better-auth better-icons scan_project_icons/sync_icon path traversal
CVSS 5.3
CVE-2026-15526 LOW
augmnt augments-mcp-server scan_project_deps scan-project-deps.ts scanProjectDeps path traversal
CVSS 3.3
CVE-2026-15524 LOW
alioshr memory-bank-mcp list-project-files-validation-factory.ts path traversal
CVSS 3.3
CVE-2026-15522 MEDIUM
tugcantopaloglu godot-mcp run_project index.js validatePath path traversal
CVSS 5.3
CVE-2026-15521 MEDIUM
makafeli n8n-workflow-builder update_node_from_file server.cjs path traversal
CVSS 5.3
CVE-2026-56260 CRITICAL
Crawl4AI - Arbitrary File Write via output_path Parameter
CVSS 9.1
CVE-2026-61445 CRITICAL
PraisonAI before 4.6.78 Arbitrary File Write and Command Execution
CVSS 9.9
CVE-2026-60088 MEDIUM
PraisonAI before 4.6.78 Path Traversal via Custom Commands
CVSS 5.5
CVE-2026-9282 HIGH
W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter
CVSS 7.5
CVE-2026-11426 MEDIUM
WebFactory UnderConstructionPage PRO <= 5.76 - Authenticated Arbitrary File Read
CVSS 6.5
CVE-2026-55852 HIGH
Frappe: TarSlip RCE in Package Import
CVE-2026-42219 MEDIUM
Frappe: Path Traversal via /backups Route
CVE-2026-41482 HIGH
Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Generator
CVE-2026-58499 HIGH
Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id
CVSS 8.2
CVE-2026-55469 MEDIUM
Snipe-IT: Path traversal vulnerability via CSV import `image` field
CVSS 6.5
CVE-2026-61432 MEDIUM
PraisonAI FastContext before 1.6.78 Path Traversal
CVSS 5.7
CVE-2026-61431 MEDIUM
PraisonAI before 4.6.78 Path Traversal via ContextGatherer
CVSS 5.5
CVE-2026-60089 MEDIUM
PraisonAI before 1.6.78 Path Traversal via config.toml
CVSS 5.5
Details
Vulnerabilities 9,572
Exploit Likelihood High