The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
169 vulnerabilities with CWE-35
CVE-2025-58380
LOW
Brocade Fabric OS <9.2.1 - Path Traversal
CVSS 2.3
CVE-2025-59099
HIGH
CompactWebServer - Path Traversal
CVE-2025-67914
HIGH
beeteam368 VidMov <= 2.3.8 - Path Traversal
CVSS 7.7
CVE-2025-46256
MEDIUM
SigmaPlugin Advanced Database Cleaner PRO <3.2.10 - Path Traversal
CVSS 6.4
CVE-2025-68428
HIGH
jsPDF < 4.0.0 - Path Traversal via loadFile Method
CVSS 7.5
CVE-2025-28973
MEDIUM
AA-Team Pro Bulk Watermark Plugin <2.0 - Path Traversal
CVSS 6.5
CVE-2025-64676
HIGH
Microsoft Purview - Path Traversal and Remote Code Execution via '.../...//'
CVSS 7.2
CVE-2025-64253
MEDIUM
WordPress.org Health Check & Troubleshooting <2.8 - Path Traversal
CVSS 4.9
CVE-2025-66004
MEDIUM
usbmuxd <3ded00c9985a5108cfc7591a309f9a23d57a8cba - Path Traversal
CVSS 5.7
CVE-2025-41736
HIGH
metz-connect ewio2-m_firmware < 2.2.0 - Path Traversal and Remote Code Execution via Python Script Upload
CVSS 8.8
CVE-2025-5454
MEDIUM
AXIS OS 12.0.0-12.6.17 - Path Traversal via ACAP Configuration File
CVSS 6.4
CVE-2025-58972
HIGH
Barcode Scanner with Inventory & Order Manager <1.10.5 - Path Trave...
CVSS 7.2
CVE-2025-48090
HIGH
Blanka - One Page WordPress Theme < 1.5 - Path Traversal and PHP Local File Inclusion via '.../...//'
CVSS 8.1
CVE-2025-39467
HIGH
Wanderland <= 1.7.1 - Path Traversal and PHP Local File Inclusion
CVSS 8.1
CVE-2025-22288
MEDIUM
WPMU DEV - Your All-in-One WordPress Platform Smush Image Compressi...
CVSS 4.1
CVE-2025-53880
HIGH
SUSE Manager Proxy - Path Traversal and Arbitrary File Write via tftpsync Scripts
CVE-2025-27222
HIGH
TRUfusion Enterprise <= 7.10.4.0 - Path Traversal
CVSS 8.6
CVE-2025-41723
CRITICAL
Sauter modulo 6 and EY-modulo 5 - Unauthenticated Path Traversal via importFile SOAP Method
CVSS 9.8
CVE-2025-8051
MEDIUM
OpenText Flipper 3.1.2 - Path Traversal
CVSS 6.5
CVE-2025-42937
CRITICAL
SAP Print Service - Unauthenticated Path Traversal via Insufficient Path Validation
CVSS 9.8
CVE-2025-43907
MEDIUM
Dell PowerProtect Data Domain Path Traversal via '.../...//'
CVSS 6.5
CVE-2025-20313
MEDIUM
Cisco IOS XE Software 17.3.1-17.3.6 - Path Traversal and Improper Image Integrity Validation
CVSS 6.7
CVE-2025-43886
MEDIUM
Dell PowerProtect Data Manager 19.19-19.20 - Path Traversal via '.../...//'
CVSS 4.4
CVE-2025-48317
HIGH
Stefan Keller WooCommerce Payment Gateway <0.4.9 - Path Traversal
CVSS 7.5
CVE-2025-4956
MEDIUM
AA-Team Pro Bulk Watermark Plugin <2.0 - Path Traversal
CVSS 4.3
Details
Vulnerabilities
169