The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
144 vulnerabilities with CWE-35
CVE-2026-26124
MEDIUM
Microsoft ACI Confidential Containers - Privilege Escalation
CVSS 6.7
CVE-2025-69325
MEDIUM
Primer MyData for Woocommerce <=4.2.8 - Path Traversal
CVSS 5.3
CVE-2026-1763
MEDIUM
GE Vernova Enervista UR Setup <8.6 - Info Disclosure
CVSS 4.6
CVE-2025-58381
LOW
Brocade Fabric OS <9.2.1c2 - Path Traversal
CVSS 2.3
CVE-2025-58380
LOW
Brocade Fabric OS <9.2.1 - Path Traversal
CVSS 2.3
CVE-2025-59099
CompactWebServer - Path Traversal
CVE-2025-67914
HIGH
beeteam368 VidMov <= 2.3.8 - Path Traversal
CVSS 7.5
CVE-2025-46256
MEDIUM
SigmaPlugin Advanced Database Cleaner PRO <3.2.10 - Path Traversal
CVSS 6.4
CVE-2025-68428
HIGH
Parall Jspdf < 4.0.0 - Path Traversal
CVSS 7.5
CVE-2025-28973
MEDIUM
AA-Team Pro Bulk Watermark Plugin <2.0 - Path Traversal
CVSS 6.5
CVE-2025-64676
HIGH
Microsoft Purview - Code Injection
CVSS 7.2
CVE-2025-64253
MEDIUM
WordPress.org Health Check & Troubleshooting <2.8 - Path Traversal
CVSS 4.9
CVE-2025-66004
MEDIUM
usbmuxd <3ded00c9985a5108cfc7591a309f9a23d57a8cba - Path Traversal
CVSS 5.7
CVE-2025-41736
HIGH
Metz-connect Ewio2-m Firmware < 2.2.0 - Path Traversal
CVSS 8.8
CVE-2025-5454
MEDIUM
Axis ACAP - Path Traversal
CVSS 6.4
CVE-2025-58972
HIGH
Barcode Scanner with Inventory & Order Manager <1.10.5 - Path Trave...
CVSS 7.2
CVE-2025-48090
HIGH
CocoBasic Blanka - Path Traversal
CVSS 8.2
CVE-2025-39467
CRITICAL
Qodeinteractive Wanderland < 1.7.2 - Path Traversal
CVSS 9.8
CVE-2025-22288
MEDIUM
WPMU DEV - Your All-in-One WordPress Platform Smush Image Compressi...
CVSS 4.1
CVE-2025-53880
tftpsync - Path Traversal
CVE-2025-27222
HIGH
TRUfusion Enterprise <= 7.10.4.0 - Path Traversal
CVSS 8.6
CVE-2025-41723
CRITICAL
SOAP - Path Traversal
CVSS 9.8
CVE-2025-8051
MEDIUM
Opentext Flipper - Path Traversal
CVSS 6.5
CVE-2025-42937
CRITICAL
SAP Print Service - Path Traversal
CVSS 9.8
CVE-2025-43907
MEDIUM
Dell Data Domain Operating System < 7.10.1.70 - Path Traversal
CVSS 6.5
Details
Vulnerabilities
144