The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
154 vulnerabilities with CWE-35
CVE-2025-39475
HIGH
Frenify Arlo <6.0.3 - Path Traversal
CVSS 8.1
CVE-2025-27445
MEDIUM
RSFirewall 2.9.7-3.1.5 - Path Traversal
CVSS 5.4
CVE-2025-5598
CRITICAL
WF Steuerungstechnik GmbH airleader MASTER <3.0046 - Path Traversal
CVE-2025-46441
MEDIUM
Section Widget <3.3.1 - Path Traversal
CVSS 5.3
CVE-2025-27010
HIGH
bslthemes Tastyc <2.5.2 - Path Traversal
CVSS 8.1
CVE-2025-39492
HIGH
WHMPress <6.2 - Path Traversal
CVSS 7.5
CVE-2025-39491
HIGH
WHMPress <6.2 - Path Traversal
CVSS 8.1
CVE-2025-40573
MEDIUM
Siemens Scalance Lpe9403 Firmware - Path Traversal
CVSS 4.4
CVE-2025-47649
HIGH
ilmosys Open Close WooCommerce Store <4.9.5 - Path Traversal
CVSS 8.8
CVE-2025-47636
HIGH
Fernando Briano <0.91.0 - Path Traversal
CVSS 7.5
CVE-2025-32950
MEDIUM
Haulmont Jmix Framework < 1.6.2 - Path Traversal
CVSS 6.5
CVE-2025-39470
HIGH
ThimPress Ivy School <1.6.0 - Path Traversal
CVSS 8.1
CVE-2025-24908
MEDIUM
Hitachi Vantara Pentaho <10.2.0.2 - Path Traversal
CVSS 6.8
CVE-2025-24907
MEDIUM
Hitachi Vantara Pentaho <10.2.0.2 - Path Traversal
CVSS 6.8
CVE-2025-39598
MEDIUM
Quý Lê 91 Administrator Z <2025.03.28 - Path Traversal
CVSS 4.9
CVE-2025-30966
MEDIUM
NotFound WPJobBoard - Path Traversal
CVSS 5.4
CVE-2025-32585
HIGH
Trusty Plugins Shop Products Filter <1.2 - Path Traversal
CVSS 7.5
CVE-2025-30014
HIGH
SAP Capital Yield Tax Management - Path Traversal
CVSS 7.7
CVE-2025-30834
HIGH
Bit Apps Bit Assist <1.5.4 - Path Traversal
CVSS 7.5
CVE-2025-26940
MEDIUM
NotFound Pie Register Premium <3.8.3.2 - Path Traversal
CVSS 6.3
CVE-2025-27274
MEDIUM
NotFound GPX Viewer <2.2.11 - Path Traversal
CVSS 4.9
CVE-2025-25122
HIGH
WizShop <3.0.2 - Path Traversal
CVSS 8.1
CVE-2025-26935
HIGH
Wpjobportal WP Job Portal < 2.2.8 - Path Traversal
CVSS 7.5
CVE-2025-26876
MEDIUM
Codemanas Search With Typesense < 2.0.9 - Path Traversal
CVSS 6.8
CVE-2025-26357
MEDIUM
Q-free Maxtime < 2.11.0 - Path Traversal
CVSS 4.9
Details
Vulnerabilities
154