The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
154 vulnerabilities with CWE-35
CVE-2025-26356
HIGH
Q-free Maxtime < 2.11.0 - Path Traversal
CVSS 7.2
CVE-2025-26355
MEDIUM
Q-free Maxtime < 2.11.0 - Path Traversal
CVSS 6.5
CVE-2025-26354
HIGH
Q-free Maxtime < 2.11.0 - Path Traversal
CVSS 7.2
CVE-2025-26353
MEDIUM
Q-free Maxtime < 2.11.0 - Path Traversal
CVSS 4.9
CVE-2025-26352
MEDIUM
Q-free Maxtime < 2.11.0 - Path Traversal
CVSS 6.5
CVE-2025-26351
MEDIUM
Q-free Maxtime < 2.11.0 - Path Traversal
CVSS 4.9
CVE-2025-24786
CRITICAL
Clidey Whodb < 0.45.0 - Path Traversal
CVSS 10.0
CVE-2025-0858
MEDIUM
Poly <8.2.1.0820 - Info Disclosure
CVE-2025-22205
HIGH
Admiror Gallery <4.x - Path Traversal
CVSS 7.5
CVE-2025-24685
HIGH
MORKVA Morkva UA Shipping <1.0.18 - Path Traversal
CVSS 8.1
CVE-2025-22786
HIGH
Elementinvader Addons For Elementor < 1.2.7 - Path Traversal
CVSS 7.5
CVE-2024-52885
MEDIUM
Checkpoint Mobile Access - Path Traversal
CVSS 5.0
CVE-2024-54362
HIGH
NotFound GetShop <1.3 - Path Traversal
CVSS 8.1
CVE-2024-49249
HIGH
SMSA Shipping <2.3 - Path Traversal
CVSS 8.6
CVE-2024-56045
CRITICAL
Vibethemes Wordpress Learning Management System - Path Traversal
CVSS 9.3
CVE-2024-56214
HIGH
DeluxeThemes Userpro <5.1.9 - Path Traversal
CVSS 8.3
CVE-2024-56213
MEDIUM
Themewinter Eventin < 4.0.9 - Path Traversal
CVSS 6.5
CVE-2024-56055
HIGH
Vibethemes Wordpress Learning Management System - Path Traversal
CVSS 8.5
CVE-2024-56049
HIGH
Vibethemes Wordpress Learning Management System - Path Traversal
CVSS 8.5
CVE-2024-54313
MEDIUM
FULL <3.1.25 - Path Traversal
CVSS 6.5
CVE-2024-21575
HIGH
ComfyUI-Impact-Pack - Path Traversal
CVSS 8.6
CVE-2024-54216
HIGH
Repute InfoSystems ARForms <6.4.1 - Path Traversal
CVSS 7.7
CVE-2024-52498
HIGH
Softpulse Infotech SP Blog Designer - Path Traversal
CVSS 7.5
CVE-2024-10857
MEDIUM
Tychesoftwares Product Input Fields For Woocommerce - Path Traversal
CVSS 6.5
CVE-2024-50054
HIGH
mySCADA myPRO Manager and Runtime - Path Traversal
CVSS 7.5
Details
Vulnerabilities
154