CWE-23— Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.— MITRE CWE catalog
523 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-23page 6 of 11
- CVE-2025-2056HIGHCVSS 7.5EG 7.52025-03-14
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.4.01 via the showFile function. This makes it possible for unauthenticated attackers to re…
- CVE-2025-27610HIGHCVSS 7.5EG 7.52025-03-10
Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack::Static` can serve files under the specified `root:` even if `urls:` are provided, which may expose other files under t…
- CVE-2025-25130HIGHCVSS 7.5EG 7.52025-03-03
Relative Path Traversal vulnerability in Shah Alom Delete Comments By Status delete-comments-by-status allows Path Traversal.This issue affects Delete Comments By Status: from n/a through <= 2.1.1.
- CVE-2024-11310HIGHCVSS 7.5EG 7.52024-11-18
The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
- CVE-2024-11309HIGHCVSS 7.5EG 7.52024-11-18
The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
- CVE-2024-11067HIGHCVSS 7.5EG 7.52024-11-11
The D-Link DSL6740C modem has a Path Traversal Vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files. Additionally, since the device's default password is a combination of the…
- CVE-2024-50453HIGHCVSS 7.5EG 7.52024-10-28
Relative Path Traversal vulnerability in webangon The Pack Elementor addons the-pack-addon allows PHP Local File Inclusion.This issue affects The Pack Elementor addons: from n/a through <= 2.0.9.
- CVE-2024-10200HIGHCVSS 7.5EG 7.52024-10-21
Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to download arbitrary files on the server.
- CVE-2024-9983HIGHCVSS 7.5EG 7.52024-10-15
Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
- CVE-2024-9922HIGHCVSS 7.5EG 7.52024-10-14
The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
- CVE-2024-47769HIGHCVSS 7.5EG 7.52024-10-04
IDURAR is open source ERP CRM accounting invoicing software. The vulnerability exists in the corePublicRouter.js file. Using the reference usage here, it is identified that the public endpoint is accessible to an unauthenticated user. The …
- CVE-2024-38258HIGHCVSS 7.5EG 7.52024-09-10
Windows Remote Desktop Licensing Service Information Disclosure Vulnerability
- CVE-2024-7693HIGHCVSS 7.5EG 7.52024-08-12
Raiden MAILD Remote Management System from Team Johnlong Software has a Relative Path Traversal vulnerability, allowing unauthenticated remote attackers to read arbitrary file on the remote server.
- CVE-2024-6433HIGHCVSS 7.5EG 7.52024-07-10
The application zips all the files in the folder specified by the user, which allows an attacker to read arbitrary files on the system by providing a crafted path. This vulnerability can be exploited by sending a request to the application…
- CVE-2024-5547HIGHCVSS 7.5EG 7.52024-06-27
A directory traversal vulnerability exists in the /api/download-project-pdf endpoint of the stitionai/devika repository, affecting the latest version. The vulnerability arises due to insufficient sanitization of the 'project_name' paramete…
- CVE-2023-3940HIGHCVSS 7.5EG 7.52024-05-21
Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to access any file on the system. This issue affects ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR041ME and possibly ot…
- CVE-2024-0335HIGHCVSS 7.5EG 7.52024-04-03
ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API component which may be used by several Symphony Plus products (e.g., S+ Operations, S+ Engineering and S+ Analyst) This issue affects Symphony P…
- CVE-2023-31036HIGHCVSS 7.5EG 7.52024-01-12
NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --model-control explicit, an attacker may use the model load API to cause a relative path tra…
- CVE-2023-6722HIGHCVSS 7.5EG 7.52023-12-13
A path traversal vulnerability has been detected in Repox, which allows an attacker to read arbitrary files on the running server, resulting in a disclosure of sensitive information. An attacker could access files such as application code …
- CVE-2023-42783HIGHCVSS 7.5EG 7.52023-11-14
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.2 through 8.4.0 and 8.3.2 through 8.3.0 and 8.2.2 allows attacker to read arbitrary files via crafted http requests.
- CVE-2023-46119HIGHCVSS 7.5EG 7.52023-10-25
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server crashes when uploading a file without extension. This vulnerability has been patched in versions 5.5.6 and 6.3.1.
- CVE-2023-3512HIGHCVSS 7.5EG 7.52023-10-04
Relative path traversal vulnerability in Setelsa Security's ConacWin CB, in its 3.8.2.2 version and earlier, the exploitation of which could allow an attacker to perform an arbitrary download of files from the system via the "Download file…
- CVE-2023-4914HIGHCVSS 7.5EG 7.52023-09-12
Relative Path Traversal in GitHub repository cecilapp/cecil prior to 7.47.1.
- CVE-2023-2913HIGHCVSS 7.5EG 7.52023-07-18
An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This feature is disabled by default. When the API is enabled and handling requests, a path traversal…
- CVE-2023-2356HIGHCVSS 7.5EG 7.52023-04-28
Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.
- CVE-2022-38202HIGHCVSS 7.5EG 7.52022-12-28
There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated attacker traverse the file system to access files outside of the intended directory on Arc…
- CVE-2021-38399HIGHCVSS 7.5EG 7.52022-10-28
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow an attacker access to unauthorized files and directories.
- CVE-2022-36081HIGHCVSS 7.5EG 7.52022-09-07
Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, Wikmd is vulnerable to path traversal when accessing `/list/<path:folderpath>` and discloses lists of files located on the server including sensitive data. Version 1.7.…
- CVE-2022-31163HIGHCVSS 7.5EG 7.52022-07-22
TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. Versions prior to 0.36.1, as well as those prior to 1.2.10 when used with the Ruby data source tzinfo-data, are vulnera…
- CVE-2022-1661HIGHCVSS 7.5EG 7.52022-06-02
The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files.
- CVE-2021-32949HIGHCVSS 7.5EG 7.52022-04-01
An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path to another path and traversing the directory, allowing the replacement of an existing file with a malicious file.
- CVE-2021-20040HIGHCVSS 7.5EG 7.52021-12-08
A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
- CVE-2021-29101HIGHCVSS 7.5EG 7.52021-05-05
ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and read arbitrary files on the system.
- CVE-2020-7008HIGHCVSS 7.5EG 7.52020-04-03
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources.
- CVE-2019-13408HIGHCVSS 7.5EG 7.52019-08-29
A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.
- CVE-2018-12473HIGHCVSS 3.1EG 7.52018-10-02
A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause access files not in the current build. On the server itself this is prevented by confining the worker via KVM. Affected …
- CVE-2026-78254HIGHCVSS 7.4EG 7.42026-09-07
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite f…
- CVE-2025-52922HIGHCVSS 7.4EG 7.42025-06-23
Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure via the /api/file_manager/files?base_fold…
- CVE-2026-103278HIGHCVSS 7.3EG 7.32026-10-01
Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff user accounts. Attackers with content publishing privileges can craft malicious pages that, when visi…
- CVE-2026-72677HIGHCVSS 7.3EG 7.32026-08-13
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without re…
- CVE-2026-41046HIGHCVSS 7.3EG 7.32026-06-22
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.
- CVE-2026-7404HIGHCVSS 7.3EG 7.32026-04-29
A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument det…
- CVE-2024-22415HIGHCVSS 7.3EG 7.32024-01-18
jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Server Protocol. Installations of jupyter-lsp running in environments without configured file s…
- CVE-2021-34605HIGHCVSS 7.3EG 7.32022-05-11
A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually …
- CVE-2021-41127HIGHCVSS 7.3EG 7.32021-10-21
Rasa is an open source machine learning framework to automate text-and voice-based conversations. In affected versions a vulnerability exists in the functionality that loads a trained model `tar.gz` file which allows a malicious actor to c…
- CVE-2026-76424HIGHCVSS 7.2EG 7.22026-09-16
A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. This vulnerability is due to insufficient validation in file operations. An attacker cou…
- CVE-2026-61343HIGHCVSS 7.2EG 7.22026-07-09
LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template director…
- CVE-2026-8134HIGHCVSS 7.2EG 7.22026-05-21
Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing …
- CVE-2026-33733HIGHCVSS 7.2EG 7.22026-04-22
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template management endpoints accept attacker-controlled `name` and `scope` values and pass them into template path construction with…
- CVE-2026-25951HIGHCVSS 7.2EG 7.22026-02-09
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path sanitization logic allows an authenticated attacker with administrative privileges to bypass directory traversal protect…
Map vulnerabilities like CWE-23 to your infrastructure
EchelonGraph correlates every CVE — across CWE-23 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →