CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,572 vulnerabilities with CWE-22
CVE-2026-26396
HIGH
OpenBMB XAgent <= 1.0.0 - Path Traversal and Sensitive Information Disclosure via filename Parameter in file() Function
CVSS 7.5
CVE-2026-61505
MEDIUM
Rejetto HFS < 3.2.1 Limited File Disclosure via Path Traversal in lang Parameter
CVSS 5.3
CVE-2026-57815
HIGH
WordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerability
CVSS 7.5
CVE-2026-57709
HIGH
WordPress Membership For WooCommerce plugin <= 3.1.0 - Arbitrary File Deletion vulnerability
CVSS 8.6
CVE-2026-57401
CRITICAL
WordPress SureDash plugin <= 1.8.0 - Arbitrary File Deletion vulnerability
CVSS 9.9
CVE-2026-57389
HIGH
WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability
CVSS 8.6
CVE-2026-13014
CRITICAL
Thales CERT Suspicious <= 1.3.4 - Unauthenticated Remote Code Execution
CVE-2026-15527
MEDIUM
better-auth better-icons scan_project_icons/sync_icon path traversal
CVSS 5.3
CVE-2026-15526
LOW
augmnt augments-mcp-server scan_project_deps scan-project-deps.ts scanProjectDeps path traversal
CVSS 3.3
CVE-2026-15524
LOW
alioshr memory-bank-mcp list-project-files-validation-factory.ts path traversal
CVSS 3.3
CVE-2026-15522
MEDIUM
tugcantopaloglu godot-mcp run_project index.js validatePath path traversal
CVSS 5.3
CVE-2026-15521
MEDIUM
makafeli n8n-workflow-builder update_node_from_file server.cjs path traversal
CVSS 5.3
CVE-2026-56260
CRITICAL
Crawl4AI - Arbitrary File Write via output_path Parameter
CVSS 9.1
CVE-2026-61445
CRITICAL
PraisonAI before 4.6.78 Arbitrary File Write and Command Execution
CVSS 9.9
CVE-2026-60088
MEDIUM
PraisonAI before 4.6.78 Path Traversal via Custom Commands
CVSS 5.5
CVE-2026-9282
HIGH
W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter
CVSS 7.5
CVE-2026-11426
MEDIUM
WebFactory UnderConstructionPage PRO <= 5.76 - Authenticated Arbitrary File Read
CVSS 6.5
CVE-2026-55852
HIGH
Frappe: TarSlip RCE in Package Import
CVE-2026-42219
MEDIUM
Frappe: Path Traversal via /backups Route
CVE-2026-41482
HIGH
Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Generator
CVE-2026-58499
HIGH
Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id
CVSS 8.2
CVE-2026-55469
MEDIUM
Snipe-IT: Path traversal vulnerability via CSV import `image` field
CVSS 6.5
CVE-2026-61432
MEDIUM
PraisonAI FastContext before 1.6.78 Path Traversal
CVSS 5.7
CVE-2026-61431
MEDIUM
PraisonAI before 4.6.78 Path Traversal via ContextGatherer
CVSS 5.5
CVE-2026-60089
MEDIUM
PraisonAI before 1.6.78 Path Traversal via config.toml
CVSS 5.5
Details
Vulnerabilities
9,572
Exploit Likelihood
High