CWE-36— Absolute Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.— MITRE CWE catalog
145 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-36page 2 of 3
- CVE-2026-49290HIGHCVSS 7.6EG 7.62026-06-19
Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Prior to 0.2.9-alpha.5, a path-traversal vulnerability in Slopsmith's archive extractors allows an attacker to write arbi…
- CVE-2026-61891HIGHCVSS 7.5EG 7.52026-08-05
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and str…
- CVE-2026-13189HIGHCVSS 7.5EG 7.52026-07-22
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side r…
- CVE-2026-10044HIGHCVSS 7.5EG 7.52026-05-28
Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attackers to read arbitrary files by supplying…
- CVE-2026-35465HIGHCVSS 7.5EG 7.52026-04-18
SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Server can achieve code execution on the C…
- CVE-2026-34515HIGHCVSS 7.5EG 7.52026-04-01
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been patched in version 3.13.…
- CVE-2026-4373HIGHCVSS 7.5EG 7.52026-03-21
The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths fro…
- CVE-2026-0846HIGHCVSS 7.5EG 7.52026-03-09
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitiza…
- CVE-2026-2753HIGHCVSS 7.5EG 7.52026-03-06
An Absolute Path Traversal vulnerability exists in Navtor NavBox. The application exposes an HTTP service that fails to properly sanitize user-supplied path input. Unauthenticated remote attackers can exploit this issue by submitting reque…
- CVE-2026-28414HIGHCVSS 7.5EG 7.52026-03-01
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that enables unauthenticated attackers to read…
- CVE-2026-27117HIGHCVSS 7.5EG 7.52026-02-24
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.11, a path traversal vulnerability ("Zip Slip") exists in bit7z's archive extraction functionality. The library does…
- CVE-2026-1330HIGHCVSS 7.5EG 7.52026-01-22
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
- CVE-2025-15227HIGHCVSS 7.5EG 7.52025-12-29
BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
- CVE-2025-8912HIGHCVSS 7.5EG 7.52025-08-13
Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
- CVE-2025-5927HIGHCVSS 7.5EG 7.52025-06-25
The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.9.4. This makes it possible for una…
- CVE-2024-11978HIGHCVSS 7.5EG 7.52024-11-29
DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
- CVE-2024-8497HIGHCVSS 7.5EG 7.52024-09-25
Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could allow an attacker obtain administrator credentials.
- CVE-2024-28806HIGHCVSS 7.5EG 7.52024-07-29
An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Remote unauthenticated attackers can upload files at an arbitrary path.
- CVE-2024-6250HIGHCVSS 7.5EG 7.52024-06-27
An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The `sanitize_path` function with `allow_absolute_path=True` allows an attacker to access arbi…
- CVE-2024-4881HIGHCVSS 7.5EG 7.52024-06-06
A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlier versions, but fixed in version 5.9.0. The vulnerability arises due to improper validation of file paths between Windo…
- CVE-2024-2548HIGHCVSS 7.5EG 7.52024-06-06
A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `lollms_core/lollms/server/endpoints/lollms_binding_files_server.py` and `lollms_core/lollms/security.py` files. Due to inadequate vali…
- CVE-2023-4172HIGHCVSS 7.5EG 7.52023-08-05
A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of t…
- CVE-2023-33871HIGHCVSS 7.5EG 7.52023-07-18
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a directory traversal vulnerability that could allow an unauthenticated user to directly access any file outside the webroot.
- CVE-2022-1554HIGHCVSS 7.5EG 7.52022-05-03
Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.
- CVE-2021-1297HIGHCVSS 7.5EG 7.52021-02-04
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrit…
- CVE-2021-1296HIGHCVSS 7.5EG 7.52021-02-04
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrit…
- CVE-2023-32054HIGHCVSS 7.3EG 7.32023-07-11
Volume Shadow Copy Elevation of Privilege Vulnerability
- CVE-2025-8575HIGHCVSS 7.2EG 7.22025-09-12
The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'lws_cl_delete_file' function in all versions up to, and including, 2.4.1.3. This makes it possible for authentic…
- CVE-2025-9518HIGHCVSS 7.2EG 7.22025-09-04
The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on the 'debug_path' parameter in all versions up to, and including, 1.2.22. This makes it possible for authenticated atta…
- CVE-2025-8213HIGHCVSS 7.2EG 7.22025-07-31
The NinjaScanner – Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'nscan_ajax_quarantine' and 'nscan_quarantine_select' functions in all versions up to, …
- CVE-2025-4799HIGHCVSS 7.2EG 7.22025-06-11
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it possible for authentic…
- CVE-2024-48850HIGHCVSS 7.2EG 7.22025-05-22
Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
- CVE-2023-36786HIGHCVSS 7.2EG 7.22023-10-10
Skype for Business Remote Code Execution Vulnerability
- CVE-2021-1618HIGHCVSS 6.5EG 7.22021-07-22
Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnera…
- CVE-2025-13283HIGHCVSS 7.1EG 7.12025-11-17
TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Copy and Paste vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF prot…
- CVE-2024-6854HIGHCVSS 7.1EG 7.12025-03-20
In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an attacker to export a model to any file in the server's file structure, thereby overwriting it. This vulnerability can be ex…
- CVE-2024-12644HIGHCVSS 7.1EG 7.12024-12-16
The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauth…
- CVE-2017-7929HIGHCVSS 7.1EG 7.12017-05-06
An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The absolute path traversal vulnerability has been identified, which may allow an attacker to traverse the file system to access restricted files…
- CVE-2026-88288MEDIUMCVSS 6.5EG 6.52026-09-10
GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to the root-run web service.
- CVE-2026-13346MEDIUMCVSS 6.5EG 6.52026-07-29
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from a…
- CVE-2026-53698MEDIUMCVSS 6.5EG 6.52026-06-10
Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.
- CVE-2026-4782MEDIUMCVSS 6.5EG 6.52026-05-13
The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2 via the 'fusion_get_svg_from_file' function with the 'custom_svg' parameter of the 'fusion_section_separator' shortcod…
- CVE-2025-9259MEDIUMCVSS 6.5EG 6.52025-08-22
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
- CVE-2025-9258MEDIUMCVSS 6.5EG 6.52025-08-22
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
- CVE-2025-9257MEDIUMCVSS 6.5EG 6.52025-08-22
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
- CVE-2025-9256MEDIUMCVSS 6.5EG 6.52025-08-22
WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
- CVE-2025-8909MEDIUMCVSS 6.5EG 6.52025-08-13
Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.
- CVE-2024-12375MEDIUMCVSS 6.5EG 6.52025-03-20
A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary files on the system by sending a specially crafted request …
- CVE-2025-0001MEDIUMCVSS 6.5EG 6.52025-02-17
Abacus ERP is versions older than 2024.210.16036, 2023.205.15833, 2022.105.15542 are affected by an authenticated arbitrary file read vulnerability.
- CVE-2024-20379MEDIUMCVSS 6.5EG 6.52024-10-23
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to read arbitrary files from the …
Map vulnerabilities like CWE-36 to your infrastructure
EchelonGraph correlates every CVE — across CWE-36 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →