CWE-23— Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.— MITRE CWE catalog
523 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-23page 2 of 11
- CVE-2020-7376CRITICALCVSS 7.1EG 9.82020-08-24
The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesys…
- CVE-2023-0745CRITICALCVSS 6.7EG 9.82023-02-09
The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path traversal characters. This vulnerability…
- CVE-2022-29844CRITICALCVSS 6.7EG 9.82023-01-26
A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This could lead to a full NAS compromise and would give remote ex…
- CVE-2022-2139CRITICALCVSS 6.5EG 9.82022-07-22
The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code.
- CVE-2023-1112CRITICALCVSS 4.7EG 9.82023-03-01
A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_na…
- CVE-2024-0550CRITICALCVSS 6.5EG 9.62024-02-28
A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any valid files. The attacker would have to have been granted priv…
- CVE-2026-103663CRITICALCVSS 9.4EG 9.42026-10-08
Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insufficient validation of layer digests by the `digestToPath` function. An unauthenticated remote attacker can specify a path traversal sequence as a layer digest, …
- CVE-2026-41948CRITICALCVSS 9.4EG 9.42026-05-18
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can …
- CVE-2025-47788CRITICALCVSS 9.4EG 9.42025-05-15
Atheos is a self-hosted browser-based cloud IDE. Prior to v602, similar to GHSA-rgjm-6p59-537v/CVE-2025-22152, the `$target` parameter in `/controller.php` was not properly validated, which could allow an attacker to execute arbitrary file…
- CVE-2026-23734CRITICALCVSS 9.3EG 9.32026-05-20
XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki…
- CVE-2026-76454CRITICALCVSS 9.1EG 9.12026-10-07
A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause…
- CVE-2026-8066CRITICALCVSS 9.1EG 9.12026-09-29
A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files a…
- CVE-2026-84939CRITICALCVSS 9.1EG 9.12026-09-10
Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default en…
- CVE-2026-66906CRITICALCVSS 9.1EG 9.12026-08-24
Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-blob compone…
- CVE-2025-41268CRITICALCVSS 9.1EG 9.12026-05-29
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the …
- CVE-2026-41551CRITICALCVSS 9.1EG 9.12026-05-12
A vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a path traversal vulnerability because user input is not properly sanitized. This could allow a remote attacker to access arbitrary files on th…
- CVE-2026-25057CRITICALCVSS 9.1EG 9.12026-02-09
MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, instructors are able to upload a zip file to create an assignment from an exported configuration (courses/<:course_id>/assignments/upload_co…
- CVE-2025-68472CRITICALCVSS 9.1EG 9.12026-01-12
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move th…
- CVE-2025-55747CRITICALCVSS 9.1EG 9.12025-09-03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10.6, configuration files are accessible through the webjars API. This is fixed in version 16.…
- CVE-2025-31493CRITICALCVSS 9.1EG 9.12025-05-13
Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `collection()` helper or `$kirby->collection()` method with a dynamic collection name…
- CVE-2025-30159CRITICALCVSS 9.1EG 9.12025-05-13
Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `snippet()` helper or `$kirby->snippet()` method with a dynamic snippet name (such as…
- CVE-2024-8551CRITICALCVSS 9.1EG 9.12025-03-20
A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read and write arbitrary JSON files on the filesystem, …
- CVE-2024-47051CRITICALCVSS 9.1EG 9.12025-02-26
This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users. * Remote Code Execution (RCE) via Asset Upload: A Remote Code Exec…
- CVE-2025-20059CRITICALCVSS 9.1EG 9.12025-02-20
Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue affects PingAM Java Policy Agent: through 5.10.3, through 2023.11.1, through 2024.9.
- CVE-2021-24035CRITICALCVSS 9.1EG 9.12021-06-11
A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for Android v2.21.8.13 could have allowed path traversal attacks that overwrite WhatsApp files.
- CVE-2020-8570CRITICALCVSS 9.1EG 9.12021-01-21
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potenti…
- CVE-2020-10619CRITICALCVSS 9.1EG 9.12020-04-09
An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
- CVE-2021-32825CRITICALCVSS 2.7EG 9.12021-08-16
bblfshd is an open source self-hosted server for source code parsing. In bblfshd before commit 4265465b9b6fb5663c30ee43806126012066aad4 there is a "zipslip" vulnerability. The unsafe handling of symbolic links in an unpacking routine may e…
- CVE-2022-20755CRITICALCVSS 9.0EG 9.02022-04-06
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the appl…
- CVE-2022-20754CRITICALCVSS 9.0EG 9.02022-04-06
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the appl…
- CVE-2026-101024HIGHCVSS 8.8EG 8.82026-10-08
Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data export functionality. An authenticated user with Viewer privileges could write attacker influenced content to file system locations ac…
- CVE-2026-80130HIGHCVSS 8.8EG 8.82026-09-07
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vu…
- CVE-2026-85199HIGHCVSS 8.8EG 8.82026-09-03
Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiers used to create, update, or delete Self-orchestrator resources were incorporated into filesystem pa…
- CVE-2026-81849HIGHCVSS 8.8EG 8.82026-08-28
Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-Download…
- CVE-2026-53528HIGHCVSS 8.8EG 8.82026-08-21
LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move files that are accessible to the LeafWik…
- CVE-2026-70337HIGHCVSS 8.8EG 8.82026-08-11
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
- CVE-2026-56196HIGHCVSS 8.8EG 8.82026-07-14
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
- CVE-2026-50663HIGHCVSS 8.8EG 8.82026-07-14
Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.
- CVE-2026-44941HIGHCVSS 8.8EG 8.82026-07-02
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.
- CVE-2026-25707HIGHCVSS 8.8EG 8.82026-06-29
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escal…
- CVE-2026-50016HIGHCVSS 8.8EG 8.82026-06-25
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses that alias as a filesystem path when linki…
- CVE-2025-62498HIGHCVSS 8.8EG 8.82025-10-23
A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an attacker who can tamper with a productivity project to execute arbitrary code on the machine wh…
- CVE-2025-55115HIGHCVSS 8.8EG 8.82025-09-16
A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and poten…
- CVE-2025-7619HIGHCVSS 8.8EG 8.82025-07-14
BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability. If a user visits a malicious website while the application is running, remote attackers can write arbitrary files to any path…
- CVE-2025-48817HIGHCVSS 8.8EG 8.82025-07-08
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2025-34510HIGHCVSS 8.8EG 8.82025-06-17
Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10.0 through 10.4 are affected by a Zip Slip vulnerability. A remote, authenticated attacker can exploit this issue by se…
- CVE-2025-32017HIGHCVSS 8.8EG 8.82025-04-08
Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location.…
- CVE-2024-54449HIGHCVSS 8.8EG 8.82025-03-14
The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file with controlled contents to an arbitrary location on the underlying file system. This can b…
- CVE-2025-26645HIGHCVSS 8.8EG 8.82025-03-11
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2025-23011HIGHCVSS 8.8EG 8.82025-01-23
Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated attacker can upload a specially crafted archive that will extract an arbitrary JSP file to a location that can be execute…
Map vulnerabilities like CWE-23 to your infrastructure
EchelonGraph correlates every CVE — across CWE-23 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →