CWE-36

Absolute Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

126 vulnerabilities with CWE-36
CVE-2025-15227 HIGH
bpmflowwebkit < 5.0.5 - Unauthenticated Arbitrary File Read via Absolute Path Traversal
CVSS 7.5
CVE-2025-14848 MEDIUM
Advantech WebAccess/SCADA - Absolute Path Traversal
CVSS 4.3
CVE-2025-67898 MEDIUM
MJML < 4.18.0 - Directory Traversal and Arbitrary File Read via mj-include
CVSS 4.5
CVE-2025-34392 CRITICAL
Barracuda RMM < 2025.1.1 - Absolute Path Traversal and Remote Code Execution via WSDL URL
CVSS 9.8
CVE-2025-14253 MEDIUM
Vitals ESP - Path Traversal
CVSS 4.9
CVE-2025-36357 HIGH
IBM Planning Analytics Local 2.1.0-2.1.14 - Authenticated Absolute Path Traversal
CVSS 8.0
CVE-2025-13283 HIGH
TenderDocTransfer < 0.41.159 - Unauthenticated Arbitrary File Copy and Paste via API
CVSS 7.1
CVE-2025-13282 HIGH
TenderDocTransfer < 0.41.159 - Unauthenticated Arbitrary File Deletion via API
CVSS 8.1
CVE-2025-7846 HIGH
WordPress User Extra Fields <16.7 - Privilege Escalation
CVSS 8.8
CVE-2025-8575 HIGH
LWS Cleaner <2.4.1.3 - Privilege Escalation
CVSS 7.2
CVE-2025-9518 HIGH
Atec Debug <1.2.22 - Privilege Escalation
CVSS 7.2
CVE-2025-9516 MEDIUM
Atec Debug <1.2.22 - Info Disclosure
CVSS 4.9
CVE-2025-9259 MEDIUM
WebITR < 2.1.0.33 - Authenticated Absolute Path Traversal
CVSS 6.5
CVE-2025-9258 MEDIUM
Uniong WebITR < 2.1.0.33 - Authenticated Arbitrary File Read via Absolute Path Traversal
CVSS 6.5
CVE-2025-9257 MEDIUM
Uniong WebITR < 2.1.0.33 - Authenticated Absolute Path Traversal
CVSS 6.5
CVE-2025-9256 MEDIUM
WebITR < 2.1.0.33 - Authenticated Arbitrary File Read via Absolute Path Traversal
CVSS 6.5
CVE-2025-57790 HIGH
Commvault < 11.36.60 - Path Traversal and Remote Code Execution
CVSS 8.8
CVE-2025-8912 HIGH
WellChoose Organization Portal System < IFTOP_P3_2_1_197 - Arbitrary File Read via Path Traversal
CVSS 7.5
CVE-2025-8909 MEDIUM
WellChoose Organization Portal System < IFTOP_P3_2_1_197 - Authenticated Arbitrary File Read via Absolute Path Traversal
CVSS 6.5
CVE-2025-8213 HIGH
NinjaScanner <= 3.2.5 - Authenticated Arbitrary File Deletion
CVSS 7.2
CVE-2025-53079 MEDIUM
Samsung Data Management Server Firmware 2.0.0-2.3.13.1 - Authenticated Absolute Path Traversal
CVSS 4.9
CVE-2025-8009 MEDIUM
Security Ninja - WordPress Security Plugin & Firewall <5.243 - Info...
CVSS 4.9
CVE-2025-53651 MEDIUM
Jenkins HTML Publisher Plugin <425 - Info Disclosure
CVSS 6.3
CVE-2025-53392 MEDIUM
pfSense 2.8.0 - Authenticated Absolute Path Traversal via diag_command.php dlPath Parameter
CVSS 5.0
CVE-2025-6381 HIGH
BeeTeam368 Extensions < 2.3.4 - Authenticated Directory Traversal via handle_remove_temp_file()
CVSS 8.8
Details
Vulnerabilities 126