CWE-23

Relative Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

461 vulnerabilities with CWE-23
CVE-2026-6540 HIGH
Tigera Calico - L7 Policy Bypass via Unnormalized HTTP Path Matching
CVE-2026-18192 MEDIUM
Vacron|IP Camera - Arbitrary File Read
CVSS 6.5
CVE-2026-63303 MEDIUM
Path Traversal in Quick.CMS
CVE-2026-47078 MEDIUM
Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass
CVE-2026-15802 HIGH
WP Foodbakery <= 4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via via delete_locations_backup_file AJAX Action
CVSS 8.1
CVE-2026-58481 MEDIUM
Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
CVSS 6.5
CVE-2026-58413 MEDIUM
EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
CVSS 6.1
CVE-2026-51026 MEDIUM
FileThingie 2.5.7 - Unauthenticated Path Traversal and Information Disclosure via Crafted Request
CVSS 6.5
CVE-2026-54910 HIGH
FileBrowser Quantum < 1.4.3-beta - Authenticated Path Traversal File Read
CVSS 7.7
CVE-2026-15415 MEDIUM
Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-server
CVSS 5.5
CVE-2026-62843 MEDIUM
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
CVSS 6.8
CVE-2026-56196 HIGH
Windows Admin Center (WAC) Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-50454 HIGH
Microsoft Windows 11 Version 24H2 - Windows User Interface Core Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-50426 MEDIUM
Microsoft Windows 10 Version 1607 - Windows DNS Server Remote Code Execution Vulnerability
CVSS 6.8
CVE-2026-50663 HIGH
Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-40400 HIGH
Microsoft Windows 10 Version 1607 - Windows PowerShell Remote Code Execution Vulnerability
CVSS 8.0
CVE-2026-14903 HIGH
Ivanti Xtraction - Relative Path Traversal
CVSS 7.7
CVE-2026-55474 MEDIUM
Snipe-IT: Directory traversal in displaySig
CVSS 6.5
CVE-2026-59792 CRITICAL
JetBrains IntelliJ IDEA - Workspace ID Path Traversal Code Execution
CVSS 9.6
CVE-2026-50181 HIGH
Langroid: Path traversal in the file tools allows read/write outside configured current directory
CVSS 7.1
CVE-2026-59832 HIGH
SiYuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db
CVSS 7.7
CVE-2026-59149 MEDIUM
Mockoon: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
CVSS 6.5
CVE-2026-61343 HIGH
LibreBooking path traversal
CVSS 7.2
CVE-2026-8650 MEDIUM
Authenticated Path Traversal allows MOVEit admins to view arbitrary system files
CVSS 4.5
CVE-2026-59996 MEDIUM
Openbsd OpenSSH < 10.4 - Relative Path Traversal
CVSS 4.2
Details
Vulnerabilities 461