CWE-23

Relative Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

461 vulnerabilities with CWE-23
CVE-2026-32725 HIGH
SciTokens C++: Relative Path Traversal Vulnerability
CVSS 8.3
CVE-2026-31831 HIGH
Tautulli: Unauthenticated Path Traversal in `/newsletter/image/images` endpoint
CVSS 7.5
CVE-2026-4415 HIGH
GIGABYTE|Gigabyte Control Center - Arbitrary File Write
CVSS 8.1
CVE-2026-33206 MEDIUM
Calibre <9.6.0 Markdown Image Handling - Path Traversal
CVSS 6.3
CVE-2026-33494 CRITICAL
Ory Oathkeeper <26.2.0 HTTP Path Traversal - Authorization Bypass
CVSS 10.0
CVE-2026-27625 HIGH
Stirling-PDF Zip Slip: Arbitrary File Write via Path Traversal in Markdown-to-PDF ZIP Extraction
CVSS 8.1
CVE-2026-29101 MEDIUM
SuiteCRM Vulnerable to Directory Traversal to DoS in Modules
CVSS 4.9
CVE-2026-29098 MEDIUM
SuiteCRM has Relative Path Traversal via ModuleBuilder Modules ExportCustom Action
CVSS 4.9
CVE-2026-30345 HIGH
CTFd v3.8.1-18-gdb5a18c4 - Path Traversal
CVSS 7.5
CVE-2026-29778 HIGH
pyLoad 0.5.0b3.dev13-0.5.0b3.dev96 - Path Traversal
CVSS 7.1
CVE-2026-21659 CRITICAL
Frick Controls Quantum HD <=10.22 - RCE
CVSS 9.8
CVE-2026-27117 MEDIUM
bit7z < 4.0.11 - Path Traversal and Arbitrary File Write via Archive Extraction
CVSS 5.5
CVE-2026-27202 HIGH
GetSimple CMS - Arbitrary File Read
CVSS 7.5
CVE-2026-2818 HIGH
Spring Data Geode 2.0.0-2.7.17 and Spring Data Gemfire 1.7.0-2.2.12 - Path Traversal via Import Snapshot
CVSS 8.2
CVE-2026-21620 LOW
Erlang/OTP 17.0-17.0 - Relative Path Traversal in tftp_file Module
CVE-2026-26362 HIGH
Dell Unisphere for PowerMax 10.2 - Path Traversal
CVSS 8.1
CVE-2026-1762 LOW
GE Vernova Enervista <8.6 - File Manipulation
CVSS 2.9
CVE-2026-25951 HIGH
FUXA < 1.2.11 - Authenticated Path Traversal and Remote Code Execution via Nested Traversal Sequences
CVSS 7.2
CVE-2026-25057 CRITICAL
Markus < 2.9.1 - Path Traversal via Assignment Configuration Upload
CVSS 9.1
CVE-2026-25575 HIGH
NavigaTUM < 2026-02-03 - Unauthenticated Path Traversal and Arbitrary File Write via Propose Edits Endpoint
CVSS 7.5
CVE-2026-25121 HIGH
apko 0.14.8-1.1.0 - Path Traversal via dirFS Filesystem Abstraction
CVSS 7.5
CVE-2026-24909 MEDIUM
vltpkg/tar < 1.0.0-rc.10 - Path Traversal during Extraction
CVSS 5.9
CVE-2026-23890 MEDIUM
pnpm < 10.28.1 - Path Traversal via Bin Linking with Scope Normalization Bypass
CVSS 6.5
CVE-2026-23888 MEDIUM
pnpm < 10.28.1 - Path Traversal and Arbitrary File Write via Binary Fetcher
CVSS 6.5
CVE-2026-1022 HIGH
Gotac Statistics Database System < 1.0.3 - Unauthenticated Arbitrary File Read via Relative Path Traversal
CVSS 7.5
Details
Vulnerabilities 461