CWE-22— Path Traversal
8,509 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 168 of 171
- CVE-2026-54223HIGHCVSS 8.6EG 8.62026-06-18
UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any file on the application’s server that application has privileges to, what results in Remote Code Execution. Because …
- CVE-2026-54286MEDIUMCVSS 5.9EG 5.92026-06-16
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \, which the Windows path resolver treats as a separator. s…
- CVE-2026-54293HIGHCVSS 7.5EG 7.52026-06-16
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path trav…
- CVE-2026-54319MEDIUMCVSS 4.2EG 4.22026-06-18
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.186, a sandbox volume reference (volumeId, which may also be a volume name) was forwarded to the runner and used to buil…
- CVE-2026-5436HIGHCVSS 8.1EG 8.12026-04-08
The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1. This is due to insufficient validation of the $name parameter (upload field key) passed to the generate_user_file_dirp…
- CVE-2026-54394MEDIUMCVSS 5.3EG 5.32026-06-12
MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable code builds organisation logo file paths using organisation-controlled fields such as id, name, and uuid without ensuring that the resolved…
- CVE-2026-54414CRITICALCVSS 9.8EG 9.82026-06-19
FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by Fol…
- CVE-2026-5478HIGHCVSS 8.1EG 8.12026-04-20
The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as leg…
- CVE-2026-55201MEDIUMCVSS 6.8EG 6.82026-06-17
Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that allows a rogue or compromised remote Windows server to write files outside the intended download directory by retu…
- CVE-2026-5535MEDIUMCVSS 4.3EG 4.32026-04-05
A security flaw has been discovered in FedML-AI FedML up to 0.8.9. This impacts an unknown function of the file FileUtils.java of the component MQTT Message Handler. Performing a manipulation of the argument dataSet results in path travers…
- CVE-2026-55443MEDIUMCVSS 5.1EG 5.12026-06-22
LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended r…
- CVE-2026-55488HIGHCVSS 7.7EG 7.72026-06-23
motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Versions prior to 0.44.0 contain an absolute path traversal vulnerability in multiple media file …
- CVE-2026-5595MEDIUMCVSS 6.3EG 6.32026-04-05
A security vulnerability has been detected in griptape-ai griptape 0.19.4. Affected by this vulnerability is the function load_files_from_disk/list_files_from_disk/save_content_to_file/save_memory_artifacts_to_disk of the component FileMan…
- CVE-2026-5597MEDIUMCVSS 6.3EG 6.32026-04-05
A flaw has been found in griptape-ai griptape 0.19.4. This affects an unknown part of the file griptape\tools\computer\tool.py of the component ComputerTool. Executing a manipulation of the argument filename can lead to path traversal. It …
- CVE-2026-56078HIGHCVSS 8.8EG 8.82026-06-18
PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Attackers can include traversal sequences like ../ in agent IDs to read, write, or overwrite a…
- CVE-2026-56138MEDIUMCVSS 5.3EG 5.32026-06-19
AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and s2 query parameters and, prior to the fix, attempted to retrieve and compare item contents w…
- CVE-2026-56258HIGHCVSS 8.1EG 8.12026-06-23
Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to write files outside the intended directory via symlink and time-of-check-time-of-use (TOCTOU)…
- CVE-2026-5638MEDIUMCVSS 5.3EG 5.32026-04-06
A vulnerability was detected in HerikLyma CPPWebFramework up to 3.1. This issue affects some unknown processing. Performing a manipulation results in path traversal. Remote exploitation of the attack is possible. The exploit is now public …
- CVE-2026-56394MEDIUMCVSS 6.5EG 6.52026-06-21
Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing t…
- CVE-2026-56448HIGHCVSS 8.3EG 8.32026-06-22
A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the investigation workflow to cau…
- CVE-2026-5656HIGHCVSS 7.0EG 7.02026-05-01
Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution
- CVE-2026-5710HIGHCVSS 7.5EG 7.52026-04-17
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] …
- CVE-2026-57296HIGHCVSS 8.8EG 0.02026-06-24
Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitra…
- CVE-2026-5841HIGHCVSS 7.3EG 7.32026-04-09
A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack can be executed remotely. T…
- CVE-2026-5849HIGHCVSS 7.3EG 7.32026-04-09
A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a manipulation can lead to path traversal. The attack may be launched remotely. The exploit ha…
- CVE-2026-5957MEDIUMCVSS 6.5EG 6.52026-05-05
The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of the CheckForm class, where realpath() is…
- CVE-2026-5962HIGHCVSS 7.3EG 7.32026-04-09
A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The manipulation results in path traversal. The attack may be launched remotely. The exploit is …
- CVE-2026-5966HIGHCVSS 8.1EG 8.12026-04-20
ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system.
- CVE-2026-5998MEDIUMCVSS 5.3EG 5.32026-04-10
A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file agent/memory/service.py of the component API Memory Content Endpoint. This manipulation of the argument filename cause…
- CVE-2026-6024HIGHCVSS 7.3EG 7.32026-04-10
A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. It is possible to initiate the attack re…
- CVE-2026-6057CRITICALCVSS 9.8EG 9.82026-04-10
FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.
- CVE-2026-6227HIGHCVSS 7.2EG 7.22026-04-14
The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/backwpup/v1/getblock` REST endpoint in all versions up to, and including, 5.6.6 due to a non-recursive `str_replace()` …
- CVE-2026-6248HIGHCVSS 8.1EG 8.12026-04-20
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. This is due to two compounding flaws: the Members::update() method does not validate or restrict the value of file-type c…
- CVE-2026-6262MEDIUMCVSS 6.5EG 6.52026-05-05
The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is due to the upload_icons() function workflow using a user-controlled upload path (`mfn-icon-upload`) in a filesystem mo…
- CVE-2026-6282HIGHCVSS 8.1EG 8.12026-05-13
A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device.
- CVE-2026-6320HIGHCVSS 7.5EG 7.52026-05-02
The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and late…
- CVE-2026-6321HIGHCVSS 7.5EG 7.52026-05-04
fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct UR…
- CVE-2026-6344MEDIUMCVSS 4.9EG 4.92026-05-06
The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path validation in the getAttachments() method of EmailNotificationActions, which resolves attack…
- CVE-2026-6381HIGHCVSS 7.5EG 7.52026-05-18
The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.
- CVE-2026-6403HIGHCVSS 7.5EG 7.52026-05-15
The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation in the qckply_zip_theme() function, which appends a user-controlled 'stylesheet' p…
- CVE-2026-6410MEDIUMCVSS 5.3EG 5.32026-04-16
@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option. The dirList.path() function resolves directories outside the configured static root using path.join() without a contai…
- CVE-2026-6487MEDIUMCVSS 4.3EG 4.32026-04-17
A flaw has been found in Qihui jtbc5 CMS 5.0.3.6. Affected is an unknown function of the file /dev/code/common/diplomat/manage.php of the component Code Endpoint. This manipulation of the argument path causes path traversal. The attack is …
- CVE-2026-6496MEDIUMCVSS 5.4EG 5.42026-04-17
A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /filemanager.php of the component POST Parameter Handler. The manipulation of the argument file[] results in path traversal. Th…
- CVE-2026-6568HIGHCVSS 7.3EG 7.32026-04-19
A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareOld of the file /app/controller/share.class.php of the component Public Share Handler. This manipulation of the argument…
- CVE-2026-6590MEDIUMCVSS 4.3EG 4.32026-04-20
A vulnerability was detected in ComfyUI up to 0.13.0. This impacts the function get_model_preview of the file app/model_manager.py of the component Model Preview Endpoint. The manipulation results in path traversal. The attack may be launc…
- CVE-2026-6591MEDIUMCVSS 4.3EG 4.32026-04-20
A flaw has been found in ComfyUI up to 0.13.0. Affected is the function folder_paths.get_annotated_filepath of the file folder_paths.py of the component LoadImage Node. This manipulation of the argument Name causes path traversal. Remote e…
- CVE-2026-6615HIGHCVSS 7.3EG 7.32026-04-20
A weakness has been identified in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function Upload of the file superagi/controllers/resources.py of the component Multipart Upload Handler. This manipulation of the arg…
- CVE-2026-6620MEDIUMCVSS 6.3EG 6.32026-04-20
A vulnerability was found in SonicCloudOrg sonic-server up to 2.0.0. The affected element is the function Upload of the file FileTool.java of the component File Upload Endpoint. The manipulation of the argument Type results in path travers…
- CVE-2026-6636MEDIUMCVSS 4.3EG 4.32026-04-20
A vulnerability was detected in p2r3 convert up to 6998584ace3e11db66dff0b423612a5cf91de75b. Affected is the function Bun.serve of the file buildCache.js of the component API. Performing a manipulation of the argument pathname results in p…
- CVE-2026-6670MEDIUMCVSS 6.5EG 6.52026-05-14
The Media Sync plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.9 via the 'sub_dir' and 'media_items' parameters. This is due to insufficient validation of user-supplied file paths, which are n…
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →