CWE-23

Relative Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

461 vulnerabilities with CWE-23
CVE-2025-25048 MEDIUM
IBM Jazz Foundation <7.0.2-7.1.0 - Privilege Escalation
CVSS 6.5
CVE-2025-55748 HIGH
XWiki Platform <16.10.6 - Info Disclosure
CVSS 7.5
CVE-2025-55747 CRITICAL
XWiki Platform <16.10.6 - Info Disclosure
CVSS 9.1
CVE-2025-9570 MEDIUM
Sunnet eHRD CTMS - Authenticated Arbitrary File Read via Relative Path Traversal
CVSS 4.9
CVE-2025-55202 MEDIUM
Opencast < 17.7 - Relative Path Traversal in UI Config Module
CVSS 5.3
CVE-2025-9639 HIGH
Ai3 QbiCRMGateway 7.5.1-8.5.02 - Unauthenticated Arbitrary File Read via Relative Path Traversal
CVSS 7.5
CVE-2025-8464 MEDIUM
Contact Form 7 <1.3.9.0 - Path Traversal
CVSS 5.3
CVE-2025-53779 HIGH
Windows Kerberos - Privilege Escalation
CVSS 7.2
CVE-2025-55013 MEDIUM
Assemblyline 4 <4.6.1.dev138 - Path Traversal
CVSS 4.2
CVE-2025-51052 MEDIUM
Vedo Suite <2024.17 - Path Traversal
CVSS 6.5
CVE-2025-53082 MEDIUM
Samsung Data Management Server Firmware 2.0.0-2.3.13.1 - Arbitrary File Deletion via Relative Path Traversal
CVSS 6.1
CVE-2025-54531 HIGH
JetBrains TeamCity < 2025.07 - Path Traversal via Plugin Unpacking on Windows
CVSS 7.7
CVE-2025-54317 HIGH
Logpoint < 7.6.0 - Authenticated Remote Code Execution via Layout Template Path Traversal
CVSS 8.4
CVE-2025-46002 MEDIUM
simogeo filemanager <= 2.5.0 - Directory Traversal via filemanager.php Endpoint
CVSS 6.5
CVE-2025-7619 HIGH
BatchSignCS < 3.318 - Arbitrary File Write via Malicious Website
CVSS 8.8
CVE-2025-48817 HIGH
Remote Desktop Client - Path Traversal
CVSS 8.8
CVE-2025-7146 HIGH
iPublish System - Unauthenticated Arbitrary File Read via Relative Path Traversal
CVSS 7.5
CVE-2025-52207 CRITICAL
MikoPBX <2024.1.114 - Code Injection
CVSS 9.9
CVE-2025-44163 MEDIUM
raspap-webgui < 3.3.6 - Authenticated Directory Traversal and Arbitrary File Write via Entity Parameter
CVSS 6.3
CVE-2025-52922 HIGH
InnoShop <= 0.4.1 - Authenticated Directory Traversal via FileManager API
CVSS 7.4
CVE-2025-34510 HIGH
Sitecore XP CVE-2025-34510 Post-Authentication Remote Code Execution
CVSS 8.8
CVE-2025-33112 HIGH
IBM AIX 7.3 & VIOS 4.1.1 - Code Injection
CVSS 8.4
CVE-2025-3365 CRITICAL
B. Braun Melsungen AG OnlineSuite 3.0 - Path Traversal
CVSS 9.8
CVE-2025-49466 MEDIUM
aerc < 93bec0de8ed5ab3d6b1f01026fe2ef20fa154329 - Path Traversal in Attachment Handling
CVSS 5.8
CVE-2025-48957 HIGH
AstrBot 3.4.4-3.5.12 - Path Traversal and Information Disclosure via Dashboard Feature
CVSS 7.5
Details
Vulnerabilities 461