CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
536 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 10 of 11
- CVE-2024-44807MEDIUMCVSS 5.3EG 5.32024-10-11
A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition before 2.25.1 allows remote attackers to obtain sensitive information by exposing a list of the uploaded files.
- CVE-2024-8655MEDIUMCVSS 5.3EG 5.32024-09-10
A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unknown part of the file /web-static/. The manipulation leads to files or directories accessible. It is possible to initia…
- CVE-2024-5587MEDIUMCVSS 5.3EG 5.32024-06-02
A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown function of the file /conf/app.conf of the component Configuration File Handler. The manipulation leads to files or directori…
- CVE-2024-5045MEDIUMCVSS 5.3EG 5.32024-05-17
A vulnerability was found in SourceCodester Online Birth Certificate Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin. The manipulation leads to files or directories acc…
- CVE-2024-1005MEDIUMCVSS 5.3EG 5.32024-01-29
A vulnerability has been found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This vulnerability affects unknown code of the file /runtime/log. The manipulation leads to files or directories accessible. The a…
- CVE-2023-52112MEDIUMCVSS 5.3EG 5.32024-01-16
Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2023-4933MEDIUMCVSS 5.3EG 5.32023-10-16
The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the aut…
- CVE-2023-5101MEDIUMCVSS 5.3EG 5.32023-10-09
Files or Directories Accessible to External Parties in RDT400 in SICK APU allows an unprivileged remote attacker to download various files from the server via HTTP requests.
- CVE-2023-34834MEDIUMCVSS 5.3EG 5.32023-06-29
A Directory Browsing vulnerability in MCL-Net version 4.3.5.8788 webserver running on default port 5080, allows attackers to gain sensitive information about the configured databases via the "/file" endpoint.
- CVE-2023-29107MEDIUMCVSS 5.3EG 5.32023-05-09
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The export endpoint discloses some undocumented files. This could allow an una…
- CVE-2023-22858MEDIUMCVSS 5.3EG 5.32023-03-06
An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs.
- CVE-2022-4346MEDIUMCVSS 5.3EG 5.32023-01-23
The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used email address.
- CVE-2022-43414MEDIUMCVSS 5.3EG 5.32022-10-19
Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specified directory as test results, allowing attackers able to control agent processes to obtain test results from files in an…
- CVE-2022-2834MEDIUMCVSS 5.3EG 5.32022-10-17
The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Em…
- CVE-2022-34049MEDIUMCVSS 5.3EG 5.32022-07-20
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.
- CVE-2022-25497MEDIUMCVSS 5.3EG 5.32022-03-15
CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.
- CVE-2021-33843MEDIUMCVSS 5.3EG 5.32022-01-21
Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settings.
- CVE-2019-3897MEDIUMCVSS 5.3EG 5.32021-03-16
It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, provided they know its name. Red Hat Certification 6 and 7 is vulnerable to this issue.
- CVE-2020-35658MEDIUMCVSS 5.3EG 5.32020-12-23
SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.
- CVE-2020-13953MEDIUMCVSS 5.3EG 5.32020-09-30
In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
- CVE-2019-20593MEDIUMCVSS 5.3EG 5.32020-03-24
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Gallery leaks Private Mode thumbnails. The Samsung ID is SVE-2019-14208 (July 2019).
- CVE-2020-10105MEDIUMCVSS 5.3EG 5.32020-03-05
An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source code allows for an attacker to formulate more precise attacks…
- CVE-2019-14273MEDIUMCVSS 5.3EG 5.32019-09-26
In SilverStripe assets 4.0, there is broken access control on files.
- CVE-2019-3811MEDIUMCVSS 5.2EG 5.22019-01-15
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's fi…
- CVE-2017-6774MEDIUMCVSS 5.0EG 5.02017-08-17
A vulnerability in Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify sensitive system files. The vulnerability is due to the inc…
- CVE-2009-3597MEDIUMCVSS v2 5.0EG 5.02009-10-08
Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for autoconfig.dd.
- CVE-2005-1835MEDIUMCVSS v2 5.0EG 5.02005-06-01
NEXTWEB (i)Site stores databases under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to databases/Users.mdb.
- CVE-2026-42063MEDIUMCVSS 4.9EG 4.92026-05-13
A vulnerability exists in iControl SOAP where an authenticated attacker with the Resource Administrator or Administrator role can download sensitive files. Note: Software versions which have reached End of Technical Support (EoTS) are n…
- CVE-2021-4474MEDIUMCVSS 4.9EG 4.92026-03-26
Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows authenticated remote attackers with administrative privileges to read arbitrary files from the underlying filesystem. Attac…
- CVE-2025-66625MEDIUMCVSS 4.9EG 4.92025-12-09
Umbraco is an ASP.NET CMS. Due to unsafe handling and deletion of temporary files in versions 10.0.0 through 13.12.0, during the dictionary upload process an attacker with access to the backoffice can trigger predictable requests to tempor…
- CVE-2025-1042MEDIUMCVSS 4.9EG 4.92025-02-12
An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way.
- CVE-2024-45894MEDIUMCVSS 4.9EG 4.92024-10-07
BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.
- CVE-2024-27182MEDIUMCVSS 4.9EG 4.92024-08-02
In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator account could delete any file accessible by the Linkis system user . Users are recommended to upgrade to version 1.6.0, whi…
- CVE-2024-22240MEDIUMCVSS 4.9EG 4.92024-02-06
Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information.
- CVE-2023-48661MEDIUMCVSS 4.9EG 4.92023-12-14
Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability to read arbitrary files from the target system.
- CVE-2022-48094MEDIUMCVSS 4.9EG 4.92023-02-01
lmxcms v1.41 was discovered to contain an arbitrary file read vulnerability via TemplateAction.class.php.
- CVE-2022-4108MEDIUMCVSS 4.9EG 4.92022-12-19
The Wholesale Market for WooCommerce WordPress plugin before 1.0.8 does not validate user input used to generate system path, allowing high privilege users such as admin to download arbitrary file from the server even when they should not …
- CVE-2022-44634MEDIUMCVSS 4.9EG 4.92022-11-18
Auth. (admin+) Arbitrary File Read vulnerability in S2W – Import Shopify to WooCommerce plugin <= 1.1.12 on WordPress.
- CVE-2022-2981MEDIUMCVSS 4.9EG 4.92022-10-10
The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even i…
- CVE-2022-35235MEDIUMCVSS 4.9EG 4.92022-08-23
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
- CVE-2022-22490MEDIUMCVSS 4.9EG 4.92022-08-10
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342.
- CVE-2022-2222MEDIUMCVSS 4.9EG 4.92022-07-17
The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even i…
- CVE-2021-25004MEDIUMCVSS 4.9EG 4.92022-02-07
The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is used for support purposes, it allows to download any file from the web server without restriction after knowing the URL …
- CVE-2021-44983MEDIUMCVSS 4.9EG 4.92022-02-04
In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column.
- CVE-2022-23316MEDIUMCVSS 4.9EG 4.92022-02-04
An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admin.php?action=file&ctrl=download&path=../../1.txt.
- CVE-2021-24154MEDIUMCVSS 4.9EG 4.92021-04-05
The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web server, such as /etc/passwd
- CVE-2015-4715MEDIUMCVSS 4.9EG 4.92020-02-17
The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arb…
- CVE-2017-7737MEDIUMCVSS 4.9EG 4.92017-08-10
An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code.
- CVE-2026-6418MEDIUMCVSS 4.6EG 4.92026-05-05
An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application allows administrative users to configure a source path for account data synchronization. Due to a lack of proper pa…
- CVE-2023-4743MEDIUMCVSS 4.8EG 4.82023-09-03
A vulnerability was found in Dreamer CMS up to 4.1.3. It has been classified as problematic. Affected is an unknown function of the file /upload/ueditorConfig?action=config. The manipulation leads to files or directories accessible. It is …
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →