The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
169 vulnerabilities with CWE-35
CVE-2025-32950
MEDIUM
Jmix Framework 1.0.0-1.6.1 and 2.0.0-2.3.4 - Path Traversal via FileRef Parameter
CVSS 6.5
CVE-2025-39470
HIGH
ThimPress Ivy School <1.6.0 - Path Traversal
CVSS 8.1
CVE-2025-24908
MEDIUM
Hitachi Vantara Pentaho <10.2.0.2 - Path Traversal
CVSS 6.8
CVE-2025-24907
MEDIUM
Hitachi Vantara Pentaho <10.2.0.2 - Path Traversal
CVSS 6.8
CVE-2025-39598
MEDIUM
Quý Lê 91 Administrator Z <2025.03.28 - Path Traversal
CVSS 4.9
CVE-2025-30966
MEDIUM
NotFound WPJobBoard - Path Traversal
CVSS 5.4
CVE-2025-32585
HIGH
Trusty Plugins Shop Products Filter <1.2 - Path Traversal
CVSS 7.5
CVE-2025-30014
HIGH
SAP Capital Yield Tax Management - Path Traversal
CVSS 7.7
CVE-2025-30834
HIGH
Bit Apps Bit Assist <1.5.4 - Path Traversal
CVSS 7.5
CVE-2025-26940
MEDIUM
NotFound Pie Register Premium <3.8.3.2 - Path Traversal
CVSS 6.3
CVE-2025-27274
MEDIUM
NotFound GPX Viewer <2.2.11 - Path Traversal
CVSS 4.9
CVE-2025-25122
HIGH
WizShop <= 3.0.2 - Path Traversal via '.../...//'
CVSS 8.1
CVE-2025-26935
HIGH
WP Job Portal <= 2.2.8 - Path Traversal and Local File Inclusion via Dot-Slash Sequence
CVSS 7.5
CVE-2025-26876
MEDIUM
CodeManas Search with Typesense <= 2.0.8 - Path Traversal via '.../...//'
CVSS 6.8
CVE-2025-26357
MEDIUM
Q-Free MaxTime <= 2.11.0 - Authenticated Path Traversal via Crafted HTTP Requests
CVSS 4.9
CVE-2025-26356
HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated Path Traversal via setActive Endpoint
CVSS 7.2
CVE-2025-26355
MEDIUM
Q-Free MaxTime <= 2.11.0 - Authenticated Path Traversal via Crafted HTTP Requests
CVSS 6.5
CVE-2025-26354
HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated Path Traversal via Database Copy Endpoint
CVSS 7.2
CVE-2025-26353
MEDIUM
Q-Free MaxTime <= 2.11.0 - Authenticated Path Traversal via Crafted HTTP Requests
CVSS 4.9
CVE-2025-26352
MEDIUM
Q-Free MaxTime <= 2.11.0 - Authenticated Path Traversal via Template Deletion Mechanism
CVSS 6.5
CVE-2025-26351
MEDIUM
Q-Free MaxTime <= 2.11.0 - Authenticated Path Traversal via Template Download Mechanism
CVSS 4.9
CVE-2025-24786
CRITICAL
clidey/whodb < 0.45.0 - Unauthenticated Path Traversal via Database File Path
CVSS 10.0
CVE-2025-0858
MEDIUM
Certain Poly Devices - Path Traversal via Firmware Builds up to 8.2.1.0820
CVE-2025-22205
HIGH
Admiror Gallery <4.x - Path Traversal
CVSS 7.5
CVE-2025-24685
HIGH
MORKVA Morkva UA Shipping <1.0.18 - Path Traversal
CVSS 8.1
Details
Vulnerabilities
169