CWE-24— Path Traversal: '../filedir'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.— MITRE CWE catalog
119 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-24page 3 of 3
- CVE-2025-70819MEDIUMCVSS 6.3EG 6.32026-09-13
Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.
- CVE-2026-14947HIGHCVSS 7.2EG 7.22026-08-20
A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve …
- CVE-2026-21436MEDIUMCVSS 5.5EG 5.52026-01-01
eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could escape the directory set by `--destdir`. This requires the installation of a package from a malicious or compromised source. Fil…
- CVE-2026-21857MEDIUMCVSS 6.5EG 6.52026-01-07
REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions can read arbitrary files within the webroot via path traversal in the Backup addon's file export functionality. The Backu…
- CVE-2026-22810HIGHCVSS 7.3EG 7.32026-05-18
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The …
- CVE-2026-28427HIGHCVSS 7.5EG 7.52026-03-04
OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins but does not properly sanitize path components. By including ../ sequences in the request…
- CVE-2026-28538MEDIUMCVSS 5.5EG 5.92026-03-05
Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-33431MEDIUMCVSS 6.5EG 6.52026-04-20
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POST /config/<service>/show API endpoint accepts a configver parameter that is directly appended to a base directory path …
- CVE-2026-34151HIGHCVSS 8.2EG 8.22026-07-07
XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix whe…
- CVE-2026-39813CRITICALCVSS 9.8EG 9.82026-04-14
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.
- CVE-2026-40318HIGHCVSS 8.5EG 8.52026-04-16
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path bound…
- CVE-2026-41082HIGHCVSS 7.8EG 7.82026-04-16
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
- CVE-2026-44942MEDIUMCVSS 6.5EG 6.52026-06-18
A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with conten…
- CVE-2026-46687HIGHCVSS 7.7EG 7.72026-07-16
Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without validation, and log_controller.php later checks file_exists…
- CVE-2026-48047MEDIUMCVSS 5.9EG 5.92026-05-26
XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, and 17.10.3, a potential path traversal vulnerability allow an attacker who manages to get a…
- CVE-2026-49103CRITICALCVSS 9.4EG 9.42026-05-27
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.
- CVE-2026-66140HIGHCVSS 7.8EG 8.42026-07-24
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
- CVE-2026-73573MEDIUMCVSS 6.5EG 6.52026-08-13
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vul…
- CVE-2026-76353MEDIUMCVSS 5.4EG 5.42026-08-19
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could submit a crafted knowledge bundle delta to delete arbitrary files accessible to Splunk Enterprise on…
Map vulnerabilities like CWE-24 to your infrastructure
EchelonGraph correlates every CVE — across CWE-24 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →