On this page

Atomicorp WAF Rule 340007

Rule Summary

Description

This rule is detecting the use of path recursion in an Argument or in the URI. This rule attempts to detect encoded recursions, an example of a recursion attack may look like:

../..

An example attack could be to get to a protected file on the system. For example:

../../../../../etc/passwd

False Positives

Some applications may use recursions to get some files. Therefore a false positive can occur. It is not recommended that you disable this rule. If this is a false positive, please report this to our security team can determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page.

If you wish to tune this rule yourself, please see the Tuning the Atomicorp WAF Rules page for basic information.

Similar Rules

WAF_340006

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2009-0545ZeroShell <= 1.0beta11 Remote Code Executionzeroshell10.0 (v2.0)High
CVE-2010-5286Joomla! Component Jstore - 'Controller' Local File Inclusioncom jstore10.0 (v2.0)High
CVE-2025-34040Zhiyuan OA - arbitrary file upload leadingZhiyuan OA Web Application System10.0 (v4.0)Critical
CVE-2025-49132Pterodactyl Panel - Remote Code Executionpanel10.0 (v3.1)Critical
CVE-2025-55169WeGIA - Directory Traversalwegia10.0 (v4.0)Critical
CVE-2026-22557UniFi Network Application - Path TraversalUniFi Network Application10.0 (v3.1)Critical
CVE-2026-58192Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-pluginappium/storage-plugin10.0 (v3.1)Critical
CVE-2026-51027FileThingie v.2.5.7 Information Disclosure Vulnerability-9.9 (v3.1)Critical
CVE-2010-2861Adobe ColdFusion - Directory Traversalcoldfusion9.8 (v3.1)Critical
CVE-2010-4239Tiki Wiki CMS Groupware 5.2 - Local File Inclusiontikiwiki cms/groupware9.8 (v3.1)Critical
CVE-2014-9148Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms9.8 (v3.0)Critical
CVE-2015-4455WordPress Plugin Aviary Image Editor Addon For Gravity Forms 3.0 Beta - Arbitrary File Uploadaviary image editor add-on for gravity forms9.8 (v3.0)Critical
CVE-2017-14094Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server9.8 (v3.0)Critical
CVE-2017-14097Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server9.8 (v3.0)Critical
CVE-2018-12031Eaton Intelligent Power Manager 1.6 - Directory Traversalintelligent power manager9.8 (v3.0)Critical
CVE-2018-13379Fortinet FortiOS - Credentials Disclosurefortios9.8 (v3.1)Critical
CVE-2018-16283WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusionwechat brodcast9.8 (v3.0)Critical
CVE-2018-17246Kibana - Local File Inclusionkibana9.8 (v3.0)Critical
CVE-2019-9618WordPress GraceMedia Media Player 1.0 - Local File Inclusiongracemedia media player9.8 (v3.0)Critical
CVE-2020-10189ManageEngine Desktop Central Java Deserializationmanageengine desktop central9.8 (v3.1)Critical
CVE-2020-17496vBulletin 5.5.4 - 5.6.2- Remote Command Executionvbulletin9.8 (v3.1)Critical
CVE-2021-21978VMware View Planner <4.6 SP1- Remote Code Executionview planner9.8 (v3.1)Critical
CVE-2021-25281SaltStack Salt <3002.5 - Auth Bypasssalt9.8 (v3.1)Critical
CVE-2021-3129Laravel with Ignition <= v8.4.2 Debug Mode - Remote Code Executionignition9.8 (v3.1)Critical
CVE-2021-40870Aviatrix Controller 6.x before 6.5-1804.1922 - Remote Command Executioncontroller9.8 (v3.1)Critical
CVE-2022-1390WordPress Admin Word Count Column 2.2 - Local File Inclusionadmin word count column9.8 (v3.1)Critical
CVE-2022-1391WordPress Cab fare calculator < 1.0.4 - Local File Inclusioncab fare calculator9.8 (v3.1)Critical
CVE-2022-32409Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusioni3geo9.8 (v3.1)Critical
CVE-2022-36642Omnia MPX 1.5.0+r1 - Local File Inclusionomnia mpx node firmware9.8 (v3.1)Critical
CVE-2022-37042Zimbra Collaboration Suite 8.8.15/9.0 - Remote Code Executioncollaboration9.8 (v3.1)Critical
CVE-2022-41840Welcart eCommerce <=2.7.7 - Local File Inclusionwelcart e-commerce9.8 (v3.1)Critical
CVE-2022-47945Thinkphp Lang - Local File Inclusionthinkphp9.8 (v3.1)Critical
CVE-2023-32563Ivanti Avalanche - Remote Code Executionavalanche9.8 (v3.1)Critical
CVE-2023-34990FortiWLM - Directory Traversalfortiwlm9.8 (v3.1)Critical
CVE-2023-40504LG Simple Editor <= v3.21.0 - Command Injectionsimple editor9.8 (v3.1)Critical
CVE-2023-47246SysAid Server - Remote Code Executionsysaid on-premises9.8 (v3.1)Critical
CVE-2025-2505WordPress Age Gate <= 3.5.3 - Unauthenticated Local File InclusionAge Gate9.8 (v3.1)Critical
CVE-2026-35471Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshsgoshs9.8 (v3.0)Critical
CVE-2026-39394CI4MS has an .env CRLF Injection via Unvalidated host Parameter in Install Controllerci4ms9.8 (v3.1)Critical
CVE-2026-75337Yu AI Code Mother v4.3 is vulnerable to path traversal VulnerabilityYu AI Code Mother v4.3 is vulnerable to path traversal9.8 (v3.1)Critical
CVE-2026-25895FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File Writefuxa9.5 (v4.0)Critical
CVE-2026-11419Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Writeon-prem enterprise server9.4 (v4.0)Critical
CVE-2026-72850Budibase before 3.40.0 Arbitrary File Write via Path Traversalserver9.4 (v4.0)Critical
CVE-2026-77086SiYuan before v3.7.4 Path Traversal via packageNamesiyuan9.4 (v4.0)Critical
CVE-2019-25727WordPress Plugin ad manager wd 1.0.11 Arbitrary File DownloadAd Manager WD9.3 (v4.0)Critical
CVE-2025-55748XWiki Platform - Path Traversalxwiki9.3 (v4.0)Critical
CVE-2025-71334Flowise - Path Traversalflowise9.3 (v4.0)Critical
CVE-2026-23734XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slashxwiki-commons9.3 (v4.0)Critical
CVE-2026-44343WGDashboard < 4.3.2 - Unauthenticated File Readwgdashboard9.3 (v4.0)Critical
CVE-2026-45668Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled)Trilium9.3 (v4.0)Critical
CVE-2026-47669DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCEdbgate9.3 (v4.0)Critical
CVE-2026-47754unauthenticated path traversal in Metacat 2.xmetacat9.3 (v3.1)Critical
CVE-2026-53976OpenChamber <1.13.0 - Unauthenticated Arbitrary File ReadOpenChamber9.3 (v4.0)Critical
CVE-2026-65700h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files APIh2ogpt9.3 (v4.0)Critical
CVE-2026-65701SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Routeso-vits-svc9.3 (v4.0)Critical
CVE-2026-69110OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/musicopencode-studio9.3 (v4.0)Critical
CVE-2026-74798SiYuan kernel Path Traversal via database_clean MCP toolsiyuan9.3 (v4.0)Critical
CVE-2026-80104DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload FilenameDB-GPT9.3 (v4.0)Critical
CVE-2026-86189WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.phpAVideo9.3 (v4.0)Critical
CVE-2026-65760Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0Easy Store extension for Joomla9.2 (v4.0)Critical
CVE-2018-14916Loytec LGATE-902 <6.4.2 - Local File Inclusionlgate-9029.1 (v3.0)Critical
CVE-2018-19365Wowza Streaming Engine Manager 4.7.4.01 - Directory Traversalstreaming engine9.1 (v3.1)Critical
CVE-2022-26960elFinder <=2.1.60 - Local File Inclusionelfinder9.1 (v3.1)Critical
CVE-2022-27593QNAP QTS Photo Station External Reference - Local File Inclusionphoto station9.1 (v3.1)Critical
CVE-2024-40422Devika v1 - Path Traversaldevika9.1 (v3.1)Critical
CVE-2024-53537OpenPanel 0.3.4 - Directory Traversalopenpanel9.1 (v3.1)Critical
CVE-2026-34745Unauthenticated Path Traversal Arbitrary File Write in /api/uploadChunked/publicfireshare9.1 (v3.1)Critical
CVE-2026-47731NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by uAIT-Core9.1 (v3.1)Critical
CVE-2026-48024Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh managerwazuh9.1 (v3.1)Critical
CVE-2026-48162Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file pawazuh9.1 (v3.1)Critical
CVE-2026-52610reportico-web <= 8.1.0 Path Traversal Vulnerabilityreportico-web <= 8.1.09.1 (v3.1)Critical
CVE-2008-4668Joomla! Image Browser 0.1.5 rc2 - Local File Inclusioncom imagebrowser9.0 (v2.0)High
CVE-2026-53581ntp: write path traversalcore9.0 (v3.1)Critical
CVE-2017-11398Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server8.8 (v3.0)High
CVE-2018-12613PhpMyAdmin <4.8.2 - Local File Inclusionphpmyadmin8.8 (v3.1)High
CVE-2020-8641Lotus Core CMS 1.0.1 - Local File Inclusionlotus core cms8.8 (v3.1)High
CVE-2026-34524SillyTavern: Path traversal in /api/chats/export and /api/chats/delete allows arbitrary file read/delete within usersillytavern8.8 (v3.1)High
CVE-2026-36723bookcars v8.3 Arbitrary Code Execution Vulnerabilitybookcars v8.38.8 (v3.1)High
CVE-2026-42605AzuraCast: Path Traversal in currentDirectory Parameter Enables Remote Code Execution via Media Uploadazuracast8.8 (v3.1)High
CVE-2026-43624F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project()F5-TTS8.8 (v4.0)High
CVE-2026-44829Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filenamegotenberg8.8 (v3.1)High
CVE-2026-62677Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNomnigent8.8 (v3.1)High
CVE-2026-65702Vanna 2.0.2 Path Traversal via FileSystemConversationStorevanna8.8 (v4.0)High
CVE-2026-76842Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment Clientsmercadopago8.8 (v4.0)High
CVE-2026-81730Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filenamedolibarr erp/crm8.8 (v4.0)High
CVE-2026-82286gpt-crawler Arbitrary File Write via outputFileName Parametergpt-crawler8.8 (v4.0)High
CVE-2026-84889A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitLangflow OSS8.8 (v3.1)High
CVE-2026-85199Eclipse aeriOS Path Traversal VulnerabilityEclipse aeriOS8.8 (v4.0)High
CVE-2026-86542knowns before 0.30.0 Path Traversal via Import Nameknowns8.8 (v4.0)High
CVE-2026-86775knowns before 0.30.0 Path Traversal via Document APIknowns8.8 (v4.0)High
CVE-2026-87927MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcherMaxSite CMS8.8 (v4.0)High
CVE-2017-20248WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File DownloadApptha Slider Gallery8.7 (v4.0)High
CVE-2017-20250WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File DownloadMac Photo Gallery8.7 (v4.0)High
CVE-2018-25374Softneta MedDream PACS Server Premium 6.7.1.1 Directory TraversalMedDream PACS Server Premium8.7 (v4.0)High
CVE-2021-47795GeoVision GeoWebServer <= 5.3.3 - Local File Inclusion / Cross-Site Scriptinggeowebserver8.7 (v4.0)High
CVE-2025-34045WeiPHP 5.0 - Path Traversalweiphp8.7 (v4.0)High
CVE-2025-71324Flowise - Path Traversalflowise8.7 (v4.0)High
CVE-2026-10108xiaomusic 0.5.7 Path Traversal via GET /music endpointxiaomusic8.7 (v4.0)High
CVE-2026-17524zip-lib Path Traversal Vulnerabilityzip-lib8.7 (v4.0)High
CVE-2026-25559OpenBullet2 0.3.2 Path Traversal via Wordlist Endpointopenbullet28.7 (v4.0)High
CVE-2026-25855OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Uploadopenbullet28.7 (v4.0)High
CVE-2026-25856OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interfaceopenbullet28.7 (v4.0)High
CVE-2026-35214Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file writebudibase8.7 (v3.1)High
CVE-2026-39352Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path Traversalfrappe8.7 (v4.0)High
CVE-2026-43982Algernon: Path traversal file write via savein()algernon8.7 (v4.0)High
CVE-2026-47394PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validatePraisonAI8.7 (v4.0)High
CVE-2026-47659Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename}pathling8.7 (v4.0)High
CVE-2026-47661Pathling has path traversal in $result endpoint that allows arbitrary warehouse file readpathling8.7 (v4.0)High
CVE-2026-57863Crater Invoice 6.0.6 Path Traversal RCE via update/unzip endpointcrater8.7 (v4.0)High
CVE-2026-62865TypeBot: Arbitrary server file read via Send Email block attachment pathtypebot.io8.7 (v4.0)High
CVE-2026-64838ICEcoder through 8.1 Path Traversal via oldFileName ParameterICEcoder8.7 (v4.0)High
CVE-2026-65694Microweber CMS <= 2.0.20 - Unauthenticated Arbitrary File Readmicroweber8.7 (v4.0)High
CVE-2026-65759Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1Easy Store extension for Joomla8.7 (v4.0)High
CVE-2026-65919Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownloadmeshery8.7 (v4.0)High
CVE-2026-67200Perspective 5.0.0 Path Traversal via cwd_static_file_handlerperspective8.7 (v4.0)High
CVE-2026-67281Unauthenticated file read in Mikrotik RouterOSRouterOS8.7 (v4.0)High
CVE-2026-69089Grav CMS before 2.0.11 Path Traversal via watermarkgrav8.7 (v4.0)High
CVE-2026-69095OpenWrt luci-app-bmx7 Path Traversal via bmx7-infoluci8.7 (v4.0)High
CVE-2026-72713XAgent Path Traversal Arbitrary File Read via /workspace/fileXAgent8.7 (v4.0)High
CVE-2026-75482SWE-agent Trajectory Inspector Path Traversal File DisclosureSWE-agent8.7 (v4.0)High
CVE-2026-75914CodeWhale before 0.8.64 Path Traversal via image_analyze symlinkCodeWhale8.7 (v4.0)High
CVE-2026-85685AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skillagentscope8.7 (v4.0)High
CVE-2026-89250WWBN AVideo Unauthenticated File Read via getRecordedFile.phpAVideo8.7 (v4.0)High
CVE-2015-4694WordPress Zip Attachments <= 1.1.4 - Arbitrary File Retrievalzip attachments8.6 (v3.0)High
CVE-2022-24900Piano LED Visualizer 1.3 - Local File Inclusionpiano led visualizer8.6 (v3.1)High
CVE-2022-41412perfSONAR 4.x <= 4.4.4 - Server-Side Request Forgeryperfsonar8.6 (v3.1)High
CVE-2023-26360Adobe ColdFusion - Local File Readcoldfusion8.6 (v3.1)High
CVE-2024-21136Oracle Retail Xstore Suite - Pre-authenticated Path Traversalretail xstore office8.6 (v3.1)High
CVE-2024-34470HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusionmailinspector8.6 (v3.1)High
CVE-2024-48766NetAlert X - Arbitary File Readnetalertx8.6 (v3.1)High
CVE-2025-2558WordPress The Wound Theme <= 0.0.1 - Local File Inclusionthe wound8.6 (v3.1)High
CVE-2025-27222TRUfusion Enterprise <= 7.10.4.0 - Path Traversaltrufusion enterprise8.6 (v3.1)High
CVE-2026-46491SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditisimplesamlphp-module-casserver8.6 (v3.1)High
CVE-2026-50553Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)note-mark8.6 (v4.0)High
CVE-2025-34023Karel IP Phone IP1211 Web Management Panel - Local File InclusionKarel IP Phone IP12118.5 (v4.0)High
CVE-2026-44881Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Updateportainer8.5 (v4.0)High
CVE-2026-73079Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstreasub2api8.5 (v3.1)High
CVE-2026-75855ArcadeDB before 26.8.1 Path Traversal via create/drop databasearcadedb8.4 (v4.0)High
CVE-2024-35219OpenAPI Generator <= 7.5.0 - Arbitrary File Read/Deleteopenapi-generator8.3 (v3.1)High
CVE-2026-48105Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide patharc8.3 (v4.0)High
CVE-2026-69086SiYuan before v3.7.3 Path Traversal via unvalidated avIDsiyuan8.3 (v4.0)High
CVE-2026-75842ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSVarcadedb8.3 (v4.0)High
CVE-2026-82673Path traversal in AshAdmin file uploads via unsanitized client filenameash admin8.3 (v4.0)High
CVE-2025-44137MapTiler Tileserver-php v2.0 - Unauthenticated File Readtileserver php8.2 (v3.1)High
CVE-2026-39363Vite Affected by Arbitrary File Read via Vite Dev Server WebSocketvite8.2 (v4.0)High
CVE-2026-39364Vite Dev Server - Directory Traversalvite8.2 (v4.0)High
CVE-2026-40075OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServletopenmrs8.2 (v4.0)High
CVE-2026-45711Mailpit: Path traversal & arbitrary file write in mailpit dump –http via attacker-controlled message IDsmailpit8.2 (v3.1)High
CVE-2026-48126Algernon: Host header path traversal in –domain mode reads files and runs Lua from parent diralgernon8.2 (v3.1)High
CVE-2026-74907Grav before 2.0.15 Path Traversal via plugin-asset-map.phpgrav8.2 (v4.0)High
CVE-2017-14095Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server8.1 (v3.0)High
CVE-2025-2636InstaWP Connect < 0.1.0.86 - Local PHP File InclusionInstaWP Connect – 1-click WP Staging & Migration8.1 (v3.1)High
CVE-2026-19303Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing clangflow8.1 (v3.1)High
CVE-2026-33236NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwritenltk8.1 (v3.1)High
CVE-2026-34522SillyTavern: Path traversal in /api/chats/import allows arbitrary file write outside intended chat directorysillytavern8.1 (v3.1)High
CVE-2026-46484Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/userheadplane8.1 (v3.1)High
CVE-2026-53580Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download featureTrilium8.1 (v3.1)High
CVE-2026-54083Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletionwazuh8.1 (v3.1)High
CVE-2026-64679Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creationatlantis8.1 (v3.1)High
CVE-2026-73659Trigger.dev: Cross-tenant object read/write via path traversal in packet presign APItrigger.dev8.1 (v3.1)High
CVE-2011-3315Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversalunified ip interactive voice response7.8 (v2.0)High
CVE-2022-25485Cuppa CMS v1.0 - Local File Inclusioncuppacms7.8 (v3.1)High
CVE-2022-25486Cuppa CMS v1.0 - Local File Inclusioncuppacms7.8 (v3.1)High
CVE-2026-65600Traefik before v2.11.52 Authentication Bypass via ReplacePathRegextraefik7.8 (v4.0)High
CVE-2026-67309Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypasstraefik7.8 (v4.0)High
CVE-2020-35749WordPress Simple Job Board <2.9.4 - Local File Inclusionsimple board job7.7 (v3.1)High
CVE-2021-21234Spring Boot Actuator Logview Directory Traversalspring-boot-actuator-logview7.7 (v3.1)High
CVE-2026-47179Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in Arcanearcane7.7 (v3.1)High
CVE-2026-53553Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromisegoploy7.7 (v3.1)High
CVE-2026-54910FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary filesfilebrowser7.7 (v3.1)High
CVE-2026-73498MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_atmcp-atlassian7.7 (v3.1)High
CVE-2026-8183Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcementlangflow7.7 (v3.1)High
CVE-2026-39369WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLsavideo7.6 (v3.1)High
CVE-2026-44239FreePBX: Authenticated Local File Inclusion in Dashboard Modulefreepbx7.6 (v4.0)High
CVE-2006-2842Squirrelmail <=1.4.6 - Local File Inclusionsquirrelmail7.5 (v2.0)High
CVE-2008-1059WordPress Sniplets 1.1.2 - Local File Inclusionsniplets plugin7.5 (v2.0)High
CVE-2009-1479boxalino 09.05.25-0421 - Directory Traversalboxalino7.5 (v2.0)High
CVE-2009-2015Joomla! MooFAQ 1.0 - Local File InclusionJoomla!7.5 (v2.0)High
CVE-2009-3318Joomla! Roland Breedveld Album 1.14 - Local File InclusionJoomla!7.5 (v2.0)High
CVE-2009-4202Joomla! Omilen Photo Gallery 0.5b - Local File Inclusionjoomla!7.5 (v2.0)High
CVE-2009-4679Joomla! Portfolio Nexus - Remote File Inclusioncom if nexus7.5 (v2.0)High
CVE-2010-0157Joomla! Component com_biblestudy - Local File Inclusionjoomla!7.5 (v2.0)High
CVE-2010-0972Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusioncom gcalendar7.5 (v2.0)High
CVE-2010-0985Joomla! Component com_abbrev - Local File Inclusioncom abbrev7.5 (v2.0)High
CVE-2010-1306Joomla! Component Picasa 2.0 - Local File Inclusioncom joomlapicasa27.5 (v2.0)High
CVE-2010-1470Joomla! Component Web TV 1.0 - Local File Inclusioncom webtv7.5 (v2.0)High
CVE-2010-1471Joomla! Component Address Book 1.5.0 - Local File Inclusioncom addressbook7.5 (v2.0)High
CVE-2010-1472Joomla! Component Horoscope 1.5.0 - Local File Inclusioncom horoscope7.5 (v2.0)High
CVE-2010-1495Joomla! Component Matamko 1.01 - Local File Inclusioncom matamko7.5 (v2.0)High
CVE-2010-1531Joomla! Component redSHOP 1.0 - Local File Inclusioncom redshop7.5 (v2.0)High
CVE-2010-1533Joomla! Component TweetLA 1.0.1 - Local File Inclusioncom tweetla7.5 (v2.0)High
CVE-2010-1535Joomla! Component TRAVELbook 1.0.1 - Local File Inclusioncom travelbook7.5 (v2.0)High
CVE-2010-1602Joomla! Component ZiMB Comment 0.8.1 - Local File Inclusioncom zimbcomment7.5 (v2.0)High
CVE-2010-1603Joomla! Component ZiMBCore 0.1 - Local File Inclusioncom zimbcore7.5 (v2.0)High
CVE-2010-1653Joomla! Component Graphics 1.0.6 - Local File Inclusioncom graphics7.5 (v2.0)High
CVE-2010-1717Joomla! Component iF surfALERT 1.2 - Local File Inclusionif surfalert7.5 (v2.0)High
CVE-2010-1875Joomla! Component Property - Local File Inclusioncom properties7.5 (v2.0)High
CVE-2010-1878Joomla! Component OrgChart 1.0.0 - Local File Inclusioncom orgchart7.5 (v2.0)High
CVE-2010-1952Joomla! Component BeeHeard 1.0 - Local File Inclusioncom beeheard7.5 (v2.0)High
CVE-2010-1953Joomla! Component iNetLanka Multiple Map 1.0 - Local File Inclusioncom multimap7.5 (v2.0)High
CVE-2010-1954Joomla! Component iNetLanka Multiple root 1.0 - Local File Inclusioncom multiroot7.5 (v2.0)High
CVE-2010-1955Joomla! Component Deluxe Blog Factory 1.1.2 - Local File Inclusioncom blogfactory7.5 (v2.0)High
CVE-2010-1956Joomla! Component Gadget Factory 1.0.0 - Local File Inclusioncom gadgetfactory7.5 (v2.0)High
CVE-2010-1957Joomla! Component Love Factory 1.3.4 - Local File Inclusioncom lovefactory7.5 (v2.0)High
CVE-2010-1977Joomla! Component J!WHMCS Integrator 1.5.0 - Local File Inclusioncom jwhmcs7.5 (v2.0)High
CVE-2010-1980Joomla! Component Joomla! Flickr 1.0 - Local File Inclusioncom joomlaflickr7.5 (v2.0)High
CVE-2010-1983Joomla! Component redTWITTER 1.0 - Local File Inclusioncom redtwitter7.5 (v2.0)High
CVE-2010-2033Joomla! Percha Categories Tree 0.6 - Local File Inclusioncom perchacategoriestree7.5 (v2.0)High
CVE-2010-2034Joomla! Component Percha Image Attach 1.1 - Directory Traversalcom perchaimageattach7.5 (v2.0)High
CVE-2010-2035Joomla! Component Percha Gallery 1.6 Beta - Directory Traversalcom perchagallery7.5 (v2.0)High
CVE-2010-2036Joomla! Component Percha Fields Attach 1.0 - Directory Traversalcom perchafieldsattach7.5 (v2.0)High
CVE-2010-2037Joomla! Component Percha Downloads Attach 1.1 - Directory Traversalcom perchadownloadsattach7.5 (v2.0)High
CVE-2010-2045Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusioncom dioneformwizard7.5 (v2.0)High
CVE-2010-2050Joomla! Component MS Comment 0.8.0b - Local File Inclusioncom mscomment7.5 (v2.0)High
CVE-2010-2128Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusioncom jequoteform7.5 (v2.0)High
CVE-2010-2259Joomla! Component com_bfsurvey - Local File Inclusioncom bfsurvey profree7.5 (v2.0)High
CVE-2010-2682Joomla! Component Realtyna Translator 1.0.15 - Local File Inclusioncom realtyna7.5 (v2.0)High
CVE-2010-2918Joomla! Component Visites 1.1 - MosConfig_absolute_path Remote File Inclusioncom joomla visites7.5 (v2.0)High
CVE-2010-3426Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusioncom jphone7.5 (v2.0)High
CVE-2010-4282Pandora Fms < 3.1.1 - Directory Traversalpandora fms7.5 (v2.0)High
CVE-2010-4719Joomla! Component JRadio - Local File Inclusioncom jradio7.5 (v2.0)High
CVE-2010-4769Joomla! Component Jimtawl 1.0.2 - Local File Inclusioncom jimtawl7.5 (v2.0)High
CVE-2010-4977Joomla! Component Canteen 1.0 - Local File Inclusioncom canteen7.5 (v2.0)High
CVE-2010-5028Joomla! Component JE Job 1.0 - Local File Inclusioncom jejob7.5 (v2.0)High
CVE-2011-4448WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki7.5 (v2.0)High
CVE-2012-1226Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilitiesdolibarr erp/crm7.5 (v2.0)High
CVE-2014-10037DomPHP 0.83 - Directory Traversaldomphp7.5 (v2.0)High
CVE-2014-9145Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms7.5 (v2.0)High
CVE-2014-9147Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms7.5 (v3.0)High
CVE-2015-1503IceWarp Mail Server < 11.1.1 - Directory Traversalmail server7.5 (v3.0)High
CVE-2015-3648ResourceSpace - Local File inclusionresourcespace7.5 (v2.0)High
CVE-2015-9406mTheme Unus < 2.3 - Directory Traversalmtheme-unus7.5 (v3.1)High
CVE-2016-10924Wordpress Zedna eBook download <1.2 - Local File Inclusionzedna ebook download7.5 (v3.0)High
CVE-2016-2389SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusionnetweaver7.5 (v3.0)High
CVE-2017-11512ManageEngine ServiceDesk 9.3.9328 - Arbitrary File Retrievalservicedesk7.5 (v3.0)High
CVE-2017-15363Luracast Restler 3.0.1 via TYPO3 Restler 1.7.1 - Local File Inclusionrestler7.5 (v3.1)High
CVE-2017-9833BOA Web Server 0.94.14 - Arbitrary File Accessboa7.5 (v3.1)High
CVE-2018-14912cgit < 1.2.1 - Directory Traversalcgit7.5 (v3.0)High
CVE-2018-14918LOYTEC LGATE-902 6.3.2 - Local File Inclusionlgate-902 firmware7.5 (v3.0)High
CVE-2018-15138LG-Ericsson iPECS NMS 30M - Local File Inclusionipecs nms7.5 (v3.0)High
CVE-2018-15535Responsive FileManager < 9.13.4 - Directory Traversalresponsive filemanager7.5 (v3.0)High
CVE-2018-15745Argus Surveillance DVR 4.0.0.0 - Local File Inclusiondvr7.5 (v3.0)High
CVE-2018-16299WordPress Localize My Post 1.0 - Local File Inclusionlocalize my post7.5 (v3.0)High
CVE-2018-19753Tarantella Enterprise <3.11 - Local File Inclusiontarantella enterprise7.5 (v3.0)High
CVE-2018-20463WordPress JSmol2WP <=1.07 - Local File Inclusionjsmol2wp7.5 (v3.0)High
CVE-2018-20470Tyto Sahi pro 7.x/8.x - Local File Inclusionsahi pro7.5 (v3.1)High
CVE-2018-6008Joomla! Jtag Members Directory 5.3.7 - Local File Inclusionjtag members directory7.5 (v3.0)High
CVE-2018-9205Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusionavatar uploader7.5 (v3.0)High
CVE-2019-12593IceWarp Mail Server <=10.4.4 - Local File Inclusionmail server7.5 (v3.0)High
CVE-2019-14205WordPress Nevma Adaptive Images <0.6.67 - Local File Inclusionadaptive images7.5 (v3.1)High
CVE-2019-14206Nevma Adaptive Images - Arbitrary File Deletionadaptive images7.5 (v3.1)High
CVE-2019-17538Jiangnan Online Judge 0.8.0 - Local File Inclusionjiangnan online judge7.5 (v3.1)High
CVE-2019-19731Roxy Fileman 1.4.5 - Directory Traversalroxy fileman7.5 (v3.1)High
CVE-2019-7254eMerge E3 1.00-06 - Local File Inclusionlinear emerge essential firmware7.5 (v3.1)High
CVE-2019-9922Joomla! Harmis Messenger 1.2.2 - Local File Inclusionje messenger7.5 (v3.1)High
CVE-2020-13158Artica Proxy Community Edition <4.30.000000 - Local File Inclusionartica proxy7.5 (v3.1)High
CVE-2020-35598Advanced Comment System 1.0 - Local File Inclusionadvanced comment system7.5 (v3.1)High
CVE-2020-8209Citrix XenMobile Server - Local File Inclusionxenmobile server7.5 (v3.1)High
CVE-2020-8982Citrix ShareFile StorageZones <=5.10.x - Arbitrary File Readsharefile storagezones controller7.5 (v3.1)High
CVE-2021-20123Draytek VigorConnect 1.6.0-B - Local File Inclusionvigorconnect7.5 (v3.1)High
CVE-2021-24227Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusionpatreon wordpress7.5 (v3.1)High
CVE-2021-24644Images to WebP < 1.9 - Authenticated Local File Inclusionimages to webp7.5 (v3.1)High
CVE-2021-33807Cartadis Gespage 8.2.1 - Directory Traversalgespage7.5 (v3.1)High
CVE-2021-35250SolarWinds Serv-U 15.3 - Directory Traversalserv-u7.5 (v3.1)High
CVE-2021-35380TermTalk Server 3.24.0.2 - Local File Inclusiontermtalk server7.5 (v3.1)High
CVE-2021-39316WordPress DZS Zoomsounds <=6.50 - Local File Inclusionzoomsounds7.5 (v3.1)High
CVE-2021-39433BIQS IT Biqs-drive v1.83 Local File Inclusionbiqsdrive7.5 (v3.1)High
CVE-2021-40661IND780 - Local File Inclusionind780 firmware7.5 (v3.1)High
CVE-2021-40822Geoserver - Server-Side Request Forgerygeoserver7.5 (v3.1)High
CVE-2021-41291ECOA Building Automation System - Directory Traversal Content Disclosureecs router controller-ecs firmware7.5 (v3.1)High
CVE-2021-43287Pre-Auth Takeover of Build Pipelines in GoCDgocd7.5 (v3.1)High
CVE-2021-43778GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability.barcode7.5 (v3.1)High
CVE-2021-46417Franklin Fueling Systems Colibri Controller Module 1.8.19.8580 - Local File Inclusion (LFI)colibri firmware7.5 (v3.1)High
CVE-2022-1119WordPress Simple File List <3.2.8 - Local File Inclusionsimple-file-list7.5 (v3.1)High
CVE-2022-23347BigAnt Server v5.6.06 - Local File Inclusionbigant server7.5 (v3.1)High
CVE-2022-2627174cmsSE v3.4.1 - Arbitrary File Read74cms7.5 (v3.1)High
CVE-2022-29298SolarView Compact 6.00 - Local File Inclusionsv-cpt-mc310 firmware7.5 (v3.1)High
CVE-2022-34121CuppaCMS v1.0 - Local File Inclusioncuppacms7.5 (v3.1)High
CVE-2022-34127GLPI 4.0.2 - Unauthenticated Local File Inclusion on Manageentities pluginmanageentities7.5 (v3.1)High
CVE-2022-37122Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Path Traversalpcoweb hvac bacnet gateway7.5 (v3.1)High
CVE-2023-2356Mlflow <2.3.0 - Local File Inclusionmlflow7.5 (v3.1)High
CVE-2023-27639PrestaShop TshirteCommerce - Directory Traversalcustom product designer7.5 (v3.1)High
CVE-2023-27640PrestaShop tshirtecommerce - Directory Traversalcustom product designer7.5 (v3.1)High
CVE-2023-29887Nuovo Spreadsheet Reader 0.5.11 - Local File Inclusionspreadsheet-reader7.5 (v3.1)High
CVE-2023-33510Jeecg P3 Biz Chat - Local File Inclusionjeecg p3 biz chat7.5 (v3.1)High
CVE-2023-38950ZKTeco BioTime v8.5.5 - Path Traversalbiotime7.5 (v3.1)High
CVE-2023-40279OpenClinic GA 5.247.01 - Path Traversal (Authenticated)openclinic ga7.5 (v3.1)High
CVE-2023-40924SolarView Compact < 6.00 - Directory Traversalsolarview compact firmware7.5 (v3.1)High
CVE-2023-6023VertaAI ModelDB - Path Traversalmodeldb7.5 (v3.1)High
CVE-2024-1483Mlflow < 2.9.2 - Path Traversalmlflow7.5 (v3.1)High
CVE-2024-28995SolarWinds Serv-U - Directory Traversalserv-u7.5 (v3.1)High
CVE-2024-2928MLflow < 2.11.3 - Path Traversalmlflow7.5 (v3.1)High
CVE-2024-3848Mlflow < 2.11.0 - Path Traversalmlflow7.5 (v3.1)High
CVE-2024-45241CentralSquare CryWolf - Path Traversalcrywolf7.5 (v3.1)High
CVE-2024-46938Sitecore Experience Platform <= 10.4 - Arbitrary File Readexperience commerce7.5 (v3.1)High
CVE-2024-9362Polyaxon - Unauthenticated Directory Traversalpolyaxon/polyaxon7.5 (v3.0)High
CVE-2024-9935PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Downloadpdf-generator-addon-for-elementor-page-builder7.5 (v3.1)High
CVE-2025-11371Gladinet CentreStack & TrioFox - Local File Inclusioncentrestack7.5 (v3.1)High
CVE-2025-13339Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File ReadHippoo Mobile App for WooCommerce7.5 (v3.1)High
CVE-2025-13801Yoco Payments <= 3.8.8 - Path TraversalYoco Payments7.5 (v3.1)High
CVE-2025-25231Omnissa Workspace ONE UEM - Path Traversalworkspace one uem console7.5 (v3.1)High
CVE-2025-31131Yeswiki < 4.5.2 - Unauthenticated Path Traversalyeswiki7.5 (v3.1)High
CVE-2025-45145Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 Path Traversal Vulnerability-7.5 (v3.1)High
CVE-2025-57231Path Traversal in avatar attachments in Docmost v0.21.0 Vulnerability-7.5 (v3.1)High
CVE-2025-66744Yonyou YonBIP - Path Traversal-7.5 (v3.1)High
CVE-2025-69411ionCube Tester Plus <= 1.3 - Local File InclusionionCube tester plus7.5 (v3.1)High
CVE-2026-32820dataCycle Public Markdown Path Traversal Via /docs/*pathdataCycle-CORE7.5 (v3.1)High
CVE-2026-36851UnPoller 2.33.0 password field Path Traversal VulnerabilityUnPoller 2.33.0 password field7.5 (v3.1)High
CVE-2026-39359Wazuh: Unauthenticated Path Traversal in authd via Agent Group Namewazuh7.5 (v3.1)High
CVE-2026-39847Emmett has a path traversal in internal assets handleremmett7.5 (v3.1)High
CVE-2026-50776Pronis Loisirs Billetterie CSE - < 04/2026 Arbitrary Code Execution VulnerabilityPronis Loisirs Billetterie CSE - < 04/20267.5 (v3.1)High
CVE-2026-5487DriveLock Directory Traversal Information Disclosure VulnerabilityDriveLock7.5 (v3.0)High
CVE-2026-5491DriveLock Directory Traversal Information Disclosure VulnerabilityDriveLock7.5 (v3.0)High
CVE-2026-55552Yamcs: Unauthenticated Directory Traversalyamcs7.5 (v3.1)High
CVE-2026-61891theia Exposure of Sensitive Information to an Unauthorized Actor Vulnerabilitytheia7.5 (v3.1)High
CVE-2026-71209audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Traveaudiobookshelf7.5 (v3.1)High
CVE-2026-75328In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java Path Traversal VulnerabilityIn DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java7.5 (v3.1)High
CVE-2026-75333yx-image-recognition v1.0 Path Traversal Vulnerability-7.5 (v3.1)High
CVE-2026-79407the SPO extension of MetaGPT 0.8.1 Path Traversal Vulnerabilitythe SPO extension of MetaGPT 0.8.17.5 (v3.1)High
CVE-2026-18274Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution VulnerabilityDatabase Proxy7.2 (v3.0)High
CVE-2026-20297Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprisesplunk7.2 (v3.1)High
CVE-2026-34968Adminer before 5.4.3 Arbitrary File Deletion via SQLite Dropadminer7.2 (v4.0)High
CVE-2026-35174Chyrp Lite has a Path Traversal to Remote Code Executionchyrp lite7.2 (v3.1)High
CVE-2026-39387BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameterboidcms7.2 (v3.1)High
CVE-2026-85160AVideo through c91b5975d CSRF and Path Traversal via stopLive.phpAVideo7.2 (v4.0)High
CVE-2018-25393Navigate CMS 2.8.5 Path Traversal via navigate_download.phpNavigate CMS7.1 (v4.0)High
CVE-2018-25421Open STA Manager 2.3 Arbitrary File Download via Path TraversalOpen STA Manager7.1 (v4.0)High
CVE-2019-10717BlogEngine.NET 3.3.6/3.3.7 - 'path' Directory Traversalblogengine.net7.1 (v3.0)High
CVE-2026-40526Volmarg Personal Management System Path Traversal via get-file Endpointpersonal-management-system7.1 (v4.0)High
CVE-2026-46555WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltrationwhatsapp mcp server7.1 (v3.1)High
CVE-2026-47735Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checksarc7.1 (v4.0)High
CVE-2026-75830grav-plugin-api before 1.0.15 Path Traversal via batchCopygrav7.1 (v4.0)High
CVE-2026-76210phpMyFAQ before v4.1.6 Local File Disclosure via PDF Exportphpmyfaq7.1 (v4.0)High
CVE-2026-81030Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items Endpointmage-ai7.1 (v4.0)High
CVE-2026-82877ILIAS before 9.22 Arbitrary File Read via SOAP addFileILIAS7.1 (v4.0)High
CVE-2026-88938knowns through 0.33.0 Path Traversal via code.find MCP toolknowns7.1 (v4.0)High
CVE-2026-40506OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.phpopenemr7.0 (v4.0)High
CVE-2026-54134OctoPrint: File exfiltration possible via query parameters on upload endpointsOctoPrint7.0 (v4.0)High
CVE-2026-73033Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.phpsucuri-wordpress-plugin7.0 (v4.0)High
CVE-2026-74038Wazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent Enrollmentwazuh-manager7.0 (v4.0)High
CVE-2019-25760Joomla! Component Easy Shop 1.2.3 Local File Inclusioneasy shop6.9 (v4.0)Medium
CVE-2022-50954WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusioncab-fare-calculator6.9 (v4.0)Medium
CVE-2022-50956WordPress Plugin amministrazione-aperta 3.7.3 Local File Readamministrazione-aperta6.9 (v4.0)Medium
CVE-2026-45731WWBN AVideo: Authenticated Arbitrary File Read in view/update.phpavideo6.9 (v4.0)Medium
CVE-2026-45774compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversalcompliance-trestle6.9 (v4.0)Medium
CVE-2026-46337WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in view/img/image404Raw.phpavideo6.9 (v4.0)Medium
CVE-2026-71932DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFileVigorSwitch G2540xs6.9 (v4.0)Medium
CVE-2026-74235GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download HandlerGFI Exinda AI6.9 (v4.0)Medium
CVE-2026-75592Kirby: Access to image files outside of the site root via path traversal in the media handlingkirby6.9 (v4.0)Medium
CVE-2026-79743MCPHub: Path Traversal via Malicious MCPB Manifest Namemcphub6.9 (v4.0)Medium
CVE-2026-79773Winter CMS before 1.2.13 Local File Inclusion via JavaScriptwinter6.9 (v4.0)Medium
CVE-2026-79781rclone serve s3 Path Traversal via dot-dot object keysrclone6.9 (v4.0)Medium
CVE-2026-82233SiYuan before v3.8.1 Path Traversal via asset.uploadsiyuan6.9 (v4.0)Medium
CVE-2026-88940knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpointknowns6.9 (v4.0)Medium
CVE-2008-2650CMSimple 3.1 - Local File Inclusioncmsimple6.8 (v2.0)Medium
CVE-2008-6172Joomla! Component RWCards 3.0.11 - Local File Inclusionrwcards6.8 (v2.0)Medium
CVE-2009-3053Joomla! Agora 3.0.0b - Local File InclusionJoomla!6.8 (v2.0)Medium
CVE-2010-1056Joomla! Component com_rokdownloads - Local File Inclusioncom rokdownloads6.8 (v2.0)Medium
CVE-2010-1219Joomla! Component com_janews - Local File Inclusioncom janews6.8 (v2.0)Medium
CVE-2010-1469Joomla! Component JProject Manager 1.0 - Local File Inclusioncom jprojectmanager6.8 (v2.0)Medium
CVE-2010-1473Joomla! Component Advertising 0.25 - Local File Inclusioncom advertising6.8 (v2.0)Medium
CVE-2010-1474Joomla! Component Sweetykeeper 1.5 - Local File Inclusioncom sweetykeeper6.8 (v2.0)Medium
CVE-2010-1475Joomla! Component Preventive And Reservation 1.0.5 - Local File Inclusioncom preventive6.8 (v2.0)Medium
CVE-2010-1476Joomla! Component AlphaUserPoints 1.5.5 - Local File Inclusioncom alphauserpoints6.8 (v2.0)Medium
CVE-2010-1478Joomla! Component Jfeedback 1.2 - Local File Inclusioncom jfeedback6.8 (v2.0)Medium
CVE-2010-1607Joomla! Component WMI 1.5.0 - Local File Inclusioncom wmi6.8 (v2.0)Medium
CVE-2010-1715Joomla! Component Online Exam 1.5.0 - Local File Inclusioncom onlineexam6.8 (v2.0)Medium
CVE-2010-1718Joomla! Component Archery Scores 1.0.6 - Local File Inclusioncom archeryscores6.8 (v2.0)Medium
CVE-2010-1719Joomla! Component MT Fire Eagle 1.2 - Local File Inclusioncom mtfireeagle6.8 (v2.0)Medium
CVE-2010-1722Joomla! Component Online Market 2.x - Local File Inclusioncom market6.8 (v2.0)Medium
CVE-2010-1723Joomla! Component iNetLanka Contact Us Draw Root Map 1.1 - Local File Inclusioncom drawroot6.8 (v2.0)Medium
CVE-2010-1979Joomla! Component Affiliate Datafeeds 880 - Local File Inclusioncom datafeeds6.8 (v2.0)Medium
CVE-2010-1981Joomla! Component Fabrik 2.0 - Local File Inclusionfabrik6.8 (v2.0)Medium
CVE-2010-2122Joomla! Component simpledownload <=0.9.5 - Arbitrary File Retrievalcom simpledownload6.8 (v2.0)Medium
CVE-2010-2507Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusioncom picasa2gallery6.8 (v2.0)Medium
CVE-2010-2680Joomla! Component jesectionfinder - Local File Inclusioncom jesectionfinder6.8 (v2.0)Medium
CVE-2010-2857Joomla! Component Music Manager - Local File Inclusioncom music6.8 (v2.0)Medium
CVE-2010-2920Joomla! Component Foobla Suggestions 1.5.1.2 - Local File Inclusioncom foobla suggestions6.8 (v2.0)Medium
CVE-2010-4617Joomla! Component JotLoader 2.2.1 - Local File Inclusioncom jotloader6.8 (v2.0)Medium
CVE-2011-2744Chyrp 2.x - Local File Inclusionchyrp6.8 (v2.0)Medium
CVE-2011-4449WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki6.8 (v2.0)Medium
CVE-2011-4452WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki6.8 (v2.0)Medium
CVE-2026-35593Trilium Notes has Local File Inclusion via upload modified file API endpointTrilium6.8 (v3.1)Medium
CVE-2026-71475Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url pathadvanced cluster management for kubernetes6.8 (v3.1)Medium
CVE-2016-6435Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusionsecure firewall management center6.5 (v3.0)Medium
CVE-2017-14537Trixbox 2.8.0 - Path Traversaltrixbox6.5 (v3.1)Medium
CVE-2018-18809TIBCO JasperReports Library - Directory Traversaljasperreports library6.5 (v3.1)Medium
CVE-2020-6950Eclipse Mojarra - Local File Readmojarra6.5 (v3.1)Medium
CVE-2021-28149Hongdian H8922 3.0.5 Devices - Local File Inclusionh8922 firmware6.5 (v3.1)Medium
CVE-2021-40651OS4Ed OpenSIS Community 8.0 - Local File Inclusionopensis6.5 (v3.1)Medium
CVE-2022-34125GLPI Activity v3.1.0 - Authenticated Local File Inclusion on Activity plugincmdb6.5 (v3.1)Medium
CVE-2022-40734Laravel Filemanager v2.5.1 - Local File Inclusionlaravel filemanager6.5 (v3.1)Medium
CVE-2024-55457MasterSAM Star Gate v11 - Local File Inclusion-6.5 (v3.1)Medium
CVE-2025-28367mojoPortal <=2.9.0.1 - Directory Traversalmojoportal6.5 (v3.1)Medium
CVE-2025-45870LogicalDOC Enterprise up to and for v9.1.1 Path Traversal Vulnerability-6.5 (v3.1)Medium
CVE-2026-11442Allegra exportReport Directory Traversal Information Disclosure VulnerabilityAllegra6.5 (v3.0)Medium
CVE-2026-14470Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base componelangflow6.5 (v3.1)Medium
CVE-2026-36227Easy Chat Server 3.1 Arbitrary Code Execution VulnerabilityEasy Chat Server 3.16.5 (v3.1)Medium
CVE-2026-46397haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0haxcms-php6.5 (v3.1)Medium
CVE-2026-52607reportico-web <= 8.1.0 Path Traversal Vulnerabilityreportico-web <= 8.1.06.5 (v3.1)Medium
CVE-2026-63667ApostropheCMS: Arbitrary file read via import-export attachment-name path traversalapostrophe6.5 (v3.1)Medium
CVE-2026-73255Mongoose: Path traversal in SSI #include directives enables arbitrary file readmongoose6.5 (v3.1)Medium
CVE-2026-73573zimbra collaboration suite Path Traversal Vulnerabilityzimbra collaboration suite6.5 (v3.1)Medium
CVE-2026-73574zimbra collaboration suite Incorrect Resource Transfer Between Spheres Vulnerabilityzimbra collaboration suite6.5 (v3.1)Medium
CVE-2026-75602OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download toolOpenList6.5 (v3.1)Medium
CVE-2026-7658Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcementlangflow6.5 (v3.1)Medium
CVE-2026-9138Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing clangflow6.5 (v3.1)Medium
CVE-2009-0932Horde/Horde Groupware - Local File Inclusionhorde6.4 (v2.0)Medium
CVE-2011-4450WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki6.4 (v2.0)Medium
CVE-2026-34371LibreChat Affected by Arbitrary File Write via execute_code Artifact Filename Traversallibrechat6.3 (v3.1)Medium
CVE-2026-39365Vite has a Path Traversal in Optimized Deps .map Handlingvite6.3 (v4.0)Medium
CVE-2026-65012InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folderInvokeAI6.3 (v4.0)Medium
CVE-2026-72814actix-web before 0.6.10 Information Disclosure via Filesactix-web6.3 (v4.0)Medium
CVE-2026-78886liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversalTREK6.3 (v4.0)Medium
CVE-2014-8727F5 BIG-IP 10.1.0 - Directory Traversalbig-ip local traffic manager6.2 (v2.0)Medium
CVE-2017-14096Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Controlsmart protection server6.1 (v3.0)Medium
CVE-2026-41363OpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image Parameteropenclaw6.0 (v4.0)Medium
CVE-2026-65698Void 1.3.4 Path Traversal via AI Agent File-Reading Toolsvoid6.0 (v4.0)Medium
CVE-2026-66004BlenderMCP Path Traversal via download_polyhaven_asset APIblender-mcp6.0 (v4.0)Medium
CVE-2026-79653Eclipse SW360 Path Traversal VulnerabilityEclipse SW3606.0 (v4.0)Medium
CVE-2026-49244SFTPGo: Path confinement bypass in public browsable share partial ZIP downloadsftpgo5.9 (v3.1)Medium
CVE-2026-82650SiYuan before v3.8.1 Path Traversal via /api/template/rendersiyuan5.9 (v4.0)Medium
CVE-2010-0467Joomla! Component CCNewsLetter - Local File Inclusioncom ccnewsletter5.8 (v3.1)Medium
CVE-2025-47423Personal Weather Station Dashboard 12 - Directory TraversalPersonal Weather Station Dashboard5.8 (v3.1)Medium
CVE-2025-1035KLog Server - Path TraversalKLog Server5.7 (v3.1)Medium
CVE-2026-40605Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion APITautulli5.7 (v4.0)Medium
CVE-2018-13980Zeta Producer Desktop CMS <14.2.1 - Local File Inclusionzeta producer5.5 (v3.1)Medium
CVE-2018-15536Responsive FileManager < 9.13.4 - Directory Traversalresponsive filemanager5.5 (v3.0)Medium
CVE-2025-13810jsnjfz WebStack-Guns KaptchaController.java renderPicture path traversalwebstack-guns5.5 (v4.0)Medium
CVE-2026-10694SourceCodester Online Food Ordering System index.php include file inclusionOnline Food Ordering System5.5 (v4.0)Medium
CVE-2026-16252Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injectionMultimedia Integrated Business Display System5.5 (v4.0)Medium
CVE-2026-18646danpros HTMLy Author Name htmly.php path traversalHTMLy5.5 (v4.0)Medium
CVE-2026-19758dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversallamp-cloud5.5 (v4.0)Medium
CVE-2026-19762DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversalTaier5.5 (v4.0)Medium
CVE-2026-19827alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversalalldata5.5 (v4.0)Medium
CVE-2026-68922MobSF: Arbitrary File Read via Path Traversal in ZIP UploadsMobile-Security-Framework-MobSF5.5 (v3.1)Medium
CVE-2026-7205duartium papers-mcp-server main.py search_papers path traversalpapers-mcp-server5.5 (v4.0)Medium
CVE-2026-7206dubydu sqlite-mcp entry.py extract_to_json sql injectionsqlite-mcp5.5 (v4.0)Medium
CVE-2026-7212edvardlindelof notes-mcp notes_mcp.py path traversalnotes-mcp5.5 (v4.0)Medium
CVE-2026-7214eghuzefa engineer-your-data server.py file_inf path traversalengineer-your-data5.5 (v4.0)Medium
CVE-2026-7217Deepractice PromptX Document File index.ts read_pdf absolute path traversalPromptX5.5 (v4.0)Medium
CVE-2026-7314eiceblue spire-doc-mcp-server base.py get_doc_path path traversalspire-doc-mcp-server5.5 (v4.0)Medium
CVE-2026-7315eiceblue spire-pdf-mcp-server PDF File server.py get_pdf_path path traversalspire-pdf-mcp-server5.5 (v4.0)Medium
CVE-2026-7319elinsky execution-system-mcp add_action Tool server.py _get_context_file_path path traversalexecution-system-mcp5.5 (v4.0)Medium
CVE-2026-81486bsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversalmcp-file-context-server5.5 (v4.0)Medium
CVE-2026-81491boxpositron with-context-mcp index.ts project_folder path traversalwith-context-mcp5.5 (v4.0)Medium
CVE-2026-84441Piwigo Image Derivative i.php path traversalPiwigo5.5 (v4.0)Medium
CVE-2023-2745WordPress Core <=6.2 - Directory TraversalWordPress5.4 (v3.1)Medium
CVE-2026-17621Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base componelangflow5.4 (v3.1)Medium
CVE-2026-7869Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcementlangflow5.4 (v3.1)Medium
CVE-2014-8676SO Planning 1.32 - Multiple Vulnerabilitiessoplanning5.3 (v3.0)Medium
CVE-2014-9609Netsweeper 4.0.8 - Directory Traversalnetsweeper5.3 (v3.1)Medium
CVE-2020-11798Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversalmicollab audio, web &amp; video conferencing5.3 (v3.1)Medium
CVE-2020-13886Intelbras TIP 200/200 LITE/300 - Local File Inclusiontip200 firmware5.3 (v3.1)Medium
CVE-2021-28377Joomla! ChronoForums 2.0.11 - Local File Inclusionchronoforums5.3 (v3.1)Medium
CVE-2022-25497Cuppa CMS v1.0 - Local File Inclusioncuppacms5.3 (v3.1)Medium
CVE-2022-31062GLPI Glpiinventory v1.0.1 - Unauthenticated Local File Inclusionglpi inventory5.3 (v3.1)Medium
CVE-2023-2059DedeCMS 5.7.87 - Directory Traversaldedecms5.3 (v3.1)Medium
CVE-2023-30943Moodle - Cross-Site Scripting/Remote Code Executionmoodle5.3 (v3.1)Medium
CVE-2023-41599JFinalCMS v5.0.0 - Directory Traversaljfinalcms5.3 (v3.1)Medium
CVE-2024-53586WebFileSys 2.31.0 - Directory Path Traversal-5.3 (v3.1)Medium
CVE-2024-7928FastAdmin < V1.3.4.20220530 - Path Traversalfastadmin5.3 (v4.0)Medium
CVE-2025-4078Wangshen SecGate 3600 Path Traversal VulnerabilitySecGate 36005.3 (v4.0)Medium
CVE-2026-15932Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path TraversalSupport Genix5.3 (v3.1)Medium
CVE-2026-16531Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servletRed Hat Enterprise Linux 105.3 (v3.1)Medium
CVE-2026-34523SillyTavern: Path traversal allows file existence oraclesillytavern5.3 (v3.1)Medium
CVE-2026-34967Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Writeadminer5.3 (v4.0)Medium
CVE-2026-36726bookcars v8.3 Path Traversal Vulnerabilitybookcars v8.35.3 (v3.1)Medium
CVE-2026-53452Ground Station: Unauthenticated out-of-containment file read via sigmfplayback recordingPathground-station5.3 (v3.1)Medium
CVE-2026-73244kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listingkkFileView5.3 (v3.1)Medium
CVE-2026-76614OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restoreopenemr5.3 (v4.0)Medium
CVE-2026-19761DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename path traversalTaier5.1 (v4.0)Medium
CVE-2026-19763DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversalTaier5.1 (v4.0)Medium
CVE-2026-82112houtini-ai houtini-lm code_task_files index.ts path traversalhoutini-lm5.1 (v4.0)Medium
CVE-2007-4504Joomla! RSfiles <=1.0.2 - Local File Inclusionrsfiles5.0 (v2.0)Medium
CVE-2008-4764Joomla! <=2.0.0 RC2 - Local File Inclusioncom extplorer5.0 (v2.0)Medium
CVE-2008-6080Joomla! ionFiles 4.4.2 - Local File Inclusioncom ionfiles5.0 (v2.0)Medium
CVE-2008-6222Joomla! ProDesk 1.0/1.2 - Local File Inclusionpro desk support center5.0 (v2.0)Medium
CVE-2008-6668nweb2fax <=0.2.7 - Local File Inclusionnweb2fax5.0 (v2.0)Medium
CVE-2009-1496Joomla! Cmimarketplace 0.1 - Local File InclusionJoomla!5.0 (v2.0)Medium
CVE-2009-2100Joomla! JoomlaPraise Projectfork 2.0.10 - Local File InclusionJoomla!5.0 (v2.0)Medium
CVE-2009-5114WebGlimpse 2.18.7 - Directory Traversalwebglimpse5.0 (v2.0)Medium
CVE-2010-0696Joomla! Component Jw_allVideos - Arbitrary File Retrievaljw allvideos5.0 (v2.0)Medium
CVE-2010-0942Joomla! Component com_jvideodirect - Directory Traversalcom jvideodirect5.0 (v2.0)Medium
CVE-2010-0943Joomla! Component com_jashowcase - Directory Traversalcom jashowcase5.0 (v2.0)Medium
CVE-2010-0944Joomla! Component com_jcollection - Directory Traversalcom jcollection5.0 (v2.0)Medium
CVE-2010-1081Joomla! Component com_communitypolls 1.5.2 - Local File Inclusioncom communitypolls5.0 (v2.0)Medium
CVE-2010-1302Joomla! Component DW Graph - Local File Inclusioncom dwgraphs5.0 (v2.0)Medium
CVE-2010-1304Joomla! Component User Status - Local File Inclusioncom userstatus5.0 (v2.0)Medium
CVE-2010-1305Joomla! Component JInventory 1.23.02 - Local File Inclusioncom jinventory5.0 (v2.0)Medium
CVE-2010-1307Joomla! Component Magic Updater - Local File Inclusioncom joomlaupdater5.0 (v2.0)Medium
CVE-2010-1308Joomla! Component SVMap 1.1.1 - Local File Inclusioncom svmap5.0 (v2.0)Medium
CVE-2010-1312Joomla! Component News Portal 1.5.x - Local File Inclusioncom news portal5.0 (v2.0)Medium
CVE-2010-1314Joomla! Component Highslide 1.5 - Local File Inclusioncom hsconfig5.0 (v2.0)Medium
CVE-2010-1315Joomla! Component webERPcustomer - Local File Inclusioncom weberpcustomer5.0 (v2.0)Medium
CVE-2010-1340Joomla! Component com_jresearch - 'Controller' Local File Inclusioncom jresearch5.0 (v2.0)Medium
CVE-2010-1345Joomla! Component Cookex Agency CKForms - Local File Inclusioncom ckforms5.0 (v2.0)Medium
CVE-2010-1352Joomla! Component Juke Box 1.7 - Local File Inclusioncom jukebox5.0 (v2.0)Medium
CVE-2010-1353Joomla! Component LoginBox - Local File Inclusioncom loginbox5.0 (v2.0)Medium
CVE-2010-1354Joomla! Component VJDEO 1.0 - Local File Inclusioncom vjdeo5.0 (v2.0)Medium
CVE-2010-1461Joomla! Component Photo Battle 1.0.1 - Local File Inclusioncom photobattle5.0 (v2.0)Medium
CVE-2010-1491Joomla! Component MMS Blog 2.3.0 - Local File Inclusioncom mmsblog5.0 (v2.0)Medium
CVE-2010-1494Joomla! Component AWDwall 1.5.4 - Local File Inclusioncom awdwall5.0 (v2.0)Medium
CVE-2010-1532Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusioncom powermail5.0 (v2.0)Medium
CVE-2010-1534Joomla! Component Shoutbox Pro - Local File Inclusioncom shoutbox5.0 (v2.0)Medium
CVE-2010-1540Joomla! Component com_blog - Directory Traversalcom myblog5.0 (v2.0)Medium
CVE-2010-1601Joomla! Component JA Comment - Local File Inclusioncom jacomment5.0 (v2.0)Medium
CVE-2010-1657Joomla! Component SmartSite 1.0.0 - Local File Inclusioncom smartsite5.0 (v2.0)Medium
CVE-2010-1658Joomla! Component NoticeBoard 1.3 - Local File Inclusioncom noticeboard5.0 (v2.0)Medium
CVE-2010-1659Joomla! Component Ultimate Portfolio 1.0 - Local File Inclusioncom ultimateportfolio5.0 (v2.0)Medium
CVE-2010-1714Joomla! Component Arcade Games 1.0 - Local File Inclusioncom arcadegames5.0 (v2.0)Medium
CVE-2010-1858Joomla! Component SMEStorage - Local File Inclusioncom smestorage5.0 (v2.0)Medium
CVE-2010-1982Joomla! Component JA Voice 2.0 - Local File Inclusioncom javoice5.0 (v2.0)Medium
CVE-2010-2018Lokomedia CMS - Local File Inclusionlokomedia cms5.0 (v2.0)Medium
CVE-2010-3203Joomla! Component PicSell 1.0 - Arbitrary File Retrievalcom picsell5.0 (v2.0)Medium
CVE-2011-0049Majordomo2 - SMTP/HTTP Directory Traversalmajordomo 25.0 (v2.0)Medium
CVE-2011-1669WP Custom Pages 0.5.0.1 - Local File Inclusion (LFI)wp custom pages5.0 (v2.0)Medium
CVE-2011-2780Chyrp 2.x - Local File Inclusionchyrp5.0 (v2.0)Medium
CVE-2011-4804Joomla! Component com_kp - 'Controller' Local File Inclusioncom obsuggest5.0 (v2.0)Medium
CVE-2012-0981phpShowtime 2.0 - Directory Traversalphpshowtime5.0 (v2.0)Medium
CVE-2012-099611in1 CMS 1.2.1 - Local File Inclusion (LFI)11in15.0 (v2.0)Medium
CVE-2013-5979Xibo 1.2.2/1.4.1 - Directory Traversalxibo5.0 (v2.0)Medium
CVE-2013-7091Zimbra Collaboration Server 7.2.2/8.0.2 Local File Inclusionzimbra collaboration suite5.0 (v2.0)Medium
CVE-2013-7240WordPress Plugin Advanced Dewplayer 1.2 - Directory Traversaladvanced dewplayer5.0 (v2.0)Medium
CVE-2014-4940WordPress Plugin Tera Charts - Local File Inclusiontera-charts5.0 (v2.0)Medium
CVE-2014-5111Fonality trixbox - Local File Inclusiontrixbox5.0 (v2.0)Medium
CVE-2014-5187Tom M8te (tom-m8te) Plugin 1.5.3 - Directory Traversaltom-m8te plugin5.0 (v2.0)Medium
CVE-2014-5368WordPress Plugin WP Content Source Control - Directory Traversalwp content source control5.0 (v2.0)Medium
CVE-2014-6308Osclass Security Advisory 3.4.1 - Local File Inclusionosclass5.0 (v2.0)Medium
CVE-2014-8799WordPress Plugin DukaPress 2.5.2 - Directory Traversaldukapress5.0 (v2.0)Medium
CVE-2014-9119WordPress DB Backup <=4.5 - Local File Inclusiondb backup5.0 (v2.0)Medium
CVE-2015-2067Magento Server MAGMI - Directory Traversalmagmi5.0 (v2.0)Medium
CVE-2015-3897Bonita BPM Portal <6.5.3 - Local File Inclusionbonita bpm portal5.0 (v2.0)Medium
CVE-2015-4414WordPress SE HTML5 Album Audio Player 1.1.0 - Directory Traversalse html5 album audio player5.0 (v2.0)Medium
CVE-2026-16955AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio TranscriptionAI Engine5.0 (v3.1)Medium
CVE-2019-2588Oracle Business Intelligence - Path Traversalbusiness intelligence publisher4.9 (v3.0)Medium
CVE-2025-15673Import and export users and customers < 2.4.3 - Admin+ Arbitrary File ReadImport and export users and customers4.9 (v3.1)Medium
CVE-2026-52832Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard containernuclio4.9 (v3.1)Medium
CVE-2026-53594FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Pathfreescout4.9 (v3.1)Medium
CVE-2008-5587phpPgAdmin <=4.2.1 - Local File Inclusionphppgadmin4.3 (v2.0)Medium
CVE-2010-0982Joomla! Component com_cartweberp - Local File Inclusioncom cartweberp4.3 (v2.0)Medium
CVE-2010-1217Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusionje form creator4.3 (v2.0)Medium
CVE-2010-1313Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusioncom sebercart4.3 (v2.0)Medium
CVE-2010-5278MODx manager - Local File Inclusionmodx revolution4.3 (v2.0)Medium
CVE-2011-4451WikkaWiki 1.3.2 - Multiple Vulnerabilitieswikkawiki4.3 (v2.0)Medium
CVE-2012-4253MySQLDumper 1.24.4 - Directory Traversalmysqldumper4.3 (v2.0)Medium
CVE-2014-9146Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms4.3 (v2.0)Medium
CVE-2018-18777Microstrategy Web 7 - Local File Inclusionmicrostrategy web4.3 (v3.0)Medium
CVE-2022-0377WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaminglearnpress4.3 (v3.1)Medium
CVE-2024-7631Openshift-console: openshift console: path traversalRed Hat OpenShift Container Platform 3.114.3 (v3.1)Medium
CVE-2026-26477dokuwiki Denial of Service Vulnerabilitydokuwiki4.3 (v3.1)Medium
CVE-2026-55495Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Accountcloudreve4.3 (v3.1)Medium
CVE-2011-4640WebTitan < 3.60 - Local File Inclusionwebtitan4.0 (v2.0)Medium
CVE-2014-1222Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesvtiger crm4.0 (v2.0)Medium
CVE-2014-5258webEdition 6.3.8.0 - Directory Traversalwebedition cms4.0 (v2.0)Medium
CVE-2012-0991OpenEMR 4.1 - Local File Inclusionopenemr3.5 (v2.0)Low
CVE-2026-55825Contao: Possible path traversal in job download URIscontao3.1 (v3.1)Low
CVE-2024-55550Mitel MiCollab - Arbitary File Readcmg suite2.7 (v3.1)Low
CVE-2026-16434Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypassadminer2.3 (v4.0)Low
CVE-2025-13816moxi159753 Mogu Blog v2 ZIP File unzipFile FileOperation.unzip path traversalmogublog2.1 (v4.0)Low
CVE-2025-13875Yohann0617 oci-helper OCI Configuration Upload OciServiceImpl.java addCfg path traversaloci-helper2.1 (v4.0)Low
CVE-2026-10213AstrBotDevs AstrBot API Endpoint delete path traversalAstrBot2.1 (v4.0)Low
CVE-2026-10278ishayoyo excel-mcp read_file/write_file index.ts path traversalexcel-mcp2.1 (v4.0)Low
CVE-2026-10559SourceCodester Pizzafy Ecommerce System index.php file inclusionPizzafy Ecommerce System2.1 (v4.0)Low
CVE-2026-11467jishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadService.java path traversaljshERP2.1 (v4.0)Low
CVE-2026-18959yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversalInnoShop2.1 (v4.0)Low
CVE-2026-19756Dromara lamp-cloud Code Generator DefGenProjectController.java path traversallamp-cloud2.1 (v4.0)Low
CVE-2026-19828648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversalwvp-GB28181-pro2.1 (v4.0)Low
CVE-2026-76576yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversalRuoYi-Vue2.1 (v4.0)Low
CVE-2026-81845arben-adm mcp-sequential-thinking Import Session/Export Session server.py export_session path traversalmcp-sequential-thinking2.1 (v4.0)Low
CVE-2026-82599SeaCMS Avatar Upload member.php unlink path traversalSeaCMS2.1 (v4.0)Low
CVE-2026-82603SeaCMS Comment Cache member.php del_pl path traversalSeaCMS2.1 (v4.0)Low
CVE-2026-82656Admidio before 5.0.12 Path Traversal via Photo ZIP Downloadadmidio2.1 (v4.0)Low
CVE-2026-9473c-rick jimeng-mcp api.ts generateVideo path traversaljimeng-mcp2.1 (v4.0)Low
CVE-2026-12211Intelbras iNVU 7016 FT Web syslog path traversaliNVU 7016 FT2.0 (v4.0)Low
CVE-2026-16088halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversalhalo2.0 (v4.0)Low
CVE-2026-78435Faveo Helpdesk Logo SettingsController.php unlink path traversalHelpdesk2.0 (v4.0)Low
CVE-2026-81847MAA-AI MaaMCP pipeline_tools.py load_pipeline path traversalMaaMCP2.0 (v4.0)Low

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-20CVE-2009-0545 , CVE-2010-4239 , CVE-2021-21978 , CVE-2026-44343 , CVE-2026-50553 , CVE-2026-16434
CWE-22CVE-2010-5286 , CVE-2025-34040 , CVE-2025-55169 , CVE-2026-22557 , CVE-2026-58192 , CVE-2010-2861 , CVE-2018-12031 , CVE-2018-13379 , CVE-2018-16283 , CVE-2019-9618 , CVE-2022-1390 , CVE-2022-1391 , CVE-2022-32409 , CVE-2022-37042 , CVE-2022-41840 , CVE-2022-47945 , CVE-2023-32563 , CVE-2023-47246 , CVE-2025-2505 , CVE-2026-35471 , CVE-2026-75337 , CVE-2026-25895 , CVE-2026-11419 , CVE-2026-72850 , CVE-2026-77086 , CVE-2019-25727 , CVE-2026-45668 , CVE-2026-47669 , CVE-2026-47754 , CVE-2026-53976 , CVE-2026-65700 , CVE-2026-65701 , CVE-2026-69110 , CVE-2026-74798 , CVE-2026-80104 , CVE-2018-19365 , CVE-2022-26960 , CVE-2024-40422 , CVE-2024-53537 , CVE-2026-34745 , CVE-2026-47731 , CVE-2026-48024 , CVE-2026-52610 , CVE-2008-4668 , CVE-2026-53581 , CVE-2020-8641 , CVE-2026-34524 , CVE-2026-36723 , CVE-2026-42605 , CVE-2026-43624 , CVE-2026-44829 , CVE-2026-62677 , CVE-2026-65702 , CVE-2026-76842 , CVE-2026-81730 , CVE-2026-82286 , CVE-2026-84889 , CVE-2026-85199 , CVE-2026-86542 , CVE-2026-86775 , CVE-2017-20248 , CVE-2017-20250 , CVE-2018-25374 , CVE-2021-47795 , CVE-2025-34045 , CVE-2026-10108 , CVE-2026-17524 , CVE-2026-25559 , CVE-2026-35214 , CVE-2026-39352 , CVE-2026-43982 , CVE-2026-47394 , CVE-2026-47659 , CVE-2026-47661 , CVE-2026-57863 , CVE-2026-64838 , CVE-2026-65694 , CVE-2026-65919 , CVE-2026-67200 , CVE-2026-67281 , CVE-2026-69089 , CVE-2026-69095 , CVE-2026-72713 , CVE-2026-75482 , CVE-2026-75914 , CVE-2026-85685 , CVE-2015-4694 , CVE-2022-24900 , CVE-2024-48766 , CVE-2025-27222 , CVE-2026-46491 , CVE-2026-50553 , CVE-2025-34023 , CVE-2026-73079 , CVE-2026-75855 , CVE-2024-35219 , CVE-2026-48105 , CVE-2026-69086 , CVE-2026-75842 , CVE-2026-82673 , CVE-2025-44137 , CVE-2026-40075 , CVE-2026-45711 , CVE-2026-48126 , CVE-2026-74907 , CVE-2025-2636 , CVE-2026-19303 , CVE-2026-33236 , CVE-2026-34522 , CVE-2026-46484 , CVE-2026-54083 , CVE-2026-64679 , CVE-2026-73659 , CVE-2011-3315 , CVE-2026-65600 , CVE-2026-67309 , CVE-2020-35749 , CVE-2021-21234 , CVE-2026-47179 , CVE-2026-53553 , CVE-2026-54910 , CVE-2026-73498 , CVE-2026-8183 , CVE-2026-39369 , CVE-2009-1479 , CVE-2009-2015 , CVE-2009-3318 , CVE-2009-4202 , CVE-2009-4679 , CVE-2010-0157 , CVE-2010-0972 , CVE-2010-0985 , CVE-2010-1306 , CVE-2010-1470 , CVE-2010-1471 , CVE-2010-1472 , CVE-2010-1495 , CVE-2010-1531 , CVE-2010-1533 , CVE-2010-1535 , CVE-2010-1602 , CVE-2010-1603 , CVE-2010-1653 , CVE-2010-1717 , CVE-2010-1875 , CVE-2010-1878 , CVE-2010-1952 , CVE-2010-1953 , CVE-2010-1954 , CVE-2010-1955 , CVE-2010-1956 , CVE-2010-1957 , CVE-2010-1977 , CVE-2010-1980 , CVE-2010-1983 , CVE-2010-2033 , CVE-2010-2034 , CVE-2010-2035 , CVE-2010-2036 , CVE-2010-2037 , CVE-2010-2045 , CVE-2010-2050 , CVE-2010-2128 , CVE-2010-2259 , CVE-2010-2682 , CVE-2010-3426 , CVE-2010-4282 , CVE-2010-4719 , CVE-2010-4769 , CVE-2012-1226 , CVE-2014-10037 , CVE-2015-1503 , CVE-2015-3648 , CVE-2015-9406 , CVE-2016-10924 , CVE-2016-2389 , CVE-2017-11512 , CVE-2017-15363 , CVE-2017-9833 , CVE-2018-14912 , CVE-2018-14918 , CVE-2018-15138 , CVE-2018-15535 , CVE-2018-15745 , CVE-2018-16299 , CVE-2018-19753 , CVE-2018-20463 , CVE-2018-20470 , CVE-2018-9205 , CVE-2019-12593 , CVE-2019-14205 , CVE-2019-14206 , CVE-2019-17538 , CVE-2019-19731 , CVE-2019-7254 , CVE-2019-9922 , CVE-2020-13158 , CVE-2020-35598 , CVE-2020-8209 , CVE-2020-8982 , CVE-2021-20123 , CVE-2021-24644 , CVE-2021-33807 , CVE-2021-35250 , CVE-2021-35380 , CVE-2021-39316 , CVE-2021-40661 , CVE-2021-41291 , CVE-2021-43778 , CVE-2021-46417 , CVE-2022-1119 , CVE-2022-23347 , CVE-2022-29298 , CVE-2022-34127 , CVE-2022-37122 , CVE-2023-27639 , CVE-2023-27640 , CVE-2023-29887 , CVE-2023-33510 , CVE-2023-38950 , CVE-2023-40279 , CVE-2023-40924 , CVE-2023-6023 , CVE-2024-1483 , CVE-2024-28995 , CVE-2024-2928 , CVE-2024-3848 , CVE-2024-45241 , CVE-2024-9362 , CVE-2024-9935 , CVE-2025-13339 , CVE-2025-13801 , CVE-2025-25231 , CVE-2025-31131 , CVE-2025-45145 , CVE-2025-57231 , CVE-2025-66744 , CVE-2025-69411 , CVE-2026-32820 , CVE-2026-36851 , CVE-2026-39359 , CVE-2026-39847 , CVE-2026-50776 , CVE-2026-5487 , CVE-2026-5491 , CVE-2026-55552 , CVE-2026-61891 , CVE-2026-71209 , CVE-2026-75328 , CVE-2026-75333 , CVE-2026-79407 , CVE-2026-18274 , CVE-2026-20297 , CVE-2026-34968 , CVE-2026-35174 , CVE-2018-25393 , CVE-2018-25421 , CVE-2019-10717 , CVE-2026-40526 , CVE-2026-46555 , CVE-2026-47735 , CVE-2026-81030 , CVE-2026-82877 , CVE-2026-88938 , CVE-2026-40506 , CVE-2026-73033 , CVE-2026-74038 , CVE-2022-50956 , CVE-2026-45731 , CVE-2026-45774 , CVE-2026-46337 , CVE-2026-71932 , CVE-2026-74235 , CVE-2026-75592 , CVE-2026-79743 , CVE-2026-79773 , CVE-2026-79781 , CVE-2026-82233 , CVE-2026-88940 , CVE-2008-2650 , CVE-2008-6172 , CVE-2009-3053 , CVE-2010-1056 , CVE-2010-1219 , CVE-2010-1469 , CVE-2010-1473 , CVE-2010-1474 , CVE-2010-1475 , CVE-2010-1476 , CVE-2010-1478 , CVE-2010-1607 , CVE-2010-1715 , CVE-2010-1718 , CVE-2010-1719 , CVE-2010-1722 , CVE-2010-1723 , CVE-2010-1979 , CVE-2010-1981 , CVE-2010-2122 , CVE-2010-2507 , CVE-2010-2680 , CVE-2010-2857 , CVE-2010-2920 , CVE-2010-4617 , CVE-2011-2744 , CVE-2026-35593 , CVE-2026-71475 , CVE-2017-14537 , CVE-2018-18809 , CVE-2020-6950 , CVE-2021-28149 , CVE-2021-40651 , CVE-2022-40734 , CVE-2024-55457 , CVE-2025-45870 , CVE-2026-11442 , CVE-2026-14470 , CVE-2026-36227 , CVE-2026-46397 , CVE-2026-52607 , CVE-2026-63667 , CVE-2026-73255 , CVE-2026-75602 , CVE-2026-7658 , CVE-2026-9138 , CVE-2009-0932 , CVE-2011-4450 , CVE-2026-34371 , CVE-2026-39365 , CVE-2026-72814 , CVE-2026-78886 , CVE-2014-8727 , CVE-2026-41363 , CVE-2026-65698 , CVE-2026-66004 , CVE-2026-79653 , CVE-2026-49244 , CVE-2010-0467 , CVE-2025-1035 , CVE-2026-40605 , CVE-2018-13980 , CVE-2018-15536 , CVE-2025-13810 , CVE-2026-18646 , CVE-2026-19758 , CVE-2026-19762 , CVE-2026-19827 , CVE-2026-68922 , CVE-2026-7205 , CVE-2026-7212 , CVE-2026-7214 , CVE-2026-7217 , CVE-2026-7314 , CVE-2026-7315 , CVE-2026-7319 , CVE-2026-81486 , CVE-2026-81491 , CVE-2026-84441 , CVE-2023-2745 , CVE-2026-17621 , CVE-2026-7869 , CVE-2014-8676 , CVE-2014-9609 , CVE-2020-11798 , CVE-2020-13886 , CVE-2021-28377 , CVE-2022-31062 , CVE-2023-41599 , CVE-2024-53586 , CVE-2024-7928 , CVE-2025-4078 , CVE-2026-15932 , CVE-2026-16531 , CVE-2026-34523 , CVE-2026-36726 , CVE-2026-53452 , CVE-2026-73244 , CVE-2026-76614 , CVE-2026-19761 , CVE-2026-19763 , CVE-2026-82112 , CVE-2008-4764 , CVE-2008-6080 , CVE-2008-6222 , CVE-2008-6668 , CVE-2009-1496 , CVE-2009-2100 , CVE-2009-5114 , CVE-2010-0696 , CVE-2010-0942 , CVE-2010-0943 , CVE-2010-0944 , CVE-2010-1081 , CVE-2010-1302 , CVE-2010-1304 , CVE-2010-1305 , CVE-2010-1307 , CVE-2010-1308 , CVE-2010-1312 , CVE-2010-1314 , CVE-2010-1315 , CVE-2010-1340 , CVE-2010-1345 , CVE-2010-1352 , CVE-2010-1353 , CVE-2010-1354 , CVE-2010-1461 , CVE-2010-1491 , CVE-2010-1494 , CVE-2010-1532 , CVE-2010-1534 , CVE-2010-1540 , CVE-2010-1601 , CVE-2010-1657 , CVE-2010-1658 , CVE-2010-1659 , CVE-2010-1714 , CVE-2010-1858 , CVE-2010-1982 , CVE-2010-2018 , CVE-2010-3203 , CVE-2011-0049 , CVE-2011-1669 , CVE-2011-2780 , CVE-2011-4804 , CVE-2012-0981 , CVE-2012-0996 , CVE-2013-5979 , CVE-2013-7091 , CVE-2013-7240 , CVE-2014-4940 , CVE-2014-5111 , CVE-2014-5187 , CVE-2014-5368 , CVE-2014-6308 , CVE-2014-8799 , CVE-2014-9119 , CVE-2015-2067 , CVE-2015-3897 , CVE-2015-4414 , CVE-2026-16955 , CVE-2025-15673 , CVE-2026-52832 , CVE-2026-53594 , CVE-2008-5587 , CVE-2010-0982 , CVE-2010-1217 , CVE-2010-1313 , CVE-2010-5278 , CVE-2012-4253 , CVE-2018-18777 , CVE-2024-7631 , CVE-2026-55495 , CVE-2011-4640 , CVE-2014-1222 , CVE-2014-5258 , CVE-2012-0991 , CVE-2026-55825 , CVE-2024-55550 , CVE-2025-13816 , CVE-2025-13875 , CVE-2026-10213 , CVE-2026-10278 , CVE-2026-11467 , CVE-2026-18959 , CVE-2026-19756 , CVE-2026-19828 , CVE-2026-76576 , CVE-2026-81845 , CVE-2026-82599 , CVE-2026-82603 , CVE-2026-82656 , CVE-2026-9473 , CVE-2026-12211 , CVE-2026-16088 , CVE-2026-78435 , CVE-2026-81847
CWE-23CVE-2021-40870 , CVE-2023-34990 , CVE-2025-55748 , CVE-2026-23734 , CVE-2026-85199 , CVE-2026-48126 , CVE-2026-54910 , CVE-2023-2356
CWE-24CVE-2026-73573 , CVE-2025-47423
CWE-28CVE-2023-2059
CWE-29CVE-2024-34470 , CVE-2023-6023 , CVE-2024-2928 , CVE-2024-3848
CWE-35CVE-2025-27222
CWE-36CVE-2026-61891 , CVE-2026-7217
CWE-59CVE-2026-44881
CWE-73CVE-2026-58192 , CVE-2018-17246 , CVE-2025-71334 , CVE-2026-86189 , CVE-2026-48162 , CVE-2026-53581 , CVE-2025-71324 , CVE-2026-62865 , CVE-2022-24900 , CVE-2026-34522 , CVE-2026-53580 , CVE-2026-64679 , CVE-2026-35174 , CVE-2026-85160 , CVE-2026-75830 , CVE-2026-76210 , CVE-2026-54134 , CVE-2026-35593 , CVE-2026-46397 , CVE-2026-75602 , CVE-2026-79653 , CVE-2026-40605 , CVE-2026-10694 , CVE-2023-30943 , CVE-2026-34967 , CVE-2026-10559
CWE-74CVE-2017-14094 , CVE-2020-17496 , CVE-2026-16252 , CVE-2026-7206
CWE-78CVE-2017-14094 , CVE-2023-40504 , CVE-2026-25855
CWE-79CVE-2026-45668 , CVE-2017-14096 , CVE-2014-9146
CWE-89CVE-2010-4977 , CVE-2010-5028 , CVE-2011-4448 , CVE-2014-9145 , CVE-2026-16252 , CVE-2026-7206
CWE-93CVE-2026-39394
CWE-94CVE-2025-49132 , CVE-2023-34990 , CVE-2026-25856 , CVE-2008-1059 , CVE-2010-2918
CWE-98CVE-2026-87927 , CVE-2017-14095 , CVE-2026-44239 , CVE-2026-39387 , CVE-2019-25760 , CVE-2022-50954
CWE-180CVE-2026-39364
CWE-200CVE-2026-51027 , CVE-2026-65760 , CVE-2026-47394 , CVE-2026-62865 , CVE-2024-21136 , CVE-2026-44881 , CVE-2026-39363 , CVE-2026-53553 , CVE-2014-9147 , CVE-2018-6008 , CVE-2021-24227 , CVE-2021-43287 , CVE-2024-46938 , CVE-2026-61891 , CVE-2026-47735 , CVE-2016-6435 , CVE-2022-34125 , CVE-2026-53452
CWE-203CVE-2022-34125
CWE-206CVE-2026-85199
CWE-284CVE-2014-9148 , CVE-2026-65760 , CVE-2026-65759 , CVE-2023-26360 , CVE-2026-39364 , CVE-2025-28367
CWE-285CVE-2017-11398 , CVE-2026-46484
CWE-287CVE-2025-55169 , CVE-2021-25281 , CVE-2018-12613
CWE-306CVE-2026-25895 , CVE-2026-89250 , CVE-2026-39363 , CVE-2026-61891 , CVE-2026-46555 , CVE-2026-65012
CWE-327CVE-2022-0377
CWE-345CVE-2026-48105
CWE-346CVE-2026-46555
CWE-352CVE-2011-4452
CWE-400CVE-2026-53580 , CVE-2026-26477
CWE-434CVE-2025-34040 , CVE-2015-4455 , CVE-2026-11419 , CVE-2026-35174
CWE-441CVE-2026-73079
CWE-472CVE-2026-39364
CWE-502CVE-2020-10189
CWE-534CVE-2017-11398
CWE-552CVE-2026-53580 , CVE-2021-39316 , CVE-2022-26271 , CVE-2025-11371 , CVE-2022-25497
CWE-610CVE-2022-27593 , CVE-2023-30943
CWE-644CVE-2026-48126
CWE-668CVE-2022-24900 , CVE-2023-33510 , CVE-2026-82650
CWE-669CVE-2026-73574
CWE-698CVE-2024-48766
CWE-732CVE-2018-14916
CWE-770CVE-2026-26477
CWE-824CVE-2026-67281
CWE-829CVE-2018-17246 , CVE-2026-45711 , CVE-2017-14095 , CVE-2022-25485 , CVE-2022-25486 , CVE-2022-34121
CWE-862CVE-2021-21978 , CVE-2022-36642 , CVE-2026-47754 , CVE-2026-47394
CWE-913CVE-2026-48105
CWE-918CVE-2026-47659 , CVE-2022-41412 , CVE-2021-40822 , CVE-2026-47735
CWE-1220CVE-2026-39363

Documentation Source

  • Original wiki page: WAF 340007
  • Source revision: 705
  • Source revision date: 2009-11-26