CWE-23— Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.— MITRE CWE catalog
523 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-23page 8 of 11
- CVE-2026-47287MEDIUMCVSS 6.5EG 6.52026-06-09
Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
- CVE-2025-48977MEDIUMCVSS 6.5EG 6.52026-05-28
Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can read any file on the server with "cmd=log" command and a log path crafted in a certain way. This issue affects Apache Ignite: from 2.0.0 thr…
- CVE-2026-20081MEDIUMCVSS 6.5EG 6.52026-04-15
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative creden…
- CVE-2026-20078MEDIUMCVSS 6.5EG 6.52026-04-15
Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative creden…
- CVE-2026-27625MEDIUMCVSS 6.5EG 6.52026-03-20
Stirling-PDF is a locally hosted web application that performs various operations on PDF files. In versions prior to 2.5.2, the /api/v1/convert/markdown/pdf endpoint extracts user-supplied ZIP entries without path checks. Any authenticated…
- CVE-2026-29778MEDIUMCVSS 6.5EG 6.52026-03-05
pyLoad is a free and open-source download manager written in Python. From version 0.5.0b3.dev13 to 0.5.0b3.dev96, the edit_package() function implements insufficient sanitization for the pack_folder parameter. The current protection relies…
- CVE-2025-58467MEDIUMCVSS 6.5EG 6.52026-02-11
A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already…
- CVE-2026-23890MEDIUMCVSS 6.5EG 6.52026-01-26
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicious npm packages to create executable shims or symlinks outside of `node_modules/.bin`. Bin names starting with `@` bypa…
- CVE-2026-23888MEDIUMCVSS 6.5EG 6.52026-01-26
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious packages to write files outside the intended extraction directory. The vulnerability has two attack vectors: (1) …
- CVE-2025-13771MEDIUMCVSS 6.5EG 6.52025-11-28
WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.
- CVE-2025-10249MEDIUMCVSS 6.5EG 6.52025-10-09
The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on several functions in all versions up to, and including, 6.7.37. This makes it possible for authen…
- CVE-2025-25048MEDIUMCVSS 6.5EG 6.52025-09-04
IBM Jazz Foundation 7.0.2 through 7.0.2 iFix033, 7.0.3 through 7.0.3 iFix012, and 7.1.0 through 7.1.0 iFix002 could allow an authenticated user to upload files to the system due to improper neutralization of sequences that can resolve to a…
- CVE-2021-4459MEDIUMCVSS 6.5EG 6.52025-08-27
An authorized remote attacker can access files and directories outside the intended web root, potentially exposing sensitive system information of the affected Sunny Boy devices.
- CVE-2025-51052MEDIUMCVSS 6.5EG 6.52025-08-06
A path traversal vulnerability in Vedo Suite 2024.17 allows remote authenticated attackers to read arbitrary filesystem files by exploiting an unsanitized 'file_get_contents()' function call in '/api_vedo/template'.
- CVE-2025-46002MEDIUMCVSS 6.5EG 6.52025-07-18
An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the filemanager.php endpoint.
- CVE-2025-27410MEDIUMCVSS 6.5EG 6.52025-02-28
PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerable to path traversal in the TAR entry's name, allowing an attacker to overwrite any file on the system with their conte…
- CVE-2024-56340MEDIUMCVSS 6.5EG 6.52025-02-28
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.
- CVE-2025-1588MEDIUMCVSS 6.5EG 6.52025-02-23
A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage-nurse.php. The manipulation of the argument profilepic leads to path …
- CVE-2025-0822MEDIUMCVSS 6.5EG 6.52025-02-15
Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the fileID Parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the c…
- CVE-2024-12645MEDIUMCVSS 6.5EG 6.52024-12-16
The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs,…
- CVE-2024-49062MEDIUMCVSS 6.5EG 6.52024-12-12
Microsoft SharePoint Information Disclosure Vulnerability
- CVE-2024-45816MEDIUMCVSS 6.5EG 6.52024-09-17
Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not inte…
- CVE-2024-36362MEDIUMCVSS 6.5EG 6.52024-05-29
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible
- CVE-2024-34712MEDIUMCVSS 6.5EG 6.52024-05-14
Oceanic is a NodeJS library for interfacing with Discord. Prior to version 1.10.4, input to functions such as `Client.rest.channels.removeBan` is not url-encoded, resulting in specially crafted input such as `../../../channels/{id}` being …
- CVE-2024-22096MEDIUMCVSS 6.5EG 6.52024-02-02
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to the filename when using a specific command, allowing them to read arbitrary files from the system.
- CVE-2023-5189MEDIUMCVSS 6.5EG 6.52023-11-14
A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in f…
- CVE-2023-37288MEDIUMCVSS 6.5EG 6.52023-07-10
SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.
- CVE-2022-42474MEDIUMCVSS 6.5EG 6.52023-06-13
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2…
- CVE-2023-20066MEDIUMCVSS 6.5EG 6.52023-03-23
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access resources that are outside the filesystem mountpoint of the web UI. This vulnerability is due …
- CVE-2022-3162MEDIUMCVSS 6.5EG 6.52023-03-01
Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the foll…
- CVE-2022-30300MEDIUMCVSS 6.5EG 6.52023-02-16
A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET …
- CVE-2021-32964MEDIUMCVSS 6.5EG 6.52022-05-24
The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an attacker to read arbitrary files from the file system.
- CVE-2022-20790MEDIUMCVSS 6.5EG 6.52022-04-21
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker t…
- CVE-2021-37196MEDIUMCVSS 6.5EG 6.52022-01-11
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.3 (All versions >= V10.3.3.3 only if web components are us…
- CVE-2021-22870MEDIUMCVSS 6.5EG 6.52021-11-10
A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files. To exploit this vulnerability, an attacker would need permission to create and build a GitH…
- CVE-2021-34594MEDIUMCVSS 6.5EG 6.52021-11-04
TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.0.194 are prone to a relative path traversal that allow administrators to create or delete any files on the system.
- CVE-2021-22674MEDIUMCVSS 6.5EG 6.52021-08-10
The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions p…
- CVE-2021-32954MEDIUMCVSS 6.5EG 6.52021-06-18
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to remotely read arbitrary files on the file system.
- CVE-2019-19287MEDIUMCVSS 6.5EG 6.52020-12-14
A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow attackers to traverse through the file system of the server based by sending specially crafted packets over the network without authentication.
- CVE-2023-23784MEDIUMCVSS 5.7EG 6.52023-02-16
A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to information disclosure via specially crafted web requests.
- CVE-2023-23778MEDIUMCVSS 4.9EG 6.52023-02-16
A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated user to obtain unauthorized access to files and data via specifically cra…
- CVE-2022-20913MEDIUMCVSS 4.9EG 6.52022-07-22
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to insufficient input validation in the web-based management interface of Cisc…
- CVE-2025-66737MEDIUMCVSS 4.3EG 6.52025-12-26
Yealink T21P_E2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbitrary files via a crafted request result read function of the diagnostic component.
- CVE-2019-11822MEDIUMCVSS 4.3EG 6.52019-06-30
Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter.
- CVE-2018-13299MEDIUMCVSS 4.3EG 6.52019-04-01
Relative path traversal vulnerability in Attachment Uploader in Synology Calendar before 2.2.2-0532 allows remote authenticated users to upload arbitrary files via the filename parameter.
- CVE-2025-60020MEDIUMCVSS 6.4EG 6.42025-09-24
nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in packet data.
- CVE-2024-52012MEDIUMCVSS 5.4EG 6.42025-01-27
Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the "configset upload" API. Commonly known as a "zipslip", m…
- CVE-2026-33206MEDIUMCVSS 6.3EG 6.32026-03-27
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar text-based file…
- CVE-2025-44163MEDIUMCVSS 6.3EG 6.32025-06-27
RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary file…
- CVE-2021-22281MEDIUMCVSS 6.3EG 6.32024-02-02
: Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation Studio: from 4.0 through 4.12.
Map vulnerabilities like CWE-23 to your infrastructure
EchelonGraph correlates every CVE — across CWE-23 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →