CWE-23— Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.— MITRE CWE catalog
523 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-23page 10 of 11
- CVE-2022-30299MEDIUMCVSS 5.3EG 5.32023-02-16
A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions may allow an authenticated attacker to retrieve specific parts…
- CVE-2022-42892MEDIUMCVSS 5.3EG 5.32022-11-17
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow directory listing in any folder…
- CVE-2019-13944MEDIUMCVSS 5.3EG 5.32019-12-12
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP…
- CVE-2026-63303MEDIUMCVSS 5.1EG 5.12026-07-28
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacke…
- CVE-2026-10720MEDIUMCVSS 5.1EG 5.12026-06-19
Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluster members) or join token can manipulate…
- CVE-2024-32116MEDIUMCVSS 5.1EG 5.12024-11-12
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before …
- CVE-2016-20023MEDIUMCVSS 5.0EG 5.02025-12-05
In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.
- CVE-2012-5972MEDIUMCVSS v2 5.0EG 5.02013-01-17
Directory traversal vulnerability in the web server in SpecView 2.5 build 853 and earlier allows remote attackers to read arbitrary files via a ... (dot dot dot) in a URI.
- CVE-2026-13224MEDIUMCVSS 4.9EG 4.92026-09-29
A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request.
- CVE-2026-87747MEDIUMCVSS 4.9EG 4.92026-09-09
The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files.
- CVE-2026-10074MEDIUMCVSS 4.9EG 4.92026-05-29
DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to exploit Relative Path Traversal to download arbitrary system files.
- CVE-2026-31927MEDIUMCVSS 4.9EG 4.92026-04-17
Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes.
- CVE-2026-29098MEDIUMCVSS 4.9EG 4.92026-03-19
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the `action_exportCustom` function in `modules/ModuleBuilder/controller.php` fails to properly ne…
- CVE-2025-58463MEDIUMCVSS 4.9EG 4.92025-11-07
A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We…
- CVE-2025-53609MEDIUMCVSS 4.9EG 4.92025-09-09
A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying syste…
- CVE-2025-9570MEDIUMCVSS 4.9EG 4.92025-09-01
The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download arbitrary system files.
- CVE-2025-46433MEDIUMCVSS 4.9EG 4.92025-04-25
In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible
- CVE-2025-32137MEDIUMCVSS 4.9EG 4.92025-04-04
Relative Path Traversal vulnerability in Cristián Lávaque s2Member s2member allows Path Traversal.This issue affects s2Member: from n/a through <= 250419.
- CVE-2024-13791MEDIUMCVSS 4.9EG 4.92025-02-14
Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the downloadResponseFile() function. This makes it possible for authenticated attackers, with Administrator-level access and ab…
- CVE-2024-9923MEDIUMCVSS 4.9EG 4.92024-10-14
The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with administrator privileges to move arbitrary system files to the website root directory and access them.
- CVE-2024-47949MEDIUMCVSS 4.9EG 4.92024-10-08
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
- CVE-2024-47948MEDIUMCVSS 4.9EG 4.92024-10-08
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
- CVE-2024-3122MEDIUMCVSS 4.9EG 4.92024-07-01
CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.
- CVE-2024-20352MEDIUMCVSS 4.9EG 4.92024-04-03
A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is du…
- CVE-2024-22398MEDIUMCVSS 4.9EG 4.92024-03-14
An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Security Appliance could allow a remote attacker with administrative privileges to conduct a directory traversal attack and de…
- CVE-2022-2922MEDIUMCVSS 4.9EG 4.92022-09-30
Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.
- CVE-2022-29097MEDIUMCVSS 4.9EG 4.92022-06-24
Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privile…
- CVE-2022-22279MEDIUMCVSS 4.9EG 4.92022-04-13
A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.…
- CVE-2026-47078MEDIUMCVSS 4.8EG 4.82026-07-27
Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory via a crafted zip archive. zip:unzip/1,2 and zip:extract/1,2 validate entry paths using zip:check_dir_l…
- CVE-2024-40588MEDIUMCVSS 4.4EG 4.42025-08-12
Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through 7.6.1, FortiMail 7.4.0…
- CVE-2024-7058MEDIUMCVSS 4.4EG 4.42025-03-20
A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as './'. This can lead to unauthorized access to directories within the persona…
- CVE-2024-6985MEDIUMCVSS 4.4EG 4.42024-10-11
A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnerability allows an attacker to read any folder in the personality_folder on the victim's computer, even though sanitize_p…
- CVE-2026-105275MEDIUMCVSS 4.3EG 4.32026-10-08
Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data import functionality. An authenticated user with Viewer privileges could access file paths outside the intended directory and use obse…
- CVE-2023-40772MEDIUMCVSS 4.3EG 4.32026-09-14
A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.
- CVE-2026-42085MEDIUMCVSS 4.3EG 4.32026-05-04
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that al…
- CVE-2025-46363MEDIUMCVSS 4.3EG 4.32025-10-30
Dell Secure Connect Gateway (SCG) 5.0 Application and Appliance version(s) 5.26.00.00 - 5.30.00.00, contain a Relative Path Traversal vulnerability in the SCG exposed for an internal collection download REST API (if this REST API is enable…
- CVE-2025-2961MEDIUMCVSS 4.3EG 4.32025-03-30
A vulnerability classified as problematic was found in opensolon up to 3.1.0. This vulnerability affects the function render_mav of the file /aa of the component org.noear.solon.core.handle.RenderManager. The manipulation of the argument t…
- CVE-2024-6583MEDIUMCVSS 4.3EG 4.32025-03-20
A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 bucket by manipulating the file path in the upload request.
- CVE-2025-1584MEDIUMCVSS 4.3EG 4.32025-02-23
A vulnerability classified as problematic was found in opensolon Solon up to 3.0.8. This vulnerability affects unknown code of the file solon-projects/solon-web/solon-web-staticfiles/src/main/java/org/noear/solon/web/staticfiles/StaticMapp…
- CVE-2025-0225MEDIUMCVSS 4.3EG 4.32025-01-05
A vulnerability classified as problematic was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is an unknown functionality of the file /setting/ClassFy/exampleDownload.html. The manipu…
- CVE-2024-13130MEDIUMCVSS 4.3EG 4.32025-01-05
A vulnerability was found in Dahua IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z and IPC-HDW1200S up to 20241222. It has been rated as problematic. Affected by this issue is some unknown functionality of the file ../mtd/Config/Sha1Account1 …
- CVE-2024-12897MEDIUMCVSS 4.3EG 4.32024-12-23
A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has been classified as critical. This affects an unknown part of the file ../mtd/Config/Sha1Account1 of the component Web I…
- CVE-2024-12482MEDIUMCVSS 4.3EG 4.32024-12-12
A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been rated as problematic. Affected by this issue is the function backup of the file wetech-cms-master\wetech-basic-common\src\main\java\tech\wetech\basic\util\BackupFileUtil…
- CVE-2024-2318MEDIUMCVSS 4.3EG 4.32024-03-08
A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of the file /pro/common/download of the component Service Port 9999. The manipulation of the …
- CVE-2023-1043MEDIUMCVSS 4.3EG 4.32023-02-26
A vulnerability was found in MuYuCMS 2.2. It has been classified as problematic. Affected is an unknown function of the file /editor/index.php. The manipulation of the argument dir_path leads to relative path traversal. It is possible to l…
- CVE-2022-22245MEDIUMCVSS 4.3EG 4.32022-10-18
A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the device by bypassing validation checks built into Junos OS. The attacker should not be able…
- CVE-2022-20862MEDIUMCVSS 4.3EG 4.32022-07-06
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker t…
- CVE-2021-29488MEDIUMCVSS 4.3EG 4.32021-05-07
SABnzbd is an open source binary newsreader. A vulnerability was discovered in SABnzbd that could trick the `filesystem.renamer()` function into writing downloaded files outside the configured Download Folder via malicious PAR2 files. A pa…
- CVE-2018-12476MEDIUMCVSS 4.3EG 4.32020-01-27
Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the machine of the local user if a malicious ser…
- CVE-2026-106552MEDIUMCVSS 4.2EG 4.22026-10-06
In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation.
Map vulnerabilities like CWE-23 to your infrastructure
EchelonGraph correlates every CVE — across CWE-23 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →