CWE-552

Files or Directories Accessible to External Parties

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product makes files or directories accessible to unauthorized actors, even though they should not be.

453 vulnerabilities with CWE-552
CVE-2026-40484 CRITICAL
ChurchCRM: Authenticated Remote Code Execution via Unrestricted PHP File Write in Database Restore Function
CVSS 9.1
CVE-2026-33698 CRITICAL
Chamilo LMS affected by unauthenticated RCE in main/install folder
CVSS 9.8
CVE-2026-35446 HIGH
LORIS has a path traversal in FilesDownloadHandler
CVSS 7.7
CVE-2026-35169 HIGH
LORIS has potential cross-site scripting in help_editor module
CVSS 8.7
CVE-2026-34392 HIGH
LORIS has a path traversal in static router
CVSS 7.5
CVE-2026-34361 CRITICAL
HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft
CVSS 9.3
CVE-2026-4900 MEDIUM
code-projects Online Food Ordering System localhost.sql privilege escalation
CVSS 5.3
CVE-2026-4760 HIGH
Potential unauthorized access to files on the Web HMI server host
CVE-2026-4532 MEDIUM
code-projects Simple Food Ordering System Database Backup food.sql file access
CVSS 5.3
CVE-2026-33071 MEDIUM
FileRise: WebDAV upload path bypasses filename validation enforced by regular uploads
CVSS 4.3
CVE-2026-32750 MEDIUM
SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes
CVSS 6.8
CVE-2026-29066 MEDIUM
Tina CMS <2.1.8 - Info Disclosure
CVSS 6.2
CVE-2026-2331 CRITICAL
AppEngine Fileaccess - Info Disclosure
CVSS 9.8
CVE-2026-2330 CRITICAL
CROWN REST Interface - Path Traversal
CVSS 9.4
CVE-2026-24732 MEDIUM
BlueSpice 5.1-5.1.3/5.2-5.2.0 - Auth Bypass
CVE-2026-25231 HIGH
FileRise <3.3.0 - Info Disclosure
CVSS 7.5
CVE-2026-25137 CRITICAL
NixOs Odoo <25.11-26.05 - Info Disclosure
CVSS 9.1
CVE-2025-69428 HIGH
Pro-Bit <1.77.4 - Path Traversal
CVSS 7.5
CVE-2025-7389 HIGH
Unauthorized Arbitrary File Read via RMI in AdminServer Interface
CVE-2025-69875 HIGH
Quickheal Total Security - Privilege Escalation
CVSS 7.8
CVE-2025-37177 MEDIUM
Mobility Conductor - File Deletion
CVSS 6.5
CVE-2025-37168 HIGH
Mobility Conductors <AOS-8 - Privilege Escalation
CVSS 8.2
CVE-2025-69990 CRITICAL
phpgurukul News Portal Project V4.1 - Info Disclosure
CVSS 9.1
CVE-2025-66689 MEDIUM
Zen MCP Server <9.8.2 - Path Traversal
CVSS 6.5
CVE-2025-68719 HIGH
KAYSUS KS-WR3600 <1.0.5.9.1 - Info Disclosure
CVSS 8.8
Details
Vulnerabilities 453