CWE-35

Path Traversal: '.../...//'

Parent: CWE-23 - Relative Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

154 vulnerabilities with CWE-35
CVE-2025-26356 HIGH
Q-free Maxtime < 2.11.0 - Path Traversal
CVSS 7.2
CVE-2025-26355 MEDIUM
Q-free Maxtime < 2.11.0 - Path Traversal
CVSS 6.5
CVE-2025-26354 HIGH
Q-free Maxtime < 2.11.0 - Path Traversal
CVSS 7.2
CVE-2025-26353 MEDIUM
Q-free Maxtime < 2.11.0 - Path Traversal
CVSS 4.9
CVE-2025-26352 MEDIUM
Q-free Maxtime < 2.11.0 - Path Traversal
CVSS 6.5
CVE-2025-26351 MEDIUM
Q-free Maxtime < 2.11.0 - Path Traversal
CVSS 4.9
CVE-2025-24786 CRITICAL
Clidey Whodb < 0.45.0 - Path Traversal
CVSS 10.0
CVE-2025-0858 MEDIUM
Poly <8.2.1.0820 - Info Disclosure
CVE-2025-22205 HIGH
Admiror Gallery <4.x - Path Traversal
CVSS 7.5
CVE-2025-24685 HIGH
MORKVA Morkva UA Shipping <1.0.18 - Path Traversal
CVSS 8.1
CVE-2025-22786 HIGH
Elementinvader Addons For Elementor < 1.2.7 - Path Traversal
CVSS 7.5
CVE-2024-52885 MEDIUM
Checkpoint Mobile Access - Path Traversal
CVSS 5.0
CVE-2024-54362 HIGH
NotFound GetShop <1.3 - Path Traversal
CVSS 8.1
CVE-2024-49249 HIGH
SMSA Shipping <2.3 - Path Traversal
CVSS 8.6
CVE-2024-56045 CRITICAL
Vibethemes Wordpress Learning Management System - Path Traversal
CVSS 9.3
CVE-2024-56214 HIGH
DeluxeThemes Userpro <5.1.9 - Path Traversal
CVSS 8.3
CVE-2024-56213 MEDIUM
Themewinter Eventin < 4.0.9 - Path Traversal
CVSS 6.5
CVE-2024-56055 HIGH
Vibethemes Wordpress Learning Management System - Path Traversal
CVSS 8.5
CVE-2024-56049 HIGH
Vibethemes Wordpress Learning Management System - Path Traversal
CVSS 8.5
CVE-2024-54313 MEDIUM
FULL <3.1.25 - Path Traversal
CVSS 6.5
CVE-2024-21575 HIGH
ComfyUI-Impact-Pack - Path Traversal
CVSS 8.6
CVE-2024-54216 HIGH
Repute InfoSystems ARForms <6.4.1 - Path Traversal
CVSS 7.7
CVE-2024-52498 HIGH
Softpulse Infotech SP Blog Designer - Path Traversal
CVSS 7.5
CVE-2024-10857 MEDIUM
Tychesoftwares Product Input Fields For Woocommerce - Path Traversal
CVSS 6.5
CVE-2024-50054 HIGH
mySCADA myPRO Manager and Runtime - Path Traversal
CVSS 7.5
Details
Vulnerabilities 154