CWE-35— Path Traversal: '.../...//'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.— MITRE CWE catalog
191 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-35page 1 of 4
- CVE-2025-8088CRITICALCVSS 8.8EG 9.0⚠ KEV2025-08-08
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov…
- CVE-2025-24786CRITICALCVSS 10.0EG 10.02025-02-06
WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the directory `/db`, there is no path traversal prevention in place. This allows an unauthenticated attacker to open any Sql…
- CVE-2026-59115CRITICALCVSS 9.9EG 9.92026-08-06
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
- CVE-2026-45661CRITICALCVSS 9.9EG 9.92026-05-29
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated users to write arbitrary files to the filesystem during appli…
- CVE-2025-59793CRITICALCVSS 9.9EG 9.92026-02-17
Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDirectory parameter, wh…
- CVE-2026-82824CRITICALCVSS 9.8EG 9.82026-10-01
Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0.
- CVE-2026-6074CRITICALCVSS 9.8EG 9.82026-04-23
Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debug Logs downloads. An unauthenticated attacker can manipulate the name parameter to read ar…
- CVE-2025-41723CRITICALCVSS 9.8EG 9.82025-10-22
The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the path restriction and upload files to arbitrary locations.
- CVE-2025-42937CRITICALCVSS 9.8EG 9.82025-10-14
SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality int…
- CVE-2025-30515CRITICALCVSS 9.8EG 9.82025-06-09
CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.
- CVE-2024-39171CRITICALCVSS 9.8EG 9.82024-07-09
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.
- CVE-2018-3744CRITICALCVSS 9.8EG 9.82018-05-29
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
- CVE-2025-39467CRITICALCVSS 8.1EG 9.82025-11-06
Path Traversal: '.../...//' vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This issue affects Wanderland: from n/a through <= 1.7.1.
- CVE-2026-52703CRITICALCVSS 9.6EG 9.62026-06-15
Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
- CVE-2025-53417CRITICALCVSS 9.3EG 9.32025-08-05
DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability
- CVE-2024-56045CRITICALCVSS 9.3EG 9.32024-12-31
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.
- CVE-2024-40505CRITICALCVSS 9.3EG 9.32024-07-16
Directory Traversal vulnerability in D-Link DAP-1650 Firmware v.1.03 allows a local attacker to escalate privileges via the hedwig.cgi component.
- CVE-2023-39916CRITICALCVSS 9.3EG 9.32023-09-13
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 as well as 0.14.0 up to and including 0.14.2 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store …
- CVE-2025-5598CRITICALCVSS 9.2EG 9.22025-06-04
Path Traversal vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Retrieve Embedded Sensitive Data.This issue affects airleader MASTER: 3.0046.
- CVE-2026-13716CRITICALCVSS 9.1EG 9.12026-08-11
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
- CVE-2026-7302CRITICALCVSS 9.1EG 9.12026-05-18
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload fi…
- CVE-2020-27130CRITICALCVSS 9.1EG 9.12020-11-17
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests t…
- CVE-2026-40128CRITICALCVSS 9.0EG 9.02026-06-09
SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Proce…
- CVE-2026-42661HIGHCVSS 8.8EG 8.82026-06-15
Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.
- CVE-2026-45495HIGHCVSS 8.8EG 8.82026-05-18
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2026-20034HIGHCVSS 8.8EG 8.82026-05-06
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-…
- CVE-2025-59099HIGHCVSS 8.8EG 8.82026-01-26
The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a path traversal vulnerability, which allows an attacker to directly access files via simple GET requests without prior a…
- CVE-2025-41736HIGHCVSS 8.8EG 8.82025-11-18
A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of the target filename in php resulting in a remote code execution.
- CVE-2025-47649HIGHCVSS 8.8EG 8.82025-05-07
Path Traversal: '.../...//' vulnerability in StackWC Open Close WooCommerce Store woc-open-close allows PHP Local File Inclusion.This issue affects Open Close WooCommerce Store: from n/a through <= 4.9.9.
- CVE-2024-47169HIGHCVSS 8.8EG 8.82024-09-26
Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload arbitrary files to attacker-chosen locations on the server, including JavaS…
- CVE-2023-46690HIGHCVSS 8.8EG 8.82023-11-30
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any location of the filesystem, which could lead to remote code execution.
- CVE-2026-42930HIGHCVSS 8.7EG 8.72026-05-13
When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS)…
- CVE-2025-53880HIGHCVSS 8.7EG 8.72025-10-30
A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent network to write or delete files on the filesystem with the privileges of the unprivileged wwwrun user. Although the end…
- CVE-2025-27222HIGHCVSS 8.6EG 8.62025-10-27
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, the application doesn't properly sanitize the input to this endpoint, ultimately allowing path traversal sequences to be…
- CVE-2024-49249HIGHCVSS 8.6EG 8.62025-01-07
Path Traversal: '.../...//' vulnerability in SMSA Express SMSA Shipping smsa-shipping-official allows Path Traversal.This issue affects SMSA Shipping: from n/a through <= 2.3.
- CVE-2024-21575HIGHCVSS 8.6EG 8.62024-12-12
ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing …
- CVE-2024-52447HIGHCVSS 8.6EG 8.62024-11-20
Path Traversal: '.../...//' vulnerability in corporatezen222 Contact Page With Google Map contact-page-with-google-map allows Path Traversal.This issue affects Contact Page With Google Map: from n/a through <= 1.6.1.
- CVE-2024-56055HIGHCVSS 8.5EG 8.52024-12-18
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
- CVE-2024-56049HIGHCVSS 8.5EG 8.52024-12-18
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
- CVE-2026-25705HIGHCVSS 8.4EG 8.42026-05-13
A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEn…
- CVE-2024-56214HIGHCVSS 8.3EG 8.32024-12-31
Path Traversal: '.../...//' vulnerability in DeluxeThemes Userpro userpro allows Path Traversal.This issue affects Userpro: from n/a through <= 5.1.9.
- CVE-2023-32714HIGHCVSS 8.1EG 8.32023-06-01
In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk ins…
- CVE-2024-11136HIGHCVSS 8.2EG 8.22024-11-14
The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability. Malicious application can supply malicious URI path and delete arbitrary files from user’s external storage.
- CVE-2025-48090HIGHCVSS 8.1EG 8.22025-11-06
Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File Inclusion.This issue affects Blanka - One Page WordPress Theme: from n/a through < 1.5.
- CVE-2026-52707HIGHCVSS 8.1EG 8.12026-06-17
Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.
- CVE-2025-52811HIGHCVSS 8.1EG 8.12025-06-27
Path Traversal: '.../...//' vulnerability in Creanncy Davenport - Versatile Blog and Magazine WordPress Theme davenport allows PHP Local File Inclusion.This issue affects Davenport - Versatile Blog and Magazine WordPress Theme: from n/a th…
- CVE-2025-52810HIGHCVSS 8.1EG 8.12025-06-27
Path Traversal vulnerability in TMRW-studio Katerio - Magazine allows PHP Local File Inclusion. This issue affects Katerio - Magazine: from n/a through 1.5.1.
- CVE-2025-49297HIGHCVSS 8.1EG 8.12025-06-09
Path Traversal: '.../...//' vulnerability in Mikado-Themes Grill and Chow grillandchow allows PHP Local File Inclusion.This issue affects Grill and Chow: from n/a through <= 1.6.
- CVE-2025-49296HIGHCVSS 8.1EG 8.12025-06-09
Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issue affects GrandPrix: from n/a through <= 1.6.
- CVE-2025-49295HIGHCVSS 8.1EG 8.12025-06-09
Path Traversal: '.../...//' vulnerability in Mikado-Themes MediClinic mediclinic allows PHP Local File Inclusion.This issue affects MediClinic: from n/a through <= 2.1.
Map vulnerabilities like CWE-35 to your infrastructure
EchelonGraph correlates every CVE — across CWE-35 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →