On this page
Atomicorp WAF Rule 340007
Rule Summary
- Rule ID: 340007
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Generic Path Recursion denied
- Observed CWEs: CWE-20 (6), CWE-22 (477), CWE-23 (8), CWE-24 (2), CWE-28 (1), CWE-29 (4), CWE-35 (1), CWE-36 (2), CWE-59 (1), CWE-73 (26), CWE-74 (4), CWE-78 (3), CWE-79 (3), CWE-89 (6), CWE-93 (1), CWE-94 (5), CWE-98 (6), CWE-180 (1), CWE-200 (18), CWE-203 (1), CWE-206 (1), CWE-284 (6), CWE-285 (2), CWE-287 (3), CWE-306 (6), CWE-327 (1), CWE-345 (1), CWE-346 (1), CWE-352 (1), CWE-400 (2), CWE-434 (4), CWE-441 (1), CWE-472 (1), CWE-502 (1), CWE-534 (1), CWE-552 (5), CWE-610 (2), CWE-644 (1), CWE-668 (3), CWE-669 (1), CWE-698 (1), CWE-732 (1), CWE-770 (1), CWE-824 (1), CWE-829 (6), CWE-862 (4), CWE-913 (1), CWE-918 (4), CWE-1220 (1)
- Revision: 48
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request arguments, JSON request data, SOAP request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule is detecting the use of path recursion in an Argument or in the URI. This rule attempts to detect encoded recursions, an example of a recursion attack may look like:
../..
An example attack could be to get to a protected file on the system. For example:
../../../../../etc/passwd
False Positives
Some applications may use recursions to get some files. Therefore a false positive can occur. It is not recommended that you disable this rule. If this is a false positive, please report this to our security team can determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page.
If you wish to tune this rule yourself, please see the Tuning the Atomicorp WAF Rules page for basic information.
Similar Rules
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2009-0545 | ZeroShell <= 1.0beta11 Remote Code Execution | zeroshell | 10.0 (v2.0) | High |
| CVE-2010-5286 | Joomla! Component Jstore - 'Controller' Local File Inclusion | com jstore | 10.0 (v2.0) | High |
| CVE-2025-34040 | Zhiyuan OA - arbitrary file upload leading | Zhiyuan OA Web Application System | 10.0 (v4.0) | Critical |
| CVE-2025-49132 | Pterodactyl Panel - Remote Code Execution | panel | 10.0 (v3.1) | Critical |
| CVE-2025-55169 | WeGIA - Directory Traversal | wegia | 10.0 (v4.0) | Critical |
| CVE-2026-22557 | UniFi Network Application - Path Traversal | UniFi Network Application | 10.0 (v3.1) | Critical |
| CVE-2026-58192 | Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-plugin | appium/storage-plugin | 10.0 (v3.1) | Critical |
| CVE-2026-51027 | FileThingie v.2.5.7 Information Disclosure Vulnerability | - | 9.9 (v3.1) | Critical |
| CVE-2010-2861 | Adobe ColdFusion - Directory Traversal | coldfusion | 9.8 (v3.1) | Critical |
| CVE-2010-4239 | Tiki Wiki CMS Groupware 5.2 - Local File Inclusion | tikiwiki cms/groupware | 9.8 (v3.1) | Critical |
| CVE-2014-9148 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 9.8 (v3.0) | Critical |
| CVE-2015-4455 | WordPress Plugin Aviary Image Editor Addon For Gravity Forms 3.0 Beta - Arbitrary File Upload | aviary image editor add-on for gravity forms | 9.8 (v3.0) | Critical |
| CVE-2017-14094 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 9.8 (v3.0) | Critical |
| CVE-2017-14097 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 9.8 (v3.0) | Critical |
| CVE-2018-12031 | Eaton Intelligent Power Manager 1.6 - Directory Traversal | intelligent power manager | 9.8 (v3.0) | Critical |
| CVE-2018-13379 | Fortinet FortiOS - Credentials Disclosure | fortios | 9.8 (v3.1) | Critical |
| CVE-2018-16283 | WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusion | wechat brodcast | 9.8 (v3.0) | Critical |
| CVE-2018-17246 | Kibana - Local File Inclusion | kibana | 9.8 (v3.0) | Critical |
| CVE-2019-9618 | WordPress GraceMedia Media Player 1.0 - Local File Inclusion | gracemedia media player | 9.8 (v3.0) | Critical |
| CVE-2020-10189 | ManageEngine Desktop Central Java Deserialization | manageengine desktop central | 9.8 (v3.1) | Critical |
| CVE-2020-17496 | vBulletin 5.5.4 - 5.6.2- Remote Command Execution | vbulletin | 9.8 (v3.1) | Critical |
| CVE-2021-21978 | VMware View Planner <4.6 SP1- Remote Code Execution | view planner | 9.8 (v3.1) | Critical |
| CVE-2021-25281 | SaltStack Salt <3002.5 - Auth Bypass | salt | 9.8 (v3.1) | Critical |
| CVE-2021-3129 | Laravel with Ignition <= v8.4.2 Debug Mode - Remote Code Execution | ignition | 9.8 (v3.1) | Critical |
| CVE-2021-40870 | Aviatrix Controller 6.x before 6.5-1804.1922 - Remote Command Execution | controller | 9.8 (v3.1) | Critical |
| CVE-2022-1390 | WordPress Admin Word Count Column 2.2 - Local File Inclusion | admin word count column | 9.8 (v3.1) | Critical |
| CVE-2022-1391 | WordPress Cab fare calculator < 1.0.4 - Local File Inclusion | cab fare calculator | 9.8 (v3.1) | Critical |
| CVE-2022-32409 | Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusion | i3geo | 9.8 (v3.1) | Critical |
| CVE-2022-36642 | Omnia MPX 1.5.0+r1 - Local File Inclusion | omnia mpx node firmware | 9.8 (v3.1) | Critical |
| CVE-2022-37042 | Zimbra Collaboration Suite 8.8.15/9.0 - Remote Code Execution | collaboration | 9.8 (v3.1) | Critical |
| CVE-2022-41840 | Welcart eCommerce <=2.7.7 - Local File Inclusion | welcart e-commerce | 9.8 (v3.1) | Critical |
| CVE-2022-47945 | Thinkphp Lang - Local File Inclusion | thinkphp | 9.8 (v3.1) | Critical |
| CVE-2023-32563 | Ivanti Avalanche - Remote Code Execution | avalanche | 9.8 (v3.1) | Critical |
| CVE-2023-34990 | FortiWLM - Directory Traversal | fortiwlm | 9.8 (v3.1) | Critical |
| CVE-2023-40504 | LG Simple Editor <= v3.21.0 - Command Injection | simple editor | 9.8 (v3.1) | Critical |
| CVE-2023-47246 | SysAid Server - Remote Code Execution | sysaid on-premises | 9.8 (v3.1) | Critical |
| CVE-2025-2505 | WordPress Age Gate <= 3.5.3 - Unauthenticated Local File Inclusion | Age Gate | 9.8 (v3.1) | Critical |
| CVE-2026-35471 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs | goshs | 9.8 (v3.0) | Critical |
| CVE-2026-39394 | CI4MS has an .env CRLF Injection via Unvalidated host Parameter in Install Controller | ci4ms | 9.8 (v3.1) | Critical |
| CVE-2026-75337 | Yu AI Code Mother v4.3 is vulnerable to path traversal Vulnerability | Yu AI Code Mother v4.3 is vulnerable to path traversal | 9.8 (v3.1) | Critical |
| CVE-2026-25895 | FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File Write | fuxa | 9.5 (v4.0) | Critical |
| CVE-2026-11419 | Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Write | on-prem enterprise server | 9.4 (v4.0) | Critical |
| CVE-2026-72850 | Budibase before 3.40.0 Arbitrary File Write via Path Traversal | server | 9.4 (v4.0) | Critical |
| CVE-2026-77086 | SiYuan before v3.7.4 Path Traversal via packageName | siyuan | 9.4 (v4.0) | Critical |
| CVE-2019-25727 | WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download | Ad Manager WD | 9.3 (v4.0) | Critical |
| CVE-2025-55748 | XWiki Platform - Path Traversal | xwiki | 9.3 (v4.0) | Critical |
| CVE-2025-71334 | Flowise - Path Traversal | flowise | 9.3 (v4.0) | Critical |
| CVE-2026-23734 | XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash | xwiki-commons | 9.3 (v4.0) | Critical |
| CVE-2026-44343 | WGDashboard < 4.3.2 - Unauthenticated File Read | wgdashboard | 9.3 (v4.0) | Critical |
| CVE-2026-45668 | Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled) | Trilium | 9.3 (v4.0) | Critical |
| CVE-2026-47669 | DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE | dbgate | 9.3 (v4.0) | Critical |
| CVE-2026-47754 | unauthenticated path traversal in Metacat 2.x | metacat | 9.3 (v3.1) | Critical |
| CVE-2026-53976 | OpenChamber <1.13.0 - Unauthenticated Arbitrary File Read | OpenChamber | 9.3 (v4.0) | Critical |
| CVE-2026-65700 | h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API | h2ogpt | 9.3 (v4.0) | Critical |
| CVE-2026-65701 | SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route | so-vits-svc | 9.3 (v4.0) | Critical |
| CVE-2026-69110 | OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music | opencode-studio | 9.3 (v4.0) | Critical |
| CVE-2026-74798 | SiYuan kernel Path Traversal via database_clean MCP tool | siyuan | 9.3 (v4.0) | Critical |
| CVE-2026-80104 | DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload Filename | DB-GPT | 9.3 (v4.0) | Critical |
| CVE-2026-86189 | WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-65760 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0 | Easy Store extension for Joomla | 9.2 (v4.0) | Critical |
| CVE-2018-14916 | Loytec LGATE-902 <6.4.2 - Local File Inclusion | lgate-902 | 9.1 (v3.0) | Critical |
| CVE-2018-19365 | Wowza Streaming Engine Manager 4.7.4.01 - Directory Traversal | streaming engine | 9.1 (v3.1) | Critical |
| CVE-2022-26960 | elFinder <=2.1.60 - Local File Inclusion | elfinder | 9.1 (v3.1) | Critical |
| CVE-2022-27593 | QNAP QTS Photo Station External Reference - Local File Inclusion | photo station | 9.1 (v3.1) | Critical |
| CVE-2024-40422 | Devika v1 - Path Traversal | devika | 9.1 (v3.1) | Critical |
| CVE-2024-53537 | OpenPanel 0.3.4 - Directory Traversal | openpanel | 9.1 (v3.1) | Critical |
| CVE-2026-34745 | Unauthenticated Path Traversal Arbitrary File Write in /api/uploadChunked/public | fireshare | 9.1 (v3.1) | Critical |
| CVE-2026-47731 | NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by u | AIT-Core | 9.1 (v3.1) | Critical |
| CVE-2026-48024 | Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager | wazuh | 9.1 (v3.1) | Critical |
| CVE-2026-48162 | Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file pa | wazuh | 9.1 (v3.1) | Critical |
| CVE-2026-52610 | reportico-web <= 8.1.0 Path Traversal Vulnerability | reportico-web <= 8.1.0 | 9.1 (v3.1) | Critical |
| CVE-2008-4668 | Joomla! Image Browser 0.1.5 rc2 - Local File Inclusion | com imagebrowser | 9.0 (v2.0) | High |
| CVE-2026-53581 | ntp: write path traversal | core | 9.0 (v3.1) | Critical |
| CVE-2017-11398 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 8.8 (v3.0) | High |
| CVE-2018-12613 | PhpMyAdmin <4.8.2 - Local File Inclusion | phpmyadmin | 8.8 (v3.1) | High |
| CVE-2020-8641 | Lotus Core CMS 1.0.1 - Local File Inclusion | lotus core cms | 8.8 (v3.1) | High |
| CVE-2026-34524 | SillyTavern: Path traversal in /api/chats/export and /api/chats/delete allows arbitrary file read/delete within user | sillytavern | 8.8 (v3.1) | High |
| CVE-2026-36723 | bookcars v8.3 Arbitrary Code Execution Vulnerability | bookcars v8.3 | 8.8 (v3.1) | High |
| CVE-2026-42605 | AzuraCast: Path Traversal in currentDirectory Parameter Enables Remote Code Execution via Media Upload | azuracast | 8.8 (v3.1) | High |
| CVE-2026-43624 | F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project() | F5-TTS | 8.8 (v4.0) | High |
| CVE-2026-44829 | Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filename | gotenberg | 8.8 (v3.1) | High |
| CVE-2026-62677 | Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUN | omnigent | 8.8 (v3.1) | High |
| CVE-2026-65702 | Vanna 2.0.2 Path Traversal via FileSystemConversationStore | vanna | 8.8 (v4.0) | High |
| CVE-2026-76842 | Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment Clients | mercadopago | 8.8 (v4.0) | High |
| CVE-2026-81730 | Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filename | dolibarr erp/crm | 8.8 (v4.0) | High |
| CVE-2026-82286 | gpt-crawler Arbitrary File Write via outputFileName Parameter | gpt-crawler | 8.8 (v4.0) | High |
| CVE-2026-84889 | A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbit | Langflow OSS | 8.8 (v3.1) | High |
| CVE-2026-85199 | Eclipse aeriOS Path Traversal Vulnerability | Eclipse aeriOS | 8.8 (v4.0) | High |
| CVE-2026-86542 | knowns before 0.30.0 Path Traversal via Import Name | knowns | 8.8 (v4.0) | High |
| CVE-2026-86775 | knowns before 0.30.0 Path Traversal via Document API | knowns | 8.8 (v4.0) | High |
| CVE-2026-87927 | MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher | MaxSite CMS | 8.8 (v4.0) | High |
| CVE-2017-20248 | WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download | Apptha Slider Gallery | 8.7 (v4.0) | High |
| CVE-2017-20250 | WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download | Mac Photo Gallery | 8.7 (v4.0) | High |
| CVE-2018-25374 | Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal | MedDream PACS Server Premium | 8.7 (v4.0) | High |
| CVE-2021-47795 | GeoVision GeoWebServer <= 5.3.3 - Local File Inclusion / Cross-Site Scripting | geowebserver | 8.7 (v4.0) | High |
| CVE-2025-34045 | WeiPHP 5.0 - Path Traversal | weiphp | 8.7 (v4.0) | High |
| CVE-2025-71324 | Flowise - Path Traversal | flowise | 8.7 (v4.0) | High |
| CVE-2026-10108 | xiaomusic 0.5.7 Path Traversal via GET /music endpoint | xiaomusic | 8.7 (v4.0) | High |
| CVE-2026-17524 | zip-lib Path Traversal Vulnerability | zip-lib | 8.7 (v4.0) | High |
| CVE-2026-25559 | OpenBullet2 0.3.2 Path Traversal via Wordlist Endpoint | openbullet2 | 8.7 (v4.0) | High |
| CVE-2026-25855 | OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload | openbullet2 | 8.7 (v4.0) | High |
| CVE-2026-25856 | OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface | openbullet2 | 8.7 (v4.0) | High |
| CVE-2026-35214 | Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write | budibase | 8.7 (v3.1) | High |
| CVE-2026-39352 | Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path Traversal | frappe | 8.7 (v4.0) | High |
| CVE-2026-43982 | Algernon: Path traversal file write via savein() | algernon | 8.7 (v4.0) | High |
| CVE-2026-47394 | PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate | PraisonAI | 8.7 (v4.0) | High |
| CVE-2026-47659 | Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename} | pathling | 8.7 (v4.0) | High |
| CVE-2026-47661 | Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read | pathling | 8.7 (v4.0) | High |
| CVE-2026-57863 | Crater Invoice 6.0.6 Path Traversal RCE via update/unzip endpoint | crater | 8.7 (v4.0) | High |
| CVE-2026-62865 | TypeBot: Arbitrary server file read via Send Email block attachment path | typebot.io | 8.7 (v4.0) | High |
| CVE-2026-64838 | ICEcoder through 8.1 Path Traversal via oldFileName Parameter | ICEcoder | 8.7 (v4.0) | High |
| CVE-2026-65694 | Microweber CMS <= 2.0.20 - Unauthenticated Arbitrary File Read | microweber | 8.7 (v4.0) | High |
| CVE-2026-65759 | Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 | Easy Store extension for Joomla | 8.7 (v4.0) | High |
| CVE-2026-65919 | Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload | meshery | 8.7 (v4.0) | High |
| CVE-2026-67200 | Perspective 5.0.0 Path Traversal via cwd_static_file_handler | perspective | 8.7 (v4.0) | High |
| CVE-2026-67281 | Unauthenticated file read in Mikrotik RouterOS | RouterOS | 8.7 (v4.0) | High |
| CVE-2026-69089 | Grav CMS before 2.0.11 Path Traversal via watermark | grav | 8.7 (v4.0) | High |
| CVE-2026-69095 | OpenWrt luci-app-bmx7 Path Traversal via bmx7-info | luci | 8.7 (v4.0) | High |
| CVE-2026-72713 | XAgent Path Traversal Arbitrary File Read via /workspace/file | XAgent | 8.7 (v4.0) | High |
| CVE-2026-75482 | SWE-agent Trajectory Inspector Path Traversal File Disclosure | SWE-agent | 8.7 (v4.0) | High |
| CVE-2026-75914 | CodeWhale before 0.8.64 Path Traversal via image_analyze symlink | CodeWhale | 8.7 (v4.0) | High |
| CVE-2026-85685 | AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skill | agentscope | 8.7 (v4.0) | High |
| CVE-2026-89250 | WWBN AVideo Unauthenticated File Read via getRecordedFile.php | AVideo | 8.7 (v4.0) | High |
| CVE-2015-4694 | WordPress Zip Attachments <= 1.1.4 - Arbitrary File Retrieval | zip attachments | 8.6 (v3.0) | High |
| CVE-2022-24900 | Piano LED Visualizer 1.3 - Local File Inclusion | piano led visualizer | 8.6 (v3.1) | High |
| CVE-2022-41412 | perfSONAR 4.x <= 4.4.4 - Server-Side Request Forgery | perfsonar | 8.6 (v3.1) | High |
| CVE-2023-26360 | Adobe ColdFusion - Local File Read | coldfusion | 8.6 (v3.1) | High |
| CVE-2024-21136 | Oracle Retail Xstore Suite - Pre-authenticated Path Traversal | retail xstore office | 8.6 (v3.1) | High |
| CVE-2024-34470 | HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusion | mailinspector | 8.6 (v3.1) | High |
| CVE-2024-48766 | NetAlert X - Arbitary File Read | netalertx | 8.6 (v3.1) | High |
| CVE-2025-2558 | WordPress The Wound Theme <= 0.0.1 - Local File Inclusion | the wound | 8.6 (v3.1) | High |
| CVE-2025-27222 | TRUfusion Enterprise <= 7.10.4.0 - Path Traversal | trufusion enterprise | 8.6 (v3.1) | High |
| CVE-2026-46491 | SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditi | simplesamlphp-module-casserver | 8.6 (v3.1) | High |
| CVE-2026-50553 | Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) | note-mark | 8.6 (v4.0) | High |
| CVE-2025-34023 | Karel IP Phone IP1211 Web Management Panel - Local File Inclusion | Karel IP Phone IP1211 | 8.5 (v4.0) | High |
| CVE-2026-44881 | Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update | portainer | 8.5 (v4.0) | High |
| CVE-2026-73079 | Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstrea | sub2api | 8.5 (v3.1) | High |
| CVE-2026-75855 | ArcadeDB before 26.8.1 Path Traversal via create/drop database | arcadedb | 8.4 (v4.0) | High |
| CVE-2024-35219 | OpenAPI Generator <= 7.5.0 - Arbitrary File Read/Delete | openapi-generator | 8.3 (v3.1) | High |
| CVE-2026-48105 | Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path | arc | 8.3 (v4.0) | High |
| CVE-2026-69086 | SiYuan before v3.7.3 Path Traversal via unvalidated avID | siyuan | 8.3 (v4.0) | High |
| CVE-2026-75842 | ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSV | arcadedb | 8.3 (v4.0) | High |
| CVE-2026-82673 | Path traversal in AshAdmin file uploads via unsanitized client filename | ash admin | 8.3 (v4.0) | High |
| CVE-2025-44137 | MapTiler Tileserver-php v2.0 - Unauthenticated File Read | tileserver php | 8.2 (v3.1) | High |
| CVE-2026-39363 | Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket | vite | 8.2 (v4.0) | High |
| CVE-2026-39364 | Vite Dev Server - Directory Traversal | vite | 8.2 (v4.0) | High |
| CVE-2026-40075 | OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServlet | openmrs | 8.2 (v4.0) | High |
| CVE-2026-45711 | Mailpit: Path traversal & arbitrary file write in mailpit dump –http via attacker-controlled message IDs | mailpit | 8.2 (v3.1) | High |
| CVE-2026-48126 | Algernon: Host header path traversal in –domain mode reads files and runs Lua from parent dir | algernon | 8.2 (v3.1) | High |
| CVE-2026-74907 | Grav before 2.0.15 Path Traversal via plugin-asset-map.php | grav | 8.2 (v4.0) | High |
| CVE-2017-14095 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 8.1 (v3.0) | High |
| CVE-2025-2636 | InstaWP Connect < 0.1.0.86 - Local PHP File Inclusion | InstaWP Connect – 1-click WP Staging & Migration | 8.1 (v3.1) | High |
| CVE-2026-19303 | Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing c | langflow | 8.1 (v3.1) | High |
| CVE-2026-33236 | NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite | nltk | 8.1 (v3.1) | High |
| CVE-2026-34522 | SillyTavern: Path traversal in /api/chats/import allows arbitrary file write outside intended chat directory | sillytavern | 8.1 (v3.1) | High |
| CVE-2026-46484 | Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/user | headplane | 8.1 (v3.1) | High |
| CVE-2026-53580 | Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download feature | Trilium | 8.1 (v3.1) | High |
| CVE-2026-54083 | Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletion | wazuh | 8.1 (v3.1) | High |
| CVE-2026-64679 | Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creation | atlantis | 8.1 (v3.1) | High |
| CVE-2026-73659 | Trigger.dev: Cross-tenant object read/write via path traversal in packet presign API | trigger.dev | 8.1 (v3.1) | High |
| CVE-2011-3315 | Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversal | unified ip interactive voice response | 7.8 (v2.0) | High |
| CVE-2022-25485 | Cuppa CMS v1.0 - Local File Inclusion | cuppacms | 7.8 (v3.1) | High |
| CVE-2022-25486 | Cuppa CMS v1.0 - Local File Inclusion | cuppacms | 7.8 (v3.1) | High |
| CVE-2026-65600 | Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex | traefik | 7.8 (v4.0) | High |
| CVE-2026-67309 | Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass | traefik | 7.8 (v4.0) | High |
| CVE-2020-35749 | WordPress Simple Job Board <2.9.4 - Local File Inclusion | simple board job | 7.7 (v3.1) | High |
| CVE-2021-21234 | Spring Boot Actuator Logview Directory Traversal | spring-boot-actuator-logview | 7.7 (v3.1) | High |
| CVE-2026-47179 | Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in Arcane | arcane | 7.7 (v3.1) | High |
| CVE-2026-53553 | Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise | goploy | 7.7 (v3.1) | High |
| CVE-2026-54910 | FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files | filebrowser | 7.7 (v3.1) | High |
| CVE-2026-73498 | MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_at | mcp-atlassian | 7.7 (v3.1) | High |
| CVE-2026-8183 | Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement | langflow | 7.7 (v3.1) | High |
| CVE-2026-39369 | WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs | avideo | 7.6 (v3.1) | High |
| CVE-2026-44239 | FreePBX: Authenticated Local File Inclusion in Dashboard Module | freepbx | 7.6 (v4.0) | High |
| CVE-2006-2842 | Squirrelmail <=1.4.6 - Local File Inclusion | squirrelmail | 7.5 (v2.0) | High |
| CVE-2008-1059 | WordPress Sniplets 1.1.2 - Local File Inclusion | sniplets plugin | 7.5 (v2.0) | High |
| CVE-2009-1479 | boxalino 09.05.25-0421 - Directory Traversal | boxalino | 7.5 (v2.0) | High |
| CVE-2009-2015 | Joomla! MooFAQ 1.0 - Local File Inclusion | Joomla! | 7.5 (v2.0) | High |
| CVE-2009-3318 | Joomla! Roland Breedveld Album 1.14 - Local File Inclusion | Joomla! | 7.5 (v2.0) | High |
| CVE-2009-4202 | Joomla! Omilen Photo Gallery 0.5b - Local File Inclusion | joomla! | 7.5 (v2.0) | High |
| CVE-2009-4679 | Joomla! Portfolio Nexus - Remote File Inclusion | com if nexus | 7.5 (v2.0) | High |
| CVE-2010-0157 | Joomla! Component com_biblestudy - Local File Inclusion | joomla! | 7.5 (v2.0) | High |
| CVE-2010-0972 | Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusion | com gcalendar | 7.5 (v2.0) | High |
| CVE-2010-0985 | Joomla! Component com_abbrev - Local File Inclusion | com abbrev | 7.5 (v2.0) | High |
| CVE-2010-1306 | Joomla! Component Picasa 2.0 - Local File Inclusion | com joomlapicasa2 | 7.5 (v2.0) | High |
| CVE-2010-1470 | Joomla! Component Web TV 1.0 - Local File Inclusion | com webtv | 7.5 (v2.0) | High |
| CVE-2010-1471 | Joomla! Component Address Book 1.5.0 - Local File Inclusion | com addressbook | 7.5 (v2.0) | High |
| CVE-2010-1472 | Joomla! Component Horoscope 1.5.0 - Local File Inclusion | com horoscope | 7.5 (v2.0) | High |
| CVE-2010-1495 | Joomla! Component Matamko 1.01 - Local File Inclusion | com matamko | 7.5 (v2.0) | High |
| CVE-2010-1531 | Joomla! Component redSHOP 1.0 - Local File Inclusion | com redshop | 7.5 (v2.0) | High |
| CVE-2010-1533 | Joomla! Component TweetLA 1.0.1 - Local File Inclusion | com tweetla | 7.5 (v2.0) | High |
| CVE-2010-1535 | Joomla! Component TRAVELbook 1.0.1 - Local File Inclusion | com travelbook | 7.5 (v2.0) | High |
| CVE-2010-1602 | Joomla! Component ZiMB Comment 0.8.1 - Local File Inclusion | com zimbcomment | 7.5 (v2.0) | High |
| CVE-2010-1603 | Joomla! Component ZiMBCore 0.1 - Local File Inclusion | com zimbcore | 7.5 (v2.0) | High |
| CVE-2010-1653 | Joomla! Component Graphics 1.0.6 - Local File Inclusion | com graphics | 7.5 (v2.0) | High |
| CVE-2010-1717 | Joomla! Component iF surfALERT 1.2 - Local File Inclusion | if surfalert | 7.5 (v2.0) | High |
| CVE-2010-1875 | Joomla! Component Property - Local File Inclusion | com properties | 7.5 (v2.0) | High |
| CVE-2010-1878 | Joomla! Component OrgChart 1.0.0 - Local File Inclusion | com orgchart | 7.5 (v2.0) | High |
| CVE-2010-1952 | Joomla! Component BeeHeard 1.0 - Local File Inclusion | com beeheard | 7.5 (v2.0) | High |
| CVE-2010-1953 | Joomla! Component iNetLanka Multiple Map 1.0 - Local File Inclusion | com multimap | 7.5 (v2.0) | High |
| CVE-2010-1954 | Joomla! Component iNetLanka Multiple root 1.0 - Local File Inclusion | com multiroot | 7.5 (v2.0) | High |
| CVE-2010-1955 | Joomla! Component Deluxe Blog Factory 1.1.2 - Local File Inclusion | com blogfactory | 7.5 (v2.0) | High |
| CVE-2010-1956 | Joomla! Component Gadget Factory 1.0.0 - Local File Inclusion | com gadgetfactory | 7.5 (v2.0) | High |
| CVE-2010-1957 | Joomla! Component Love Factory 1.3.4 - Local File Inclusion | com lovefactory | 7.5 (v2.0) | High |
| CVE-2010-1977 | Joomla! Component J!WHMCS Integrator 1.5.0 - Local File Inclusion | com jwhmcs | 7.5 (v2.0) | High |
| CVE-2010-1980 | Joomla! Component Joomla! Flickr 1.0 - Local File Inclusion | com joomlaflickr | 7.5 (v2.0) | High |
| CVE-2010-1983 | Joomla! Component redTWITTER 1.0 - Local File Inclusion | com redtwitter | 7.5 (v2.0) | High |
| CVE-2010-2033 | Joomla! Percha Categories Tree 0.6 - Local File Inclusion | com perchacategoriestree | 7.5 (v2.0) | High |
| CVE-2010-2034 | Joomla! Component Percha Image Attach 1.1 - Directory Traversal | com perchaimageattach | 7.5 (v2.0) | High |
| CVE-2010-2035 | Joomla! Component Percha Gallery 1.6 Beta - Directory Traversal | com perchagallery | 7.5 (v2.0) | High |
| CVE-2010-2036 | Joomla! Component Percha Fields Attach 1.0 - Directory Traversal | com perchafieldsattach | 7.5 (v2.0) | High |
| CVE-2010-2037 | Joomla! Component Percha Downloads Attach 1.1 - Directory Traversal | com perchadownloadsattach | 7.5 (v2.0) | High |
| CVE-2010-2045 | Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusion | com dioneformwizard | 7.5 (v2.0) | High |
| CVE-2010-2050 | Joomla! Component MS Comment 0.8.0b - Local File Inclusion | com mscomment | 7.5 (v2.0) | High |
| CVE-2010-2128 | Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusion | com jequoteform | 7.5 (v2.0) | High |
| CVE-2010-2259 | Joomla! Component com_bfsurvey - Local File Inclusion | com bfsurvey profree | 7.5 (v2.0) | High |
| CVE-2010-2682 | Joomla! Component Realtyna Translator 1.0.15 - Local File Inclusion | com realtyna | 7.5 (v2.0) | High |
| CVE-2010-2918 | Joomla! Component Visites 1.1 - MosConfig_absolute_path Remote File Inclusion | com joomla visites | 7.5 (v2.0) | High |
| CVE-2010-3426 | Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusion | com jphone | 7.5 (v2.0) | High |
| CVE-2010-4282 | Pandora Fms < 3.1.1 - Directory Traversal | pandora fms | 7.5 (v2.0) | High |
| CVE-2010-4719 | Joomla! Component JRadio - Local File Inclusion | com jradio | 7.5 (v2.0) | High |
| CVE-2010-4769 | Joomla! Component Jimtawl 1.0.2 - Local File Inclusion | com jimtawl | 7.5 (v2.0) | High |
| CVE-2010-4977 | Joomla! Component Canteen 1.0 - Local File Inclusion | com canteen | 7.5 (v2.0) | High |
| CVE-2010-5028 | Joomla! Component JE Job 1.0 - Local File Inclusion | com jejob | 7.5 (v2.0) | High |
| CVE-2011-4448 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 7.5 (v2.0) | High |
| CVE-2012-1226 | Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilities | dolibarr erp/crm | 7.5 (v2.0) | High |
| CVE-2014-10037 | DomPHP 0.83 - Directory Traversal | domphp | 7.5 (v2.0) | High |
| CVE-2014-9145 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 7.5 (v2.0) | High |
| CVE-2014-9147 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 7.5 (v3.0) | High |
| CVE-2015-1503 | IceWarp Mail Server < 11.1.1 - Directory Traversal | mail server | 7.5 (v3.0) | High |
| CVE-2015-3648 | ResourceSpace - Local File inclusion | resourcespace | 7.5 (v2.0) | High |
| CVE-2015-9406 | mTheme Unus < 2.3 - Directory Traversal | mtheme-unus | 7.5 (v3.1) | High |
| CVE-2016-10924 | Wordpress Zedna eBook download <1.2 - Local File Inclusion | zedna ebook download | 7.5 (v3.0) | High |
| CVE-2016-2389 | SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusion | netweaver | 7.5 (v3.0) | High |
| CVE-2017-11512 | ManageEngine ServiceDesk 9.3.9328 - Arbitrary File Retrieval | servicedesk | 7.5 (v3.0) | High |
| CVE-2017-15363 | Luracast Restler 3.0.1 via TYPO3 Restler 1.7.1 - Local File Inclusion | restler | 7.5 (v3.1) | High |
| CVE-2017-9833 | BOA Web Server 0.94.14 - Arbitrary File Access | boa | 7.5 (v3.1) | High |
| CVE-2018-14912 | cgit < 1.2.1 - Directory Traversal | cgit | 7.5 (v3.0) | High |
| CVE-2018-14918 | LOYTEC LGATE-902 6.3.2 - Local File Inclusion | lgate-902 firmware | 7.5 (v3.0) | High |
| CVE-2018-15138 | LG-Ericsson iPECS NMS 30M - Local File Inclusion | ipecs nms | 7.5 (v3.0) | High |
| CVE-2018-15535 | Responsive FileManager < 9.13.4 - Directory Traversal | responsive filemanager | 7.5 (v3.0) | High |
| CVE-2018-15745 | Argus Surveillance DVR 4.0.0.0 - Local File Inclusion | dvr | 7.5 (v3.0) | High |
| CVE-2018-16299 | WordPress Localize My Post 1.0 - Local File Inclusion | localize my post | 7.5 (v3.0) | High |
| CVE-2018-19753 | Tarantella Enterprise <3.11 - Local File Inclusion | tarantella enterprise | 7.5 (v3.0) | High |
| CVE-2018-20463 | WordPress JSmol2WP <=1.07 - Local File Inclusion | jsmol2wp | 7.5 (v3.0) | High |
| CVE-2018-20470 | Tyto Sahi pro 7.x/8.x - Local File Inclusion | sahi pro | 7.5 (v3.1) | High |
| CVE-2018-6008 | Joomla! Jtag Members Directory 5.3.7 - Local File Inclusion | jtag members directory | 7.5 (v3.0) | High |
| CVE-2018-9205 | Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusion | avatar uploader | 7.5 (v3.0) | High |
| CVE-2019-12593 | IceWarp Mail Server <=10.4.4 - Local File Inclusion | mail server | 7.5 (v3.0) | High |
| CVE-2019-14205 | WordPress Nevma Adaptive Images <0.6.67 - Local File Inclusion | adaptive images | 7.5 (v3.1) | High |
| CVE-2019-14206 | Nevma Adaptive Images - Arbitrary File Deletion | adaptive images | 7.5 (v3.1) | High |
| CVE-2019-17538 | Jiangnan Online Judge 0.8.0 - Local File Inclusion | jiangnan online judge | 7.5 (v3.1) | High |
| CVE-2019-19731 | Roxy Fileman 1.4.5 - Directory Traversal | roxy fileman | 7.5 (v3.1) | High |
| CVE-2019-7254 | eMerge E3 1.00-06 - Local File Inclusion | linear emerge essential firmware | 7.5 (v3.1) | High |
| CVE-2019-9922 | Joomla! Harmis Messenger 1.2.2 - Local File Inclusion | je messenger | 7.5 (v3.1) | High |
| CVE-2020-13158 | Artica Proxy Community Edition <4.30.000000 - Local File Inclusion | artica proxy | 7.5 (v3.1) | High |
| CVE-2020-35598 | Advanced Comment System 1.0 - Local File Inclusion | advanced comment system | 7.5 (v3.1) | High |
| CVE-2020-8209 | Citrix XenMobile Server - Local File Inclusion | xenmobile server | 7.5 (v3.1) | High |
| CVE-2020-8982 | Citrix ShareFile StorageZones <=5.10.x - Arbitrary File Read | sharefile storagezones controller | 7.5 (v3.1) | High |
| CVE-2021-20123 | Draytek VigorConnect 1.6.0-B - Local File Inclusion | vigorconnect | 7.5 (v3.1) | High |
| CVE-2021-24227 | Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusion | patreon wordpress | 7.5 (v3.1) | High |
| CVE-2021-24644 | Images to WebP < 1.9 - Authenticated Local File Inclusion | images to webp | 7.5 (v3.1) | High |
| CVE-2021-33807 | Cartadis Gespage 8.2.1 - Directory Traversal | gespage | 7.5 (v3.1) | High |
| CVE-2021-35250 | SolarWinds Serv-U 15.3 - Directory Traversal | serv-u | 7.5 (v3.1) | High |
| CVE-2021-35380 | TermTalk Server 3.24.0.2 - Local File Inclusion | termtalk server | 7.5 (v3.1) | High |
| CVE-2021-39316 | WordPress DZS Zoomsounds <=6.50 - Local File Inclusion | zoomsounds | 7.5 (v3.1) | High |
| CVE-2021-39433 | BIQS IT Biqs-drive v1.83 Local File Inclusion | biqsdrive | 7.5 (v3.1) | High |
| CVE-2021-40661 | IND780 - Local File Inclusion | ind780 firmware | 7.5 (v3.1) | High |
| CVE-2021-40822 | Geoserver - Server-Side Request Forgery | geoserver | 7.5 (v3.1) | High |
| CVE-2021-41291 | ECOA Building Automation System - Directory Traversal Content Disclosure | ecs router controller-ecs firmware | 7.5 (v3.1) | High |
| CVE-2021-43287 | Pre-Auth Takeover of Build Pipelines in GoCD | gocd | 7.5 (v3.1) | High |
| CVE-2021-43778 | GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability. | barcode | 7.5 (v3.1) | High |
| CVE-2021-46417 | Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion (LFI) | colibri firmware | 7.5 (v3.1) | High |
| CVE-2022-1119 | WordPress Simple File List <3.2.8 - Local File Inclusion | simple-file-list | 7.5 (v3.1) | High |
| CVE-2022-23347 | BigAnt Server v5.6.06 - Local File Inclusion | bigant server | 7.5 (v3.1) | High |
| CVE-2022-26271 | 74cmsSE v3.4.1 - Arbitrary File Read | 74cms | 7.5 (v3.1) | High |
| CVE-2022-29298 | SolarView Compact 6.00 - Local File Inclusion | sv-cpt-mc310 firmware | 7.5 (v3.1) | High |
| CVE-2022-34121 | CuppaCMS v1.0 - Local File Inclusion | cuppacms | 7.5 (v3.1) | High |
| CVE-2022-34127 | GLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities plugin | manageentities | 7.5 (v3.1) | High |
| CVE-2022-37122 | Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Path Traversal | pcoweb hvac bacnet gateway | 7.5 (v3.1) | High |
| CVE-2023-2356 | Mlflow <2.3.0 - Local File Inclusion | mlflow | 7.5 (v3.1) | High |
| CVE-2023-27639 | PrestaShop TshirteCommerce - Directory Traversal | custom product designer | 7.5 (v3.1) | High |
| CVE-2023-27640 | PrestaShop tshirtecommerce - Directory Traversal | custom product designer | 7.5 (v3.1) | High |
| CVE-2023-29887 | Nuovo Spreadsheet Reader 0.5.11 - Local File Inclusion | spreadsheet-reader | 7.5 (v3.1) | High |
| CVE-2023-33510 | Jeecg P3 Biz Chat - Local File Inclusion | jeecg p3 biz chat | 7.5 (v3.1) | High |
| CVE-2023-38950 | ZKTeco BioTime v8.5.5 - Path Traversal | biotime | 7.5 (v3.1) | High |
| CVE-2023-40279 | OpenClinic GA 5.247.01 - Path Traversal (Authenticated) | openclinic ga | 7.5 (v3.1) | High |
| CVE-2023-40924 | SolarView Compact < 6.00 - Directory Traversal | solarview compact firmware | 7.5 (v3.1) | High |
| CVE-2023-6023 | VertaAI ModelDB - Path Traversal | modeldb | 7.5 (v3.1) | High |
| CVE-2024-1483 | Mlflow < 2.9.2 - Path Traversal | mlflow | 7.5 (v3.1) | High |
| CVE-2024-28995 | SolarWinds Serv-U - Directory Traversal | serv-u | 7.5 (v3.1) | High |
| CVE-2024-2928 | MLflow < 2.11.3 - Path Traversal | mlflow | 7.5 (v3.1) | High |
| CVE-2024-3848 | Mlflow < 2.11.0 - Path Traversal | mlflow | 7.5 (v3.1) | High |
| CVE-2024-45241 | CentralSquare CryWolf - Path Traversal | crywolf | 7.5 (v3.1) | High |
| CVE-2024-46938 | Sitecore Experience Platform <= 10.4 - Arbitrary File Read | experience commerce | 7.5 (v3.1) | High |
| CVE-2024-9362 | Polyaxon - Unauthenticated Directory Traversal | polyaxon/polyaxon | 7.5 (v3.0) | High |
| CVE-2024-9935 | PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Download | pdf-generator-addon-for-elementor-page-builder | 7.5 (v3.1) | High |
| CVE-2025-11371 | Gladinet CentreStack & TrioFox - Local File Inclusion | centrestack | 7.5 (v3.1) | High |
| CVE-2025-13339 | Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File Read | Hippoo Mobile App for WooCommerce | 7.5 (v3.1) | High |
| CVE-2025-13801 | Yoco Payments <= 3.8.8 - Path Traversal | Yoco Payments | 7.5 (v3.1) | High |
| CVE-2025-25231 | Omnissa Workspace ONE UEM - Path Traversal | workspace one uem console | 7.5 (v3.1) | High |
| CVE-2025-31131 | Yeswiki < 4.5.2 - Unauthenticated Path Traversal | yeswiki | 7.5 (v3.1) | High |
| CVE-2025-45145 | Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 Path Traversal Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2025-57231 | Path Traversal in avatar attachments in Docmost v0.21.0 Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2025-66744 | Yonyou YonBIP - Path Traversal | - | 7.5 (v3.1) | High |
| CVE-2025-69411 | ionCube Tester Plus <= 1.3 - Local File Inclusion | ionCube tester plus | 7.5 (v3.1) | High |
| CVE-2026-32820 | dataCycle Public Markdown Path Traversal Via /docs/*path | dataCycle-CORE | 7.5 (v3.1) | High |
| CVE-2026-36851 | UnPoller 2.33.0 password field Path Traversal Vulnerability | UnPoller 2.33.0 password field | 7.5 (v3.1) | High |
| CVE-2026-39359 | Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name | wazuh | 7.5 (v3.1) | High |
| CVE-2026-39847 | Emmett has a path traversal in internal assets handler | emmett | 7.5 (v3.1) | High |
| CVE-2026-50776 | Pronis Loisirs Billetterie CSE - < 04/2026 Arbitrary Code Execution Vulnerability | Pronis Loisirs Billetterie CSE - < 04/2026 | 7.5 (v3.1) | High |
| CVE-2026-5487 | DriveLock Directory Traversal Information Disclosure Vulnerability | DriveLock | 7.5 (v3.0) | High |
| CVE-2026-5491 | DriveLock Directory Traversal Information Disclosure Vulnerability | DriveLock | 7.5 (v3.0) | High |
| CVE-2026-55552 | Yamcs: Unauthenticated Directory Traversal | yamcs | 7.5 (v3.1) | High |
| CVE-2026-61891 | theia Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | theia | 7.5 (v3.1) | High |
| CVE-2026-71209 | audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Trave | audiobookshelf | 7.5 (v3.1) | High |
| CVE-2026-75328 | In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java Path Traversal Vulnerability | In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java | 7.5 (v3.1) | High |
| CVE-2026-75333 | yx-image-recognition v1.0 Path Traversal Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-79407 | the SPO extension of MetaGPT 0.8.1 Path Traversal Vulnerability | the SPO extension of MetaGPT 0.8.1 | 7.5 (v3.1) | High |
| CVE-2026-18274 | Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability | Database Proxy | 7.2 (v3.0) | High |
| CVE-2026-20297 | Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise | splunk | 7.2 (v3.1) | High |
| CVE-2026-34968 | Adminer before 5.4.3 Arbitrary File Deletion via SQLite Drop | adminer | 7.2 (v4.0) | High |
| CVE-2026-35174 | Chyrp Lite has a Path Traversal to Remote Code Execution | chyrp lite | 7.2 (v3.1) | High |
| CVE-2026-39387 | BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameter | boidcms | 7.2 (v3.1) | High |
| CVE-2026-85160 | AVideo through c91b5975d CSRF and Path Traversal via stopLive.php | AVideo | 7.2 (v4.0) | High |
| CVE-2018-25393 | Navigate CMS 2.8.5 Path Traversal via navigate_download.php | Navigate CMS | 7.1 (v4.0) | High |
| CVE-2018-25421 | Open STA Manager 2.3 Arbitrary File Download via Path Traversal | Open STA Manager | 7.1 (v4.0) | High |
| CVE-2019-10717 | BlogEngine.NET 3.3.6/3.3.7 - 'path' Directory Traversal | blogengine.net | 7.1 (v3.0) | High |
| CVE-2026-40526 | Volmarg Personal Management System Path Traversal via get-file Endpoint | personal-management-system | 7.1 (v4.0) | High |
| CVE-2026-46555 | WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration | whatsapp mcp server | 7.1 (v3.1) | High |
| CVE-2026-47735 | Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks | arc | 7.1 (v4.0) | High |
| CVE-2026-75830 | grav-plugin-api before 1.0.15 Path Traversal via batchCopy | grav | 7.1 (v4.0) | High |
| CVE-2026-76210 | phpMyFAQ before v4.1.6 Local File Disclosure via PDF Export | phpmyfaq | 7.1 (v4.0) | High |
| CVE-2026-81030 | Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items Endpoint | mage-ai | 7.1 (v4.0) | High |
| CVE-2026-82877 | ILIAS before 9.22 Arbitrary File Read via SOAP addFile | ILIAS | 7.1 (v4.0) | High |
| CVE-2026-88938 | knowns through 0.33.0 Path Traversal via code.find MCP tool | knowns | 7.1 (v4.0) | High |
| CVE-2026-40506 | OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.php | openemr | 7.0 (v4.0) | High |
| CVE-2026-54134 | OctoPrint: File exfiltration possible via query parameters on upload endpoints | OctoPrint | 7.0 (v4.0) | High |
| CVE-2026-73033 | Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php | sucuri-wordpress-plugin | 7.0 (v4.0) | High |
| CVE-2026-74038 | Wazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent Enrollment | wazuh-manager | 7.0 (v4.0) | High |
| CVE-2019-25760 | Joomla! Component Easy Shop 1.2.3 Local File Inclusion | easy shop | 6.9 (v4.0) | Medium |
| CVE-2022-50954 | WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusion | cab-fare-calculator | 6.9 (v4.0) | Medium |
| CVE-2022-50956 | WordPress Plugin amministrazione-aperta 3.7.3 Local File Read | amministrazione-aperta | 6.9 (v4.0) | Medium |
| CVE-2026-45731 | WWBN AVideo: Authenticated Arbitrary File Read in view/update.php | avideo | 6.9 (v4.0) | Medium |
| CVE-2026-45774 | compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal | compliance-trestle | 6.9 (v4.0) | Medium |
| CVE-2026-46337 | WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in view/img/image404Raw.php | avideo | 6.9 (v4.0) | Medium |
| CVE-2026-71932 | DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile | VigorSwitch G2540xs | 6.9 (v4.0) | Medium |
| CVE-2026-74235 | GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download Handler | GFI Exinda AI | 6.9 (v4.0) | Medium |
| CVE-2026-75592 | Kirby: Access to image files outside of the site root via path traversal in the media handling | kirby | 6.9 (v4.0) | Medium |
| CVE-2026-79743 | MCPHub: Path Traversal via Malicious MCPB Manifest Name | mcphub | 6.9 (v4.0) | Medium |
| CVE-2026-79773 | Winter CMS before 1.2.13 Local File Inclusion via JavaScript | winter | 6.9 (v4.0) | Medium |
| CVE-2026-79781 | rclone serve s3 Path Traversal via dot-dot object keys | rclone | 6.9 (v4.0) | Medium |
| CVE-2026-82233 | SiYuan before v3.8.1 Path Traversal via asset.upload | siyuan | 6.9 (v4.0) | Medium |
| CVE-2026-88940 | knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint | knowns | 6.9 (v4.0) | Medium |
| CVE-2008-2650 | CMSimple 3.1 - Local File Inclusion | cmsimple | 6.8 (v2.0) | Medium |
| CVE-2008-6172 | Joomla! Component RWCards 3.0.11 - Local File Inclusion | rwcards | 6.8 (v2.0) | Medium |
| CVE-2009-3053 | Joomla! Agora 3.0.0b - Local File Inclusion | Joomla! | 6.8 (v2.0) | Medium |
| CVE-2010-1056 | Joomla! Component com_rokdownloads - Local File Inclusion | com rokdownloads | 6.8 (v2.0) | Medium |
| CVE-2010-1219 | Joomla! Component com_janews - Local File Inclusion | com janews | 6.8 (v2.0) | Medium |
| CVE-2010-1469 | Joomla! Component JProject Manager 1.0 - Local File Inclusion | com jprojectmanager | 6.8 (v2.0) | Medium |
| CVE-2010-1473 | Joomla! Component Advertising 0.25 - Local File Inclusion | com advertising | 6.8 (v2.0) | Medium |
| CVE-2010-1474 | Joomla! Component Sweetykeeper 1.5 - Local File Inclusion | com sweetykeeper | 6.8 (v2.0) | Medium |
| CVE-2010-1475 | Joomla! Component Preventive And Reservation 1.0.5 - Local File Inclusion | com preventive | 6.8 (v2.0) | Medium |
| CVE-2010-1476 | Joomla! Component AlphaUserPoints 1.5.5 - Local File Inclusion | com alphauserpoints | 6.8 (v2.0) | Medium |
| CVE-2010-1478 | Joomla! Component Jfeedback 1.2 - Local File Inclusion | com jfeedback | 6.8 (v2.0) | Medium |
| CVE-2010-1607 | Joomla! Component WMI 1.5.0 - Local File Inclusion | com wmi | 6.8 (v2.0) | Medium |
| CVE-2010-1715 | Joomla! Component Online Exam 1.5.0 - Local File Inclusion | com onlineexam | 6.8 (v2.0) | Medium |
| CVE-2010-1718 | Joomla! Component Archery Scores 1.0.6 - Local File Inclusion | com archeryscores | 6.8 (v2.0) | Medium |
| CVE-2010-1719 | Joomla! Component MT Fire Eagle 1.2 - Local File Inclusion | com mtfireeagle | 6.8 (v2.0) | Medium |
| CVE-2010-1722 | Joomla! Component Online Market 2.x - Local File Inclusion | com market | 6.8 (v2.0) | Medium |
| CVE-2010-1723 | Joomla! Component iNetLanka Contact Us Draw Root Map 1.1 - Local File Inclusion | com drawroot | 6.8 (v2.0) | Medium |
| CVE-2010-1979 | Joomla! Component Affiliate Datafeeds 880 - Local File Inclusion | com datafeeds | 6.8 (v2.0) | Medium |
| CVE-2010-1981 | Joomla! Component Fabrik 2.0 - Local File Inclusion | fabrik | 6.8 (v2.0) | Medium |
| CVE-2010-2122 | Joomla! Component simpledownload <=0.9.5 - Arbitrary File Retrieval | com simpledownload | 6.8 (v2.0) | Medium |
| CVE-2010-2507 | Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusion | com picasa2gallery | 6.8 (v2.0) | Medium |
| CVE-2010-2680 | Joomla! Component jesectionfinder - Local File Inclusion | com jesectionfinder | 6.8 (v2.0) | Medium |
| CVE-2010-2857 | Joomla! Component Music Manager - Local File Inclusion | com music | 6.8 (v2.0) | Medium |
| CVE-2010-2920 | Joomla! Component Foobla Suggestions 1.5.1.2 - Local File Inclusion | com foobla suggestions | 6.8 (v2.0) | Medium |
| CVE-2010-4617 | Joomla! Component JotLoader 2.2.1 - Local File Inclusion | com jotloader | 6.8 (v2.0) | Medium |
| CVE-2011-2744 | Chyrp 2.x - Local File Inclusion | chyrp | 6.8 (v2.0) | Medium |
| CVE-2011-4449 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.8 (v2.0) | Medium |
| CVE-2011-4452 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.8 (v2.0) | Medium |
| CVE-2026-35593 | Trilium Notes has Local File Inclusion via upload modified file API endpoint | Trilium | 6.8 (v3.1) | Medium |
| CVE-2026-71475 | Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path | advanced cluster management for kubernetes | 6.8 (v3.1) | Medium |
| CVE-2016-6435 | Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion | secure firewall management center | 6.5 (v3.0) | Medium |
| CVE-2017-14537 | Trixbox 2.8.0 - Path Traversal | trixbox | 6.5 (v3.1) | Medium |
| CVE-2018-18809 | TIBCO JasperReports Library - Directory Traversal | jasperreports library | 6.5 (v3.1) | Medium |
| CVE-2020-6950 | Eclipse Mojarra - Local File Read | mojarra | 6.5 (v3.1) | Medium |
| CVE-2021-28149 | Hongdian H8922 3.0.5 Devices - Local File Inclusion | h8922 firmware | 6.5 (v3.1) | Medium |
| CVE-2021-40651 | OS4Ed OpenSIS Community 8.0 - Local File Inclusion | opensis | 6.5 (v3.1) | Medium |
| CVE-2022-34125 | GLPI Activity v3.1.0 - Authenticated Local File Inclusion on Activity plugin | cmdb | 6.5 (v3.1) | Medium |
| CVE-2022-40734 | Laravel Filemanager v2.5.1 - Local File Inclusion | laravel filemanager | 6.5 (v3.1) | Medium |
| CVE-2024-55457 | MasterSAM Star Gate v11 - Local File Inclusion | - | 6.5 (v3.1) | Medium |
| CVE-2025-28367 | mojoPortal <=2.9.0.1 - Directory Traversal | mojoportal | 6.5 (v3.1) | Medium |
| CVE-2025-45870 | LogicalDOC Enterprise up to and for v9.1.1 Path Traversal Vulnerability | - | 6.5 (v3.1) | Medium |
| CVE-2026-11442 | Allegra exportReport Directory Traversal Information Disclosure Vulnerability | Allegra | 6.5 (v3.0) | Medium |
| CVE-2026-14470 | Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base compone | langflow | 6.5 (v3.1) | Medium |
| CVE-2026-36227 | Easy Chat Server 3.1 Arbitrary Code Execution Vulnerability | Easy Chat Server 3.1 | 6.5 (v3.1) | Medium |
| CVE-2026-46397 | haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0 | haxcms-php | 6.5 (v3.1) | Medium |
| CVE-2026-52607 | reportico-web <= 8.1.0 Path Traversal Vulnerability | reportico-web <= 8.1.0 | 6.5 (v3.1) | Medium |
| CVE-2026-63667 | ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal | apostrophe | 6.5 (v3.1) | Medium |
| CVE-2026-73255 | Mongoose: Path traversal in SSI #include directives enables arbitrary file read | mongoose | 6.5 (v3.1) | Medium |
| CVE-2026-73573 | zimbra collaboration suite Path Traversal Vulnerability | zimbra collaboration suite | 6.5 (v3.1) | Medium |
| CVE-2026-73574 | zimbra collaboration suite Incorrect Resource Transfer Between Spheres Vulnerability | zimbra collaboration suite | 6.5 (v3.1) | Medium |
| CVE-2026-75602 | OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool | OpenList | 6.5 (v3.1) | Medium |
| CVE-2026-7658 | Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement | langflow | 6.5 (v3.1) | Medium |
| CVE-2026-9138 | Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing c | langflow | 6.5 (v3.1) | Medium |
| CVE-2009-0932 | Horde/Horde Groupware - Local File Inclusion | horde | 6.4 (v2.0) | Medium |
| CVE-2011-4450 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 6.4 (v2.0) | Medium |
| CVE-2026-34371 | LibreChat Affected by Arbitrary File Write via execute_code Artifact Filename Traversal | librechat | 6.3 (v3.1) | Medium |
| CVE-2026-39365 | Vite has a Path Traversal in Optimized Deps .map Handling | vite | 6.3 (v4.0) | Medium |
| CVE-2026-65012 | InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder | InvokeAI | 6.3 (v4.0) | Medium |
| CVE-2026-72814 | actix-web before 0.6.10 Information Disclosure via Files | actix-web | 6.3 (v4.0) | Medium |
| CVE-2026-78886 | liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversal | TREK | 6.3 (v4.0) | Medium |
| CVE-2014-8727 | F5 BIG-IP 10.1.0 - Directory Traversal | big-ip local traffic manager | 6.2 (v2.0) | Medium |
| CVE-2017-14096 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | 6.1 (v3.0) | Medium |
| CVE-2026-41363 | OpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image Parameter | openclaw | 6.0 (v4.0) | Medium |
| CVE-2026-65698 | Void 1.3.4 Path Traversal via AI Agent File-Reading Tools | void | 6.0 (v4.0) | Medium |
| CVE-2026-66004 | BlenderMCP Path Traversal via download_polyhaven_asset API | blender-mcp | 6.0 (v4.0) | Medium |
| CVE-2026-79653 | Eclipse SW360 Path Traversal Vulnerability | Eclipse SW360 | 6.0 (v4.0) | Medium |
| CVE-2026-49244 | SFTPGo: Path confinement bypass in public browsable share partial ZIP download | sftpgo | 5.9 (v3.1) | Medium |
| CVE-2026-82650 | SiYuan before v3.8.1 Path Traversal via /api/template/render | siyuan | 5.9 (v4.0) | Medium |
| CVE-2010-0467 | Joomla! Component CCNewsLetter - Local File Inclusion | com ccnewsletter | 5.8 (v3.1) | Medium |
| CVE-2025-47423 | Personal Weather Station Dashboard 12 - Directory Traversal | Personal Weather Station Dashboard | 5.8 (v3.1) | Medium |
| CVE-2025-1035 | KLog Server - Path Traversal | KLog Server | 5.7 (v3.1) | Medium |
| CVE-2026-40605 | Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API | Tautulli | 5.7 (v4.0) | Medium |
| CVE-2018-13980 | Zeta Producer Desktop CMS <14.2.1 - Local File Inclusion | zeta producer | 5.5 (v3.1) | Medium |
| CVE-2018-15536 | Responsive FileManager < 9.13.4 - Directory Traversal | responsive filemanager | 5.5 (v3.0) | Medium |
| CVE-2025-13810 | jsnjfz WebStack-Guns KaptchaController.java renderPicture path traversal | webstack-guns | 5.5 (v4.0) | Medium |
| CVE-2026-10694 | SourceCodester Online Food Ordering System index.php include file inclusion | Online Food Ordering System | 5.5 (v4.0) | Medium |
| CVE-2026-16252 | Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injection | Multimedia Integrated Business Display System | 5.5 (v4.0) | Medium |
| CVE-2026-18646 | danpros HTMLy Author Name htmly.php path traversal | HTMLy | 5.5 (v4.0) | Medium |
| CVE-2026-19758 | dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal | lamp-cloud | 5.5 (v4.0) | Medium |
| CVE-2026-19762 | DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversal | Taier | 5.5 (v4.0) | Medium |
| CVE-2026-19827 | alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal | alldata | 5.5 (v4.0) | Medium |
| CVE-2026-68922 | MobSF: Arbitrary File Read via Path Traversal in ZIP Uploads | Mobile-Security-Framework-MobSF | 5.5 (v3.1) | Medium |
| CVE-2026-7205 | duartium papers-mcp-server main.py search_papers path traversal | papers-mcp-server | 5.5 (v4.0) | Medium |
| CVE-2026-7206 | dubydu sqlite-mcp entry.py extract_to_json sql injection | sqlite-mcp | 5.5 (v4.0) | Medium |
| CVE-2026-7212 | edvardlindelof notes-mcp notes_mcp.py path traversal | notes-mcp | 5.5 (v4.0) | Medium |
| CVE-2026-7214 | eghuzefa engineer-your-data server.py file_inf path traversal | engineer-your-data | 5.5 (v4.0) | Medium |
| CVE-2026-7217 | Deepractice PromptX Document File index.ts read_pdf absolute path traversal | PromptX | 5.5 (v4.0) | Medium |
| CVE-2026-7314 | eiceblue spire-doc-mcp-server base.py get_doc_path path traversal | spire-doc-mcp-server | 5.5 (v4.0) | Medium |
| CVE-2026-7315 | eiceblue spire-pdf-mcp-server PDF File server.py get_pdf_path path traversal | spire-pdf-mcp-server | 5.5 (v4.0) | Medium |
| CVE-2026-7319 | elinsky execution-system-mcp add_action Tool server.py _get_context_file_path path traversal | execution-system-mcp | 5.5 (v4.0) | Medium |
| CVE-2026-81486 | bsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversal | mcp-file-context-server | 5.5 (v4.0) | Medium |
| CVE-2026-81491 | boxpositron with-context-mcp index.ts project_folder path traversal | with-context-mcp | 5.5 (v4.0) | Medium |
| CVE-2026-84441 | Piwigo Image Derivative i.php path traversal | Piwigo | 5.5 (v4.0) | Medium |
| CVE-2023-2745 | WordPress Core <=6.2 - Directory Traversal | WordPress | 5.4 (v3.1) | Medium |
| CVE-2026-17621 | Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base compone | langflow | 5.4 (v3.1) | Medium |
| CVE-2026-7869 | Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement | langflow | 5.4 (v3.1) | Medium |
| CVE-2014-8676 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | 5.3 (v3.0) | Medium |
| CVE-2014-9609 | Netsweeper 4.0.8 - Directory Traversal | netsweeper | 5.3 (v3.1) | Medium |
| CVE-2020-11798 | Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal | micollab audio, web & video conferencing | 5.3 (v3.1) | Medium |
| CVE-2020-13886 | Intelbras TIP 200/200 LITE/300 - Local File Inclusion | tip200 firmware | 5.3 (v3.1) | Medium |
| CVE-2021-28377 | Joomla! ChronoForums 2.0.11 - Local File Inclusion | chronoforums | 5.3 (v3.1) | Medium |
| CVE-2022-25497 | Cuppa CMS v1.0 - Local File Inclusion | cuppacms | 5.3 (v3.1) | Medium |
| CVE-2022-31062 | GLPI Glpiinventory v1.0.1 - Unauthenticated Local File Inclusion | glpi inventory | 5.3 (v3.1) | Medium |
| CVE-2023-2059 | DedeCMS 5.7.87 - Directory Traversal | dedecms | 5.3 (v3.1) | Medium |
| CVE-2023-30943 | Moodle - Cross-Site Scripting/Remote Code Execution | moodle | 5.3 (v3.1) | Medium |
| CVE-2023-41599 | JFinalCMS v5.0.0 - Directory Traversal | jfinalcms | 5.3 (v3.1) | Medium |
| CVE-2024-53586 | WebFileSys 2.31.0 - Directory Path Traversal | - | 5.3 (v3.1) | Medium |
| CVE-2024-7928 | FastAdmin < V1.3.4.20220530 - Path Traversal | fastadmin | 5.3 (v4.0) | Medium |
| CVE-2025-4078 | Wangshen SecGate 3600 Path Traversal Vulnerability | SecGate 3600 | 5.3 (v4.0) | Medium |
| CVE-2026-15932 | Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal | Support Genix | 5.3 (v3.1) | Medium |
| CVE-2026-16531 | Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet | Red Hat Enterprise Linux 10 | 5.3 (v3.1) | Medium |
| CVE-2026-34523 | SillyTavern: Path traversal allows file existence oracle | sillytavern | 5.3 (v3.1) | Medium |
| CVE-2026-34967 | Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Write | adminer | 5.3 (v4.0) | Medium |
| CVE-2026-36726 | bookcars v8.3 Path Traversal Vulnerability | bookcars v8.3 | 5.3 (v3.1) | Medium |
| CVE-2026-53452 | Ground Station: Unauthenticated out-of-containment file read via sigmfplayback recordingPath | ground-station | 5.3 (v3.1) | Medium |
| CVE-2026-73244 | kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listing | kkFileView | 5.3 (v3.1) | Medium |
| CVE-2026-76614 | OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore | openemr | 5.3 (v4.0) | Medium |
| CVE-2026-19761 | DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename path traversal | Taier | 5.1 (v4.0) | Medium |
| CVE-2026-19763 | DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversal | Taier | 5.1 (v4.0) | Medium |
| CVE-2026-82112 | houtini-ai houtini-lm code_task_files index.ts path traversal | houtini-lm | 5.1 (v4.0) | Medium |
| CVE-2007-4504 | Joomla! RSfiles <=1.0.2 - Local File Inclusion | rsfiles | 5.0 (v2.0) | Medium |
| CVE-2008-4764 | Joomla! <=2.0.0 RC2 - Local File Inclusion | com extplorer | 5.0 (v2.0) | Medium |
| CVE-2008-6080 | Joomla! ionFiles 4.4.2 - Local File Inclusion | com ionfiles | 5.0 (v2.0) | Medium |
| CVE-2008-6222 | Joomla! ProDesk 1.0/1.2 - Local File Inclusion | pro desk support center | 5.0 (v2.0) | Medium |
| CVE-2008-6668 | nweb2fax <=0.2.7 - Local File Inclusion | nweb2fax | 5.0 (v2.0) | Medium |
| CVE-2009-1496 | Joomla! Cmimarketplace 0.1 - Local File Inclusion | Joomla! | 5.0 (v2.0) | Medium |
| CVE-2009-2100 | Joomla! JoomlaPraise Projectfork 2.0.10 - Local File Inclusion | Joomla! | 5.0 (v2.0) | Medium |
| CVE-2009-5114 | WebGlimpse 2.18.7 - Directory Traversal | webglimpse | 5.0 (v2.0) | Medium |
| CVE-2010-0696 | Joomla! Component Jw_allVideos - Arbitrary File Retrieval | jw allvideos | 5.0 (v2.0) | Medium |
| CVE-2010-0942 | Joomla! Component com_jvideodirect - Directory Traversal | com jvideodirect | 5.0 (v2.0) | Medium |
| CVE-2010-0943 | Joomla! Component com_jashowcase - Directory Traversal | com jashowcase | 5.0 (v2.0) | Medium |
| CVE-2010-0944 | Joomla! Component com_jcollection - Directory Traversal | com jcollection | 5.0 (v2.0) | Medium |
| CVE-2010-1081 | Joomla! Component com_communitypolls 1.5.2 - Local File Inclusion | com communitypolls | 5.0 (v2.0) | Medium |
| CVE-2010-1302 | Joomla! Component DW Graph - Local File Inclusion | com dwgraphs | 5.0 (v2.0) | Medium |
| CVE-2010-1304 | Joomla! Component User Status - Local File Inclusion | com userstatus | 5.0 (v2.0) | Medium |
| CVE-2010-1305 | Joomla! Component JInventory 1.23.02 - Local File Inclusion | com jinventory | 5.0 (v2.0) | Medium |
| CVE-2010-1307 | Joomla! Component Magic Updater - Local File Inclusion | com joomlaupdater | 5.0 (v2.0) | Medium |
| CVE-2010-1308 | Joomla! Component SVMap 1.1.1 - Local File Inclusion | com svmap | 5.0 (v2.0) | Medium |
| CVE-2010-1312 | Joomla! Component News Portal 1.5.x - Local File Inclusion | com news portal | 5.0 (v2.0) | Medium |
| CVE-2010-1314 | Joomla! Component Highslide 1.5 - Local File Inclusion | com hsconfig | 5.0 (v2.0) | Medium |
| CVE-2010-1315 | Joomla! Component webERPcustomer - Local File Inclusion | com weberpcustomer | 5.0 (v2.0) | Medium |
| CVE-2010-1340 | Joomla! Component com_jresearch - 'Controller' Local File Inclusion | com jresearch | 5.0 (v2.0) | Medium |
| CVE-2010-1345 | Joomla! Component Cookex Agency CKForms - Local File Inclusion | com ckforms | 5.0 (v2.0) | Medium |
| CVE-2010-1352 | Joomla! Component Juke Box 1.7 - Local File Inclusion | com jukebox | 5.0 (v2.0) | Medium |
| CVE-2010-1353 | Joomla! Component LoginBox - Local File Inclusion | com loginbox | 5.0 (v2.0) | Medium |
| CVE-2010-1354 | Joomla! Component VJDEO 1.0 - Local File Inclusion | com vjdeo | 5.0 (v2.0) | Medium |
| CVE-2010-1461 | Joomla! Component Photo Battle 1.0.1 - Local File Inclusion | com photobattle | 5.0 (v2.0) | Medium |
| CVE-2010-1491 | Joomla! Component MMS Blog 2.3.0 - Local File Inclusion | com mmsblog | 5.0 (v2.0) | Medium |
| CVE-2010-1494 | Joomla! Component AWDwall 1.5.4 - Local File Inclusion | com awdwall | 5.0 (v2.0) | Medium |
| CVE-2010-1532 | Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusion | com powermail | 5.0 (v2.0) | Medium |
| CVE-2010-1534 | Joomla! Component Shoutbox Pro - Local File Inclusion | com shoutbox | 5.0 (v2.0) | Medium |
| CVE-2010-1540 | Joomla! Component com_blog - Directory Traversal | com myblog | 5.0 (v2.0) | Medium |
| CVE-2010-1601 | Joomla! Component JA Comment - Local File Inclusion | com jacomment | 5.0 (v2.0) | Medium |
| CVE-2010-1657 | Joomla! Component SmartSite 1.0.0 - Local File Inclusion | com smartsite | 5.0 (v2.0) | Medium |
| CVE-2010-1658 | Joomla! Component NoticeBoard 1.3 - Local File Inclusion | com noticeboard | 5.0 (v2.0) | Medium |
| CVE-2010-1659 | Joomla! Component Ultimate Portfolio 1.0 - Local File Inclusion | com ultimateportfolio | 5.0 (v2.0) | Medium |
| CVE-2010-1714 | Joomla! Component Arcade Games 1.0 - Local File Inclusion | com arcadegames | 5.0 (v2.0) | Medium |
| CVE-2010-1858 | Joomla! Component SMEStorage - Local File Inclusion | com smestorage | 5.0 (v2.0) | Medium |
| CVE-2010-1982 | Joomla! Component JA Voice 2.0 - Local File Inclusion | com javoice | 5.0 (v2.0) | Medium |
| CVE-2010-2018 | Lokomedia CMS - Local File Inclusion | lokomedia cms | 5.0 (v2.0) | Medium |
| CVE-2010-3203 | Joomla! Component PicSell 1.0 - Arbitrary File Retrieval | com picsell | 5.0 (v2.0) | Medium |
| CVE-2011-0049 | Majordomo2 - SMTP/HTTP Directory Traversal | majordomo 2 | 5.0 (v2.0) | Medium |
| CVE-2011-1669 | WP Custom Pages 0.5.0.1 - Local File Inclusion (LFI) | wp custom pages | 5.0 (v2.0) | Medium |
| CVE-2011-2780 | Chyrp 2.x - Local File Inclusion | chyrp | 5.0 (v2.0) | Medium |
| CVE-2011-4804 | Joomla! Component com_kp - 'Controller' Local File Inclusion | com obsuggest | 5.0 (v2.0) | Medium |
| CVE-2012-0981 | phpShowtime 2.0 - Directory Traversal | phpshowtime | 5.0 (v2.0) | Medium |
| CVE-2012-0996 | 11in1 CMS 1.2.1 - Local File Inclusion (LFI) | 11in1 | 5.0 (v2.0) | Medium |
| CVE-2013-5979 | Xibo 1.2.2/1.4.1 - Directory Traversal | xibo | 5.0 (v2.0) | Medium |
| CVE-2013-7091 | Zimbra Collaboration Server 7.2.2/8.0.2 Local File Inclusion | zimbra collaboration suite | 5.0 (v2.0) | Medium |
| CVE-2013-7240 | WordPress Plugin Advanced Dewplayer 1.2 - Directory Traversal | advanced dewplayer | 5.0 (v2.0) | Medium |
| CVE-2014-4940 | WordPress Plugin Tera Charts - Local File Inclusion | tera-charts | 5.0 (v2.0) | Medium |
| CVE-2014-5111 | Fonality trixbox - Local File Inclusion | trixbox | 5.0 (v2.0) | Medium |
| CVE-2014-5187 | Tom M8te (tom-m8te) Plugin 1.5.3 - Directory Traversal | tom-m8te plugin | 5.0 (v2.0) | Medium |
| CVE-2014-5368 | WordPress Plugin WP Content Source Control - Directory Traversal | wp content source control | 5.0 (v2.0) | Medium |
| CVE-2014-6308 | Osclass Security Advisory 3.4.1 - Local File Inclusion | osclass | 5.0 (v2.0) | Medium |
| CVE-2014-8799 | WordPress Plugin DukaPress 2.5.2 - Directory Traversal | dukapress | 5.0 (v2.0) | Medium |
| CVE-2014-9119 | WordPress DB Backup <=4.5 - Local File Inclusion | db backup | 5.0 (v2.0) | Medium |
| CVE-2015-2067 | Magento Server MAGMI - Directory Traversal | magmi | 5.0 (v2.0) | Medium |
| CVE-2015-3897 | Bonita BPM Portal <6.5.3 - Local File Inclusion | bonita bpm portal | 5.0 (v2.0) | Medium |
| CVE-2015-4414 | WordPress SE HTML5 Album Audio Player 1.1.0 - Directory Traversal | se html5 album audio player | 5.0 (v2.0) | Medium |
| CVE-2026-16955 | AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription | AI Engine | 5.0 (v3.1) | Medium |
| CVE-2019-2588 | Oracle Business Intelligence - Path Traversal | business intelligence publisher | 4.9 (v3.0) | Medium |
| CVE-2025-15673 | Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read | Import and export users and customers | 4.9 (v3.1) | Medium |
| CVE-2026-52832 | Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container | nuclio | 4.9 (v3.1) | Medium |
| CVE-2026-53594 | FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path | freescout | 4.9 (v3.1) | Medium |
| CVE-2008-5587 | phpPgAdmin <=4.2.1 - Local File Inclusion | phppgadmin | 4.3 (v2.0) | Medium |
| CVE-2010-0982 | Joomla! Component com_cartweberp - Local File Inclusion | com cartweberp | 4.3 (v2.0) | Medium |
| CVE-2010-1217 | Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusion | je form creator | 4.3 (v2.0) | Medium |
| CVE-2010-1313 | Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusion | com sebercart | 4.3 (v2.0) | Medium |
| CVE-2010-5278 | MODx manager - Local File Inclusion | modx revolution | 4.3 (v2.0) | Medium |
| CVE-2011-4451 | WikkaWiki 1.3.2 - Multiple Vulnerabilities | wikkawiki | 4.3 (v2.0) | Medium |
| CVE-2012-4253 | MySQLDumper 1.24.4 - Directory Traversal | mysqldumper | 4.3 (v2.0) | Medium |
| CVE-2014-9146 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 4.3 (v2.0) | Medium |
| CVE-2018-18777 | Microstrategy Web 7 - Local File Inclusion | microstrategy web | 4.3 (v3.0) | Medium |
| CVE-2022-0377 | WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaming | learnpress | 4.3 (v3.1) | Medium |
| CVE-2024-7631 | Openshift-console: openshift console: path traversal | Red Hat OpenShift Container Platform 3.11 | 4.3 (v3.1) | Medium |
| CVE-2026-26477 | dokuwiki Denial of Service Vulnerability | dokuwiki | 4.3 (v3.1) | Medium |
| CVE-2026-55495 | Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account | cloudreve | 4.3 (v3.1) | Medium |
| CVE-2011-4640 | WebTitan < 3.60 - Local File Inclusion | webtitan | 4.0 (v2.0) | Medium |
| CVE-2014-1222 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | vtiger crm | 4.0 (v2.0) | Medium |
| CVE-2014-5258 | webEdition 6.3.8.0 - Directory Traversal | webedition cms | 4.0 (v2.0) | Medium |
| CVE-2012-0991 | OpenEMR 4.1 - Local File Inclusion | openemr | 3.5 (v2.0) | Low |
| CVE-2026-55825 | Contao: Possible path traversal in job download URIs | contao | 3.1 (v3.1) | Low |
| CVE-2024-55550 | Mitel MiCollab - Arbitary File Read | cmg suite | 2.7 (v3.1) | Low |
| CVE-2026-16434 | Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypass | adminer | 2.3 (v4.0) | Low |
| CVE-2025-13816 | moxi159753 Mogu Blog v2 ZIP File unzipFile FileOperation.unzip path traversal | mogublog | 2.1 (v4.0) | Low |
| CVE-2025-13875 | Yohann0617 oci-helper OCI Configuration Upload OciServiceImpl.java addCfg path traversal | oci-helper | 2.1 (v4.0) | Low |
| CVE-2026-10213 | AstrBotDevs AstrBot API Endpoint delete path traversal | AstrBot | 2.1 (v4.0) | Low |
| CVE-2026-10278 | ishayoyo excel-mcp read_file/write_file index.ts path traversal | excel-mcp | 2.1 (v4.0) | Low |
| CVE-2026-10559 | SourceCodester Pizzafy Ecommerce System index.php file inclusion | Pizzafy Ecommerce System | 2.1 (v4.0) | Low |
| CVE-2026-11467 | jishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadService.java path traversal | jshERP | 2.1 (v4.0) | Low |
| CVE-2026-18959 | yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal | InnoShop | 2.1 (v4.0) | Low |
| CVE-2026-19756 | Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal | lamp-cloud | 2.1 (v4.0) | Low |
| CVE-2026-19828 | 648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal | wvp-GB28181-pro | 2.1 (v4.0) | Low |
| CVE-2026-76576 | yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversal | RuoYi-Vue | 2.1 (v4.0) | Low |
| CVE-2026-81845 | arben-adm mcp-sequential-thinking Import Session/Export Session server.py export_session path traversal | mcp-sequential-thinking | 2.1 (v4.0) | Low |
| CVE-2026-82599 | SeaCMS Avatar Upload member.php unlink path traversal | SeaCMS | 2.1 (v4.0) | Low |
| CVE-2026-82603 | SeaCMS Comment Cache member.php del_pl path traversal | SeaCMS | 2.1 (v4.0) | Low |
| CVE-2026-82656 | Admidio before 5.0.12 Path Traversal via Photo ZIP Download | admidio | 2.1 (v4.0) | Low |
| CVE-2026-9473 | c-rick jimeng-mcp api.ts generateVideo path traversal | jimeng-mcp | 2.1 (v4.0) | Low |
| CVE-2026-12211 | Intelbras iNVU 7016 FT Web syslog path traversal | iNVU 7016 FT | 2.0 (v4.0) | Low |
| CVE-2026-16088 | halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversal | halo | 2.0 (v4.0) | Low |
| CVE-2026-78435 | Faveo Helpdesk Logo SettingsController.php unlink path traversal | Helpdesk | 2.0 (v4.0) | Low |
| CVE-2026-81847 | MAA-AI MaaMCP pipeline_tools.py load_pipeline path traversal | MaaMCP | 2.0 (v4.0) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.
Documentation Source
- Original wiki page: WAF 340007
- Source revision: 705
- Source revision date: 2009-11-26