CWE-36

Absolute Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

117 vulnerabilities with CWE-36
CVE-2026-7217 MEDIUM
Deepractice PromptX Document File index.ts read_pdf absolute path traversal
CVSS 5.3
CVE-2026-35465 HIGH
SecureDrop Client has path injection in read_gzip_header_filename()
CVSS 7.5
CVE-2026-34515 HIGH
AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
CVSS 7.5
CVE-2026-4373 HIGH
JetFormBuilder <= 3.5.6.2 - Unauthenticated Arbitrary File Read via Media Field
CVSS 7.5
CVE-2026-0846 HIGH
nltk 3.9.2 - Path Traversal
CVSS 7.5
CVE-2026-2753 HIGH
Navtor NavBox - Path Traversal
CVSS 7.5
CVE-2026-28414 HIGH
Gradio <6.7 - Path Traversal
CVSS 7.5
CVE-2026-27117 MEDIUM
bit7z <4.0.11 - Path Traversal
CVSS 5.5
CVE-2026-26337 HIGH
Hyland Alfresco - Path Traversal & SSRF
CVSS 8.2
CVE-2026-1330 HIGH
MeetingHub - Path Traversal
CVSS 7.5
CVE-2026-1020 MEDIUM
Gotac Police Statistics Database System - Absolute Path Traversal
CVSS 5.3
CVE-2026-1018 HIGH
Gotac Police Statistics Database System - Absolute Path Traversal
CVSS 7.5
CVE-2026-20834 MEDIUM
Microsoft Windows Shell - Absolute Path Traversal Spoofing via Physical Attack
CVSS 4.6
CVE-2025-68472 HIGH
Mindsdb < 25.11.1 - Path Traversal
CVSS 8.1
CVE-2025-15237 MEDIUM
Quantatw Qoca Aim < 2.7.6 - Absolute Path Traversal
CVSS 4.3
CVE-2025-15236 MEDIUM
Quantatw Qoca Aim < 2.7.6 - Absolute Path Traversal
CVSS 4.3
CVE-2025-15227 HIGH
Welltend Bpmflowwebkit < 5.0.5 - Path Traversal
CVSS 7.5
CVE-2025-14848 MEDIUM
Advantech Webaccess/scada - Absolute Path Traversal
CVSS 4.3
CVE-2025-67898 MEDIUM
NPM Mjml - Absolute Path Traversal
CVSS 4.5
CVE-2025-34392 CRITICAL
Barracuda Rmm < 2025.1.1 - Absolute Path Traversal
CVSS 9.8
CVE-2025-14253 MEDIUM
Vitals ESP - Path Traversal
CVSS 4.9
CVE-2025-36357 HIGH
IBM Planning Analytics Local < 2.1.15 - Absolute Path Traversal
CVSS 8.0
CVE-2025-13283 HIGH
CHT Tenderdoctransfer < 0.41.159 - Absolute Path Traversal
CVSS 7.1
CVE-2025-13282 HIGH
CHT Tenderdoctransfer < 0.41.159 - Absolute Path Traversal
CVSS 8.1
CVE-2025-7846 HIGH
WordPress User Extra Fields <16.7 - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 117