CWE-35— Path Traversal: '.../...//'
70 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-35page 2 of 2
- CVE-2024-49258MEDIUMCVSS 6.5EG 6.52024-10-16
Path Traversal: '.../...//' vulnerability in Limbcode WordPress Gallery Plugin – Limb Image Gallery limb-gallery.This issue affects WordPress Gallery Plugin – Limb Image Gallery: from n/a through <= 1.5.7.
- CVE-2024-49770HIGHCVSS 7.7EG 7.52024-11-01
`oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. By default `oak` does not allow transferring of hidden files with `Context.send` API. However, prior to version…
- CVE-2024-50054HIGHCVSS 7.5EG 7.52024-11-22
The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.
- CVE-2024-51582HIGHCVSS 7.5EG 7.52024-11-04
Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9.
- CVE-2024-52390MEDIUMCVSS 4.9EG 4.92024-11-18
Path Traversal: '.../...//' vulnerability in Greg Ross CYAN Backup cyan-backup allows Path Traversal.This issue affects CYAN Backup: from n/a through <= 2.5.3.
- CVE-2024-52447HIGHCVSS 8.6EG 8.62024-11-20
Path Traversal: '.../...//' vulnerability in corporatezen222 Contact Page With Google Map contact-page-with-google-map allows Path Traversal.This issue affects Contact Page With Google Map: from n/a through <= 1.6.1.
- CVE-2024-52498HIGHCVSS 7.5EG 7.52024-11-28
Path Traversal: '.../...//' vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows PHP Local File Inclusion.This issue affects SP Blog Designer: from n/a through <= 1.0.0.
- CVE-2024-54216HIGHCVSS 7.7EG 7.72024-12-06
Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms arforms allows Path Traversal.This issue affects ARForms: from n/a through <= 6.4.1.
- CVE-2024-54313MEDIUMCVSS 6.5EG 6.52024-12-13
Path Traversal vulnerability in FULL. FULL Customer allows Path Traversal.This issue affects FULL Customer: from n/a through 3.1.25.
- CVE-2024-5481MEDIUMCVSS 6.8EG 6.82024-06-07
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.8.23 via the esc_dir function. This makes it possible for authenticated attackers to …
- CVE-2024-56045CRITICALCVSS 9.3EG 9.32024-12-31
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.
- CVE-2024-56049HIGHCVSS 8.5EG 8.52024-12-18
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
- CVE-2024-56055HIGHCVSS 8.5EG 8.52024-12-18
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
- CVE-2024-56213MEDIUMCVSS 6.5EG 6.52024-12-31
Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.7.
- CVE-2024-56214HIGHCVSS 8.3EG 8.32024-12-31
Path Traversal: '.../...//' vulnerability in DeluxeThemes Userpro userpro allows Path Traversal.This issue affects Userpro: from n/a through <= 5.1.9.
- CVE-2024-7608MEDIUMCVSS 5.9EG 6.42024-08-27
An authenticated user can access the restricted files from NX, EX, FX, AX, IVX and CMS using path traversal.
- CVE-2026-0804MEDIUMCVSS 6.7EG 6.72026-05-12
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the inst…
- CVE-2026-44933HIGHCVSS 7.8EG 7.82026-05-20
`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the chroot target is `/`, it is a no-op, allowing the traversed pa…
- CVE-2026-45495HIGHCVSS 8.8EG 8.82026-05-18
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2026-7302CRITICALCVSS 9.1EG 9.12026-05-18
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload fi…
Map vulnerabilities like CWE-35 to your infrastructure
EchelonGraph correlates every CVE — across CWE-35 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →