On this page

Atomicorp WAF Rule 390709

Rule Summary

Description

This rule detects when a protected file is accessed remotely. This rule specifically protects sensitive OS and application configuration files, such as webserver configuration files, operating system configuration files, password files, and command history files.

Troubleshooting

False Positives

A false positive can occur when an application legitimately requires access to these files. The rules contain a large library of known web applications and safe methods for access these highly sensitive files, and can detect known safe methods and ignore them. However it is possible for a new or custom application to do this in an unknown manner and incorrectly trigger this rule.

It is not recommended that you disable this rule if you have a false positive. If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.

Tuning Guidance

If you know that this behavior is acceptable for your application, you can either disable the rule for the domain, or you can disable it for the application. Please see the Tuning the Atomicorp WAF Rules page for basic information.

Additional Information

Similar Rules

WAF_390719

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2009-0545ZeroShell <= 1.0beta11 Remote Code Executionzeroshell10.0 (v2.0)High
CVE-2010-5286Joomla! Component Jstore - 'Controller' Local File Inclusioncom jstore10.0 (v2.0)High
CVE-2026-51027FileThingie v.2.5.7 Information Disclosure Vulnerability-9.9 (v3.1)Critical
CVE-2010-2861Adobe ColdFusion - Directory Traversalcoldfusion9.8 (v3.1)Critical
CVE-2014-9148Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms9.8 (v3.0)Critical
CVE-2018-12031Eaton Intelligent Power Manager 1.6 - Directory Traversalintelligent power manager9.8 (v3.0)Critical
CVE-2018-16283WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusionwechat brodcast9.8 (v3.0)Critical
CVE-2018-17246Kibana - Local File Inclusionkibana9.8 (v3.0)Critical
CVE-2019-9618WordPress GraceMedia Media Player 1.0 - Local File Inclusiongracemedia media player9.8 (v3.0)Critical
CVE-2020-10148SolarWinds Orion API - Auth Bypassorion platform9.8 (v3.1)Critical
CVE-2020-17496vBulletin 5.5.4 - 5.6.2- Remote Command Executionvbulletin9.8 (v3.1)Critical
CVE-2020-29227Car Rental Management System 1.0 - Local File Inclusioncar rental management system9.8 (v3.1)Critical
CVE-2020-5902F5 BIG-IP TMUI - Remote Code Executionbig-ip access policy manager9.8 (v3.1)Critical
CVE-2021-40960Galera WebTemplate 1.0 Directory Traversalgalera webtemplate9.8 (v3.1)Critical
CVE-2022-0679WordPress Narnoo Distributor <=2.5.1 - Local File Inclusionnarnoo distributor9.8 (v3.1)Critical
CVE-2022-1390WordPress Admin Word Count Column 2.2 - Local File Inclusionadmin word count column9.8 (v3.1)Critical
CVE-2022-1391WordPress Cab fare calculator < 1.0.4 - Local File Inclusioncab fare calculator9.8 (v3.1)Critical
CVE-2022-32409Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusioni3geo9.8 (v3.1)Critical
CVE-2022-41840Welcart eCommerce <=2.7.7 - Local File Inclusionwelcart e-commerce9.8 (v3.1)Critical
CVE-2022-47615LearnPress Plugin < 4.2.0 - Local File Inclusionlearnpress9.8 (v3.1)Critical
CVE-2023-3643CAREL Boss Mini <= 1.4.0 - Local File Inclusionboss-mini9.8 (v3.1)Critical
CVE-2023-36845Juniper J-Web - Remote Code Executionjunos9.8 (v3.1)Critical
CVE-2023-5991Hotel Booking Lite < 4.8.5 - Arbitrary File Download & Deletionhotel booking lite9.8 (v3.1)Critical
CVE-2024-12209WP Umbrella Update Backup Restore & Monitoring <= 2.17.0 - Local File Inclusionwp-umbrella9.8 (v3.1)Critical
CVE-2024-51978Brother Printers – Authentication Bypass via Default Admin PasswordDCP-J928N-W/B9.8 (v3.1)Critical
CVE-2025-2294Kubio AI Page Builder <= 2.5.1 - Local File InclusionKubio AI Page Builder9.8 (v3.1)Critical
CVE-2025-4524WordPress Madara - Local File InclusionMadara – Responsive and modern WordPress theme for manga sites9.8 (v3.1)Critical
CVE-2025-47445WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Downloadeventin9.8 (v3.1)Critical
CVE-2026-35471Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshsgoshs9.8 (v3.0)Critical
CVE-2026-75337The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 Path Traversal Vulnerability-9.8 (v3.1)Critical
CVE-2026-11419Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Writeon-prem enterprise server9.4 (v4.0)Critical
CVE-2026-11423Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege EscalationAltium Enterprise Server9.4 (v4.0)Critical
CVE-2026-72850Budibase before 3.40.0 Arbitrary File Write via Path Traversalserver9.4 (v4.0)Critical
CVE-2026-77086SiYuan before v3.7.4 Path Traversal via packageNamesiyuan9.4 (v4.0)Critical
CVE-2019-25727WordPress Plugin ad manager wd 1.0.11 Arbitrary File DownloadAd Manager WD9.3 (v4.0)Critical
CVE-2026-23734XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slashxwiki-commons9.3 (v4.0)Critical
CVE-2026-44343WGDashboard < 4.3.2 - Unauthenticated File Readwgdashboard9.3 (v4.0)Critical
CVE-2026-45668Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled)Trilium9.3 (v4.0)Critical
CVE-2026-47669DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCEdbgate9.3 (v4.0)Critical
CVE-2026-47754unauthenticated path traversal in Metacat 2.xmetacat9.3 (v3.1)Critical
CVE-2026-53976OpenChamber <1.13.0 - Unauthenticated Arbitrary File ReadOpenChamber9.3 (v4.0)Critical
CVE-2026-65700h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files APIh2ogpt9.3 (v4.0)Critical
CVE-2026-65701SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Routeso-vits-svc9.3 (v4.0)Critical
CVE-2026-69110OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/musicopencode-studio9.3 (v4.0)Critical
CVE-2026-74798SiYuan kernel Path Traversal via database_clean MCP toolsiyuan9.3 (v4.0)Critical
CVE-2026-80104DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload FilenameDB-GPT9.3 (v4.0)Critical
CVE-2026-86189WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.phpAVideo9.3 (v4.0)Critical
CVE-2026-65760Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0Easy Store extension for Joomla9.2 (v4.0)Critical
CVE-2018-14916Loytec LGATE-902 <6.4.2 - Local File Inclusionlgate-9029.1 (v3.0)Critical
CVE-2018-16716NCBI ToolBox - Directory Traversalncbi toolbox9.1 (v3.0)Critical
CVE-2018-19365Wowza Streaming Engine Manager 4.7.4.01 - Directory Traversalstreaming engine9.1 (v3.1)Critical
CVE-2022-26960elFinder <=2.1.60 - Local File Inclusionelfinder9.1 (v3.1)Critical
CVE-2024-3673Web Directory Free < 1.7.3 - Local File Inclusionweb directory free9.1 (v3.1)Critical
CVE-2024-40422Devika v1 - Path Traversaldevika9.1 (v3.1)Critical
CVE-2025-55526n8n workflow collection Path Traversal Vulnerabilityn8n workflow collection9.1 (v3.1)Critical
CVE-2026-34745Unauthenticated Path Traversal Arbitrary File Write in /api/uploadChunked/publicfireshare9.1 (v3.1)Critical
CVE-2026-47731NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by uAIT-Core9.1 (v3.1)Critical
CVE-2026-48024Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh managerwazuh9.1 (v3.1)Critical
CVE-2026-48162Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file pawazuh9.1 (v3.1)Critical
CVE-2026-52610reportico-web <= 8.1.0 Path Traversal Vulnerabilityreportico-web <= 8.1.09.1 (v3.1)Critical
CVE-2008-4668Joomla! Image Browser 0.1.5 rc2 - Local File Inclusioncom imagebrowser9.0 (v2.0)High
CVE-2026-53581ntp: write path traversalcore9.0 (v3.1)Critical
CVE-2018-12613PhpMyAdmin <4.8.2 - Local File Inclusionphpmyadmin8.8 (v3.1)High
CVE-2018-15142OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actionsopenemr8.8 (v3.0)High
CVE-2019-14530OpenEMR <5.0.2 - Local File Inclusionopenemr8.8 (v3.1)High
CVE-2020-8641Lotus Core CMS 1.0.1 - Local File Inclusionlotus core cms8.8 (v3.1)High
CVE-2023-52163Digiever DS-2105 Pro - Command Injectionds-2105 pro firmware8.8 (v3.1)High
CVE-2025-32614EventON Lite <= 2.4 - Authenticated Local File Inclusionflavor8.8 (v3.1)High
CVE-2026-17623Langflow is affected OS Command Injection in Model Context Protocol featureslangflow8.8 (v3.1)High
CVE-2026-17625Langflow is affected by OS Command Injection in Model Context Protocol featureslangflow8.8 (v3.1)High
CVE-2026-34524SillyTavern: Path traversal in /api/chats/export and /api/chats/delete allows arbitrary file read/delete within usersillytavern8.8 (v3.1)High
CVE-2026-36723the /api/create-user component of bookcars v8.3 Arbitrary Code Execution Vulnerabilitythe /api/create-user component of bookcars v8.38.8 (v3.1)High
CVE-2026-42605AzuraCast: Path Traversal in currentDirectory Parameter Enables Remote Code Execution via Media Uploadazuracast8.8 (v3.1)High
CVE-2026-43624F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project()F5-TTS8.8 (v4.0)High
CVE-2026-44829Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filenamegotenberg8.8 (v3.1)High
CVE-2026-501864gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Board Export4gaBoards8.8 (v3.1)High
CVE-2026-62677Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNomnigent8.8 (v3.1)High
CVE-2026-65702Vanna 2.0.2 Path Traversal via FileSystemConversationStorevanna8.8 (v4.0)High
CVE-2026-76842Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment Clientsmercadopago8.8 (v4.0)High
CVE-2026-81730Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filenamedolibarr erp/crm8.8 (v4.0)High
CVE-2026-82286gpt-crawler Arbitrary File Write via outputFileName Parametergpt-crawler8.8 (v4.0)High
CVE-2026-85199Eclipse aeriOS Path Traversal VulnerabilityEclipse aeriOS8.8 (v4.0)High
CVE-2026-86542knowns before 0.30.0 Path Traversal via Import Nameknowns8.8 (v4.0)High
CVE-2026-86775knowns before 0.30.0 Path Traversal via Document APIknowns8.8 (v4.0)High
CVE-2026-87927MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcherMaxSite CMS8.8 (v4.0)High
CVE-2017-20248WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File DownloadApptha Slider Gallery8.7 (v4.0)High
CVE-2017-20250WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File DownloadMac Photo Gallery8.7 (v4.0)High
CVE-2018-25374Softneta MedDream PACS Server Premium 6.7.1.1 Directory TraversalMedDream PACS Server Premium8.7 (v4.0)High
CVE-2021-4463Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File DownloadBEMS API8.7 (v4.0)High
CVE-2024-26291Avid NEXIS Agent - Arbitrary File Readnexis8.7 (v4.0)High
CVE-2026-10108xiaomusic 0.5.7 Path Traversal via GET /music endpointxiaomusic8.7 (v4.0)High
CVE-2026-17524zip-lib Path Traversal Vulnerabilityzip-lib8.7 (v4.0)High
CVE-2026-25559OpenBullet2 0.3.2 Path Traversal via Wordlist Endpointopenbullet28.7 (v4.0)High
CVE-2026-25855OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Uploadopenbullet28.7 (v4.0)High
CVE-2026-25856OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interfaceopenbullet28.7 (v4.0)High
CVE-2026-35029LiteLLM - Arbitrary File Readlitellm8.7 (v4.0)High
CVE-2026-35214Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file writebudibase8.7 (v3.1)High
CVE-2026-39352Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path Traversalfrappe8.7 (v4.0)High
CVE-2026-43982Algernon: Path traversal file write via savein()algernon8.7 (v4.0)High
CVE-2026-47394PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validatePraisonAI8.7 (v4.0)High
CVE-2026-47659Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename}pathling8.7 (v4.0)High
CVE-2026-47661Pathling has path traversal in $result endpoint that allows arbitrary warehouse file readpathling8.7 (v4.0)High
CVE-2026-57863Crater Invoice 6.0.6 Path Traversal RCE via update/unzip endpointcrater8.7 (v4.0)High
CVE-2026-62865TypeBot: Arbitrary server file read via Send Email block attachment pathtypebot.io8.7 (v4.0)High
CVE-2026-65694Microweber CMS <= 2.0.20 - Unauthenticated Arbitrary File Readmicroweber8.7 (v4.0)High
CVE-2026-65759Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1Easy Store extension for Joomla8.7 (v4.0)High
CVE-2026-65919Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownloadmeshery8.7 (v4.0)High
CVE-2026-67200Perspective 5.0.0 Path Traversal via cwd_static_file_handlerperspective8.7 (v4.0)High
CVE-2026-67281Unauthenticated file read in Mikrotik RouterOSRouterOS8.7 (v4.0)High
CVE-2026-69089Grav CMS before 2.0.11 Path Traversal via watermarkgrav8.7 (v4.0)High
CVE-2026-69095OpenWrt luci-app-bmx7 Path Traversal via bmx7-infoluci8.7 (v4.0)High
CVE-2026-72713XAgent Path Traversal Arbitrary File Read via /workspace/fileXAgent8.7 (v4.0)High
CVE-2026-75111Evidently UI Path Traversal via Dataset Materialization Filenameevidently8.7 (v4.0)High
CVE-2026-75482SWE-agent Trajectory Inspector Path Traversal File DisclosureSWE-agent8.7 (v4.0)High
CVE-2026-75914CodeWhale before 0.8.64 Path Traversal via image_analyze symlinkCodeWhale8.7 (v4.0)High
CVE-2026-85685AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skillagentscope8.7 (v4.0)High
CVE-2026-86538knowns before 0.30.0 Path Traversal via templateFile parameterknowns8.7 (v4.0)High
CVE-2026-9506Path Traversal Vulnerability in BagistoBagisto8.7 (v4.0)High
CVE-2015-4694WordPress Zip Attachments <= 1.1.4 - Arbitrary File Retrievalzip attachments8.6 (v3.0)High
CVE-2021-32820Express-handlebars - Local File Inclusionexpress handlebars8.6 (v3.1)High
CVE-2022-24900Piano LED Visualizer 1.3 - Local File Inclusionpiano led visualizer8.6 (v3.1)High
CVE-2023-26360Adobe ColdFusion - Local File Readcoldfusion8.6 (v3.1)High
CVE-2024-34470HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusionmailinspector8.6 (v3.1)High
CVE-2025-2558WordPress The Wound Theme <= 0.0.1 - Local File Inclusionthe wound8.6 (v3.1)High
CVE-2026-11974Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Downloadwp-media-folder-addon8.6 (v3.1)High
CVE-2026-46491SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditisimplesamlphp-module-casserver8.6 (v3.1)High
CVE-2026-50553Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)note-mark8.6 (v4.0)High
CVE-2026-7412Eclipse BaSyx SSRF VulnerabilityEclipse BaSyx8.6 (v3.1)High
CVE-2015-2996SysAid Help Desk <15.2 - Local File Inclusionsysaid8.5 (v2.0)High
CVE-2025-34023Karel IP Phone IP1211 Web Management Panel - Local File InclusionKarel IP Phone IP12118.5 (v4.0)High
CVE-2026-16033Arbitrary file read+write on host via templates/ symlink in malicious imageLXD8.5 (v3.1)High
CVE-2026-44881Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Updateportainer8.5 (v4.0)High
CVE-2026-73079Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstreasub2api8.5 (v3.1)High
CVE-2026-75855ArcadeDB before 26.8.1 Path Traversal via create/drop databasearcadedb8.4 (v4.0)High
CVE-2026-48105Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide patharc8.3 (v4.0)High
CVE-2026-69086SiYuan before v3.7.3 Path Traversal via unvalidated avIDsiyuan8.3 (v4.0)High
CVE-2026-75842ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSVarcadedb8.3 (v4.0)High
CVE-2026-82673Path traversal in AshAdmin file uploads via unsanitized client filenameash admin8.3 (v4.0)High
CVE-2025-44137MapTiler Tileserver-php v2.0 - Unauthenticated File Readtileserver php8.2 (v3.1)High
CVE-2026-39363Vite Affected by Arbitrary File Read via Vite Dev Server WebSocketvite8.2 (v4.0)High
CVE-2026-39364Vite Dev Server - Directory Traversalvite8.2 (v4.0)High
CVE-2026-40075OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServletopenmrs8.2 (v4.0)High
CVE-2026-45711Mailpit: Path traversal & arbitrary file write in mailpit dump –http via attacker-controlled message IDsmailpit8.2 (v3.1)High
CVE-2026-48126Algernon: Host header path traversal in –domain mode reads files and runs Lua from parent diralgernon8.2 (v3.1)High
CVE-2026-74907Grav before 2.0.15 Path Traversal via plugin-asset-map.phpgrav8.2 (v4.0)High
CVE-2023-6831mlflow - Path Traversalmlflow8.1 (v3.1)High
CVE-2024-38473Apache HTTP Server - ACL BypassApache HTTP Server8.1 (v3.1)High
CVE-2025-48157WordPress Formality Plugin <= 1.5.9 - Local File InclusionFormality8.1 (v3.1)High
CVE-2026-19303Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing clangflow8.1 (v3.1)High
CVE-2026-33236NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwritenltk8.1 (v3.1)High
CVE-2026-34522SillyTavern: Path traversal in /api/chats/import allows arbitrary file write outside intended chat directorysillytavern8.1 (v3.1)High
CVE-2026-46484Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/userheadplane8.1 (v3.1)High
CVE-2026-54083Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletionwazuh8.1 (v3.1)High
CVE-2026-64679Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creationatlantis8.1 (v3.1)High
CVE-2026-73659Trigger.dev: Cross-tenant object read/write via path traversal in packet presign APItrigger.dev8.1 (v3.1)High
CVE-2009-1558Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusionwvc54gca7.8 (v2.0)High
CVE-2011-3315Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversalunified ip interactive voice response7.8 (v2.0)High
CVE-2014-2962Belkin N150 Router 1.00.08/1.00.09 - Path Traversaln150 f9k1009 firmware7.8 (v2.0)High
CVE-2022-25485Cuppa CMS v1.0 - Local File Inclusioncuppacms7.8 (v3.1)High
CVE-2022-25486Cuppa CMS v1.0 - Local File Inclusioncuppacms7.8 (v3.1)High
CVE-2026-65600Traefik before v2.11.52 Authentication Bypass via ReplacePathRegextraefik7.8 (v4.0)High
CVE-2026-67309Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypasstraefik7.8 (v4.0)High
CVE-2020-35749WordPress Simple Job Board <2.9.4 - Local File Inclusionsimple board job7.7 (v3.1)High
CVE-2021-21234Spring Boot Actuator Logview Directory Traversalspring-boot-actuator-logview7.7 (v3.1)High
CVE-2026-47179Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in Arcanearcane7.7 (v3.1)High
CVE-2026-53553Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromisegoploy7.7 (v3.1)High
CVE-2026-54910FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary filesfilebrowser7.7 (v3.1)High
CVE-2026-73498MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_atmcp-atlassian7.7 (v3.1)High
CVE-2026-8183Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcementlangflow7.7 (v3.1)High
CVE-2026-39369WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLsavideo7.6 (v3.1)High
CVE-2026-44239FreePBX: Authenticated Local File Inclusion in Dashboard Modulefreepbx7.6 (v4.0)High
CVE-2026-65695Office-Word-MCP-Server 1.1.11 Path Traversal via document toolsOffice-Word-MCP-Server7.6 (v4.0)High
CVE-2006-2842Squirrelmail <=1.4.6 - Local File Inclusionsquirrelmail7.5 (v2.0)High
CVE-2009-1479boxalino 09.05.25-0421 - Directory Traversalboxalino7.5 (v2.0)High
CVE-2009-2015Joomla! MooFAQ 1.0 - Local File InclusionJoomla!7.5 (v2.0)High
CVE-2009-3318Joomla! Roland Breedveld Album 1.14 - Local File InclusionJoomla!7.5 (v2.0)High
CVE-2009-4202Joomla! Omilen Photo Gallery 0.5b - Local File Inclusionjoomla!7.5 (v2.0)High
CVE-2009-4679Joomla! Portfolio Nexus - Remote File Inclusioncom if nexus7.5 (v2.0)High
CVE-2010-0157Joomla! Component com_biblestudy - Local File Inclusionjoomla!7.5 (v2.0)High
CVE-2010-0759Joomla! Plugin Core Design Scriptegrator - Local File Inclusionscriptegrator plugin7.5 (v2.0)High
CVE-2010-0972Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusioncom gcalendar7.5 (v2.0)High
CVE-2010-0985Joomla! Component com_abbrev - Local File Inclusioncom abbrev7.5 (v2.0)High
CVE-2010-1306Joomla! Component Picasa 2.0 - Local File Inclusioncom joomlapicasa27.5 (v2.0)High
CVE-2010-1470Joomla! Component Web TV 1.0 - Local File Inclusioncom webtv7.5 (v2.0)High
CVE-2010-1471Joomla! Component Address Book 1.5.0 - Local File Inclusioncom addressbook7.5 (v2.0)High
CVE-2010-1472Joomla! Component Horoscope 1.5.0 - Local File Inclusioncom horoscope7.5 (v2.0)High
CVE-2010-1495Joomla! Component Matamko 1.01 - Local File Inclusioncom matamko7.5 (v2.0)High
CVE-2010-1531Joomla! Component redSHOP 1.0 - Local File Inclusioncom redshop7.5 (v2.0)High
CVE-2010-1533Joomla! Component TweetLA 1.0.1 - Local File Inclusioncom tweetla7.5 (v2.0)High
CVE-2010-1535Joomla! Component TRAVELbook 1.0.1 - Local File Inclusioncom travelbook7.5 (v2.0)High
CVE-2010-1602Joomla! Component ZiMB Comment 0.8.1 - Local File Inclusioncom zimbcomment7.5 (v2.0)High
CVE-2010-1603Joomla! Component ZiMBCore 0.1 - Local File Inclusioncom zimbcore7.5 (v2.0)High
CVE-2010-1653Joomla! Component Graphics 1.0.6 - Local File Inclusioncom graphics7.5 (v2.0)High
CVE-2010-1717Joomla! Component iF surfALERT 1.2 - Local File Inclusionif surfalert7.5 (v2.0)High
CVE-2010-1875Joomla! Component Property - Local File Inclusioncom properties7.5 (v2.0)High
CVE-2010-1878Joomla! Component OrgChart 1.0.0 - Local File Inclusioncom orgchart7.5 (v2.0)High
CVE-2010-1952Joomla! Component BeeHeard 1.0 - Local File Inclusioncom beeheard7.5 (v2.0)High
CVE-2010-1953Joomla! Component iNetLanka Multiple Map 1.0 - Local File Inclusioncom multimap7.5 (v2.0)High
CVE-2010-1954Joomla! Component iNetLanka Multiple root 1.0 - Local File Inclusioncom multiroot7.5 (v2.0)High
CVE-2010-1955Joomla! Component Deluxe Blog Factory 1.1.2 - Local File Inclusioncom blogfactory7.5 (v2.0)High
CVE-2010-1956Joomla! Component Gadget Factory 1.0.0 - Local File Inclusioncom gadgetfactory7.5 (v2.0)High
CVE-2010-1957Joomla! Component Love Factory 1.3.4 - Local File Inclusioncom lovefactory7.5 (v2.0)High
CVE-2010-1977Joomla! Component J!WHMCS Integrator 1.5.0 - Local File Inclusioncom jwhmcs7.5 (v2.0)High
CVE-2010-1980Joomla! Component Joomla! Flickr 1.0 - Local File Inclusioncom joomlaflickr7.5 (v2.0)High
CVE-2010-1983Joomla! Component redTWITTER 1.0 - Local File Inclusioncom redtwitter7.5 (v2.0)High
CVE-2010-2033Joomla! Percha Categories Tree 0.6 - Local File Inclusioncom perchacategoriestree7.5 (v2.0)High
CVE-2010-2034Joomla! Component Percha Image Attach 1.1 - Directory Traversalcom perchaimageattach7.5 (v2.0)High
CVE-2010-2035Joomla! Component Percha Gallery 1.6 Beta - Directory Traversalcom perchagallery7.5 (v2.0)High
CVE-2010-2036Joomla! Component Percha Fields Attach 1.0 - Directory Traversalcom perchafieldsattach7.5 (v2.0)High
CVE-2010-2037Joomla! Component Percha Downloads Attach 1.1 - Directory Traversalcom perchadownloadsattach7.5 (v2.0)High
CVE-2010-2045Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusioncom dioneformwizard7.5 (v2.0)High
CVE-2010-2050Joomla! Component MS Comment 0.8.0b - Local File Inclusioncom mscomment7.5 (v2.0)High
CVE-2010-2128Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusioncom jequoteform7.5 (v2.0)High
CVE-2010-2259Joomla! Component com_bfsurvey - Local File Inclusioncom bfsurvey profree7.5 (v2.0)High
CVE-2010-2682Joomla! Component Realtyna Translator 1.0.15 - Local File Inclusioncom realtyna7.5 (v2.0)High
CVE-2010-2918Joomla! Component Visites 1.1 - MosConfig_absolute_path Remote File Inclusioncom joomla visites7.5 (v2.0)High
CVE-2010-3426Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusioncom jphone7.5 (v2.0)High
CVE-2010-4282Pandora Fms < 3.1.1 - Directory Traversalpandora fms7.5 (v2.0)High
CVE-2010-4719Joomla! Component JRadio - Local File Inclusioncom jradio7.5 (v2.0)High
CVE-2010-4769Joomla! Component Jimtawl 1.0.2 - Local File Inclusioncom jimtawl7.5 (v2.0)High
CVE-2010-4977Joomla! Component Canteen 1.0 - Local File Inclusioncom canteen7.5 (v2.0)High
CVE-2010-5028Joomla! Component JE Job 1.0 - Local File Inclusioncom jejob7.5 (v2.0)High
CVE-2012-1226Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilitiesdolibarr erp/crm7.5 (v2.0)High
CVE-2014-10037DomPHP 0.83 - Directory Traversaldomphp7.5 (v2.0)High
CVE-2014-9145Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms7.5 (v2.0)High
CVE-2014-9147Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms7.5 (v3.0)High
CVE-2015-1000005WordPress Candidate Application Form <= 1.3 - Local File Inclusioncandidate-application-form7.5 (v3.0)High
CVE-2015-1000010WordPress Simple Image Manipulator < 1.0 - Local File Inclusionsimple-image-manipulator7.5 (v3.0)High
CVE-2015-1000012WordPress MyPixs <=0.3 - Local File Inclusionmypixs7.5 (v3.0)High
CVE-2015-1503IceWarp Mail Server < 11.1.1 - Directory Traversalmail server7.5 (v3.0)High
CVE-2015-3648ResourceSpace - Local File inclusionresourcespace7.5 (v2.0)High
CVE-2015-4074Joomla! Helpdesk Pro plugin <1.4.0 - Local File Inclusionhelpdesk pro7.5 (v3.0)High
CVE-2015-4632Koha 3.20.1 - Directory Traversalkoha7.5 (v3.0)High
CVE-2015-5469WordPress MDC YouTube Downloader 2.1.0 - Local File Inclusionmdc youtube downloader7.5 (v3.0)High
CVE-2016-10367Opsview Monitor Pro - Local File Inclusionopsview7.5 (v3.0)High
CVE-2016-10956WordPress Mail Masta 1.0 - Local File Inclusionmail-masta7.5 (v3.1)High
CVE-2016-2389SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusionnetweaver7.5 (v3.0)High
CVE-2016-6601WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilitieswebnms framework7.5 (v3.0)High
CVE-2017-15647FiberHome Routers - Local File Inclusionrouterfiberhome firmware7.5 (v3.0)High
CVE-2017-16806Ulterius Server < 1.9.5.0 - Directory Traversalulterius server7.5 (v3.0)High
CVE-2017-16894Laravel <5.5.21 - Information Disclosurelaravel7.5 (v3.0)High
CVE-2017-9833BOA Web Server 0.94.14 - Arbitrary File Accessboa7.5 (v3.1)High
CVE-2018-12909Webgrind <= 1.5 - Local File Inclusionwebgrind7.5 (v3.0)High
CVE-2018-14912cgit < 1.2.1 - Directory Traversalcgit7.5 (v3.0)High
CVE-2018-14918LOYTEC LGATE-902 6.3.2 - Local File Inclusionlgate-902 firmware7.5 (v3.0)High
CVE-2018-15138LG-Ericsson iPECS NMS 30M - Local File Inclusionipecs nms7.5 (v3.0)High
CVE-2018-15535Responsive FileManager < 9.13.4 - Directory Traversalresponsive filemanager7.5 (v3.0)High
CVE-2018-16299WordPress Localize My Post 1.0 - Local File Inclusionlocalize my post7.5 (v3.0)High
CVE-2018-19753Tarantella Enterprise <3.11 - Local File Inclusiontarantella enterprise7.5 (v3.0)High
CVE-2018-6008Joomla! Jtag Members Directory 5.3.7 - Local File Inclusionjtag members directory7.5 (v3.0)High
CVE-2018-7422WordPress Site Editor <=1.1.1 - Local File Inclusionsite editor7.5 (v3.0)High
CVE-2018-9205Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusionavatar uploader7.5 (v3.0)High
CVE-2019-12276GrandNode 4.40 - Local File Inclusiongrandnode7.5 (v3.0)High
CVE-2019-14251T24 Web Server - Local File Inclusiont247.5 (v3.1)High
CVE-2019-16123PilusCart <=1.4.1 - Local File Inclusionpiluscart7.5 (v3.1)High
CVE-2019-18371Xiaomi Mi WiFi R3G Routers - Local file Inclusionmillet router 3g firmware7.5 (v3.1)High
CVE-2019-18665DOMOS 5.5 - Local File Inclusiondomos7.5 (v3.1)High
CVE-2019-7254eMerge E3 1.00-06 - Local File Inclusionlinear emerge essential firmware7.5 (v3.1)High
CVE-2019-9922Joomla! Harmis Messenger 1.2.2 - Local File Inclusionje messenger7.5 (v3.1)High
CVE-2020-11738WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusionduplicator7.5 (v3.1)High
CVE-2020-13158Artica Proxy Community Edition <4.30.000000 - Local File Inclusionartica proxy7.5 (v3.1)High
CVE-2020-14864Oracle Fusion - Directory Traversal/Local File Inclusionbusiness intelligence7.5 (v3.1)High
CVE-2020-17519Apache Flink - Local File Inclusionflink7.5 (v3.1)High
CVE-2020-19360FHEM 6.0 - Local File Inclusionfhem7.5 (v3.1)High
CVE-2020-24285INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusiontip2007.5 (v3.1)High
CVE-2020-27467Processwire CMS <2.7.1 - Local File Inclusionprocesswire7.5 (v3.1)High
CVE-2020-35580SearchBlox <9.2.2 - Local File Inclusionsearchblox7.5 (v3.1)High
CVE-2020-35598Advanced Comment System 1.0 - Local File Inclusionadvanced comment system7.5 (v3.1)High
CVE-2020-5410Spring Cloud Config Server - Local File Inclusionspring cloud config7.5 (v3.1)High
CVE-2020-8209Citrix XenMobile Server - Local File Inclusionxenmobile server7.5 (v3.1)High
CVE-2021-20123Draytek VigorConnect 1.6.0-B - Local File Inclusionvigorconnect7.5 (v3.1)High
CVE-2021-20124Draytek VigorConnect 6.0-B3 - Local File Inclusionvigorconnect7.5 (v3.1)High
CVE-2021-24227Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusionpatreon wordpress7.5 (v3.1)High
CVE-2021-39316WordPress DZS Zoomsounds <=6.50 - Local File Inclusionzoomsounds7.5 (v3.1)High
CVE-2021-39433BIQS IT Biqs-drive v1.83 Local File Inclusionbiqsdrive7.5 (v3.1)High
CVE-2021-41291ECOA Building Automation System - Directory Traversal Content Disclosureecs router controller-ecs firmware7.5 (v3.1)High
CVE-2021-43287Pre-Auth Takeover of Build Pipelines in GoCDgocd7.5 (v3.1)High
CVE-2021-43778GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability.barcode7.5 (v3.1)High
CVE-2021-46104webp_server_go 0.4.0 - Path Traversalwebp server go7.5 (v3.1)High
CVE-2021-46381DLINK DAP-1620 A1 v1.01 - Directory Traversaldap-1620 firmware7.5 (v3.1)High
CVE-2022-0656uDraw <3.3.3 - Local File Inclusion[web to print shop](/vendors/webtoprint/web-to-print-shop/)7.5 (v3.1)High
CVE-2022-27043Yearning - Directory Traversalyearning7.5 (v3.1)High
CVE-2022-29298SolarView Compact 6.00 - Local File Inclusionsv-cpt-mc310 firmware7.5 (v3.1)High
CVE-2022-31474BackupBuddy - Local File Inclusionbackupbuddy7.5 (v3.1)High
CVE-2022-33901WordPress MultiSafepay for WooCommerce <=4.13.1 - Arbitrary File Readmultisafepay plugin for woocommerce7.5 (v3.1)High
CVE-2022-34121CuppaCMS v1.0 - Local File Inclusioncuppacms7.5 (v3.1)High
CVE-2022-37122Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Path Traversalpcoweb hvac bacnet gateway7.5 (v3.1)High
CVE-2022-4140WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Accesswelcart e-commerce7.5 (v3.1)High
CVE-2023-23063Cellinx NVT Web Server - Local File Disclosurenvt web server7.5 (v3.1)High
CVE-2023-26256STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusionstagil navigation7.5 (v3.1)High
CVE-2023-29887Nuovo Spreadsheet Reader 0.5.11 - Local File Inclusionspreadsheet-reader7.5 (v3.1)High
CVE-2023-33510Jeecg P3 Biz Chat - Local File Inclusionjeecg p3 biz chat7.5 (v3.1)High
CVE-2023-34092Vite Dev Server - Information Exposurevite7.5 (v3.1)High
CVE-2023-38879openSIS v9.0 - Path Traversalopensis7.5 (v3.1)High
CVE-2023-40924SolarView Compact < 6.00 - Directory Traversalsolarview compact firmware7.5 (v3.1)High
CVE-2023-6023VertaAI ModelDB - Path Traversalmodeldb7.5 (v3.1)High
CVE-2023-6038H2O ImportFiles - Local File Inclusionh2o7.5 (v3.1)High
CVE-2024-12849Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Arbitrary File Readerror-log-viewer-wp7.5 (v3.1)High
CVE-2024-1483Mlflow < 2.9.2 - Path Traversalmlflow7.5 (v3.1)High
CVE-2024-27292Docassemble - Local File Inclusiondocassemble7.5 (v3.1)High
CVE-2024-2928MLflow < 2.11.3 - Path Traversalmlflow7.5 (v3.1)High
CVE-2024-36420Flowise 1.4.3 - Arbitrary File Readflowise7.5 (v3.1)High
CVE-2024-3848Mlflow < 2.11.0 - Path Traversalmlflow7.5 (v3.1)High
CVE-2024-38819Spring Framework Path Traversal in Functional Web Frameworksspring framework7.5 (v3.1)High
CVE-2024-45388Hoverfly < 1.10.3 - Arbitrary File Readhoverfly7.5 (v3.1)High
CVE-2024-46938Sitecore Experience Platform <= 10.4 - Arbitrary File Readexperience commerce7.5 (v3.1)High
CVE-2024-5334Devika - Local File Inclusiondevika7.5 (v3.0)High
CVE-2024-9362Polyaxon - Unauthenticated Directory Traversalpolyaxon/polyaxon7.5 (v3.0)High
CVE-2024-9935PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Downloadpdf-generator-addon-for-elementor-page-builder7.5 (v3.1)High
CVE-2025-13339Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File ReadHippoo Mobile App for WooCommerce7.5 (v3.1)High
CVE-2025-13801Yoco Payments <= 3.8.8 - Path TraversalYoco Payments7.5 (v3.1)High
CVE-2025-24963Vitest Browser Mode - Local File Readvitest7.5 (v3.1)High
CVE-2025-2539File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Readfile away7.5 (v3.1)High
CVE-2025-30208Vite - Arbitrary File Readvite7.5 (v3.1)High
CVE-2025-30567WordPress WP01 - Path TraversalWP017.5 (v3.1)High
CVE-2025-31125Vite Development Server - Path Traversalvite7.5 (v3.1)High
CVE-2025-31131Yeswiki < 4.5.2 - Unauthenticated Path Traversalyeswiki7.5 (v3.1)High
CVE-2025-45145Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 Path Traversal Vulnerability-7.5 (v3.1)High
CVE-2025-69411ionCube Tester Plus <= 1.3 - Local File InclusionionCube tester plus7.5 (v3.1)High
CVE-2026-23536Feast Feature Server <=0.58.0 - Arbitrary File Readfeast7.5 (v3.1)High
CVE-2026-32820dataCycle Public Markdown Path Traversal Via /docs/*pathdataCycle-CORE7.5 (v3.1)High
CVE-2026-36851UnPoller 2.33.0 password field Path Traversal VulnerabilityUnPoller 2.33.0 password field7.5 (v3.1)High
CVE-2026-39359Wazuh: Unauthenticated Path Traversal in authd via Agent Group Namewazuh7.5 (v3.1)High
CVE-2026-39844NiceGUI has a Path Traversal in NiceGUI Upload Filename on Windows via Backslash Bypass of PurePosixPath Sanitizationnicegui7.5 (v3.1)High
CVE-2026-39847Emmett has a path traversal in internal assets handleremmett7.5 (v3.1)High
CVE-2026-50776Pronis Loisirs Billetterie CSE - < 04/2026 Arbitrary Code Execution VulnerabilityPronis Loisirs Billetterie CSE - < 04/20267.5 (v3.1)High
CVE-2026-5487DriveLock Directory Traversal Information Disclosure VulnerabilityDriveLock7.5 (v3.0)High
CVE-2026-5491DriveLock Directory Traversal Information Disclosure VulnerabilityDriveLock7.5 (v3.0)High
CVE-2026-55552Yamcs: Unauthenticated Directory Traversalyamcs7.5 (v3.1)High
CVE-2026-56671ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file readComfyUI7.5 (v3.1)High
CVE-2026-61891theia Exposure of Sensitive Information to an Unauthorized Actor Vulnerabilitytheia7.5 (v3.1)High
CVE-2026-71209audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Traveaudiobookshelf7.5 (v3.1)High
CVE-2026-75328In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java Path Traversal VulnerabilityIn DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java7.5 (v3.1)High
CVE-2026-75333yx-image-recognition v1.0 Path Traversal Vulnerability-7.5 (v3.1)High
CVE-2026-15244HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter searchHUSKY7.2 (v3.1)High
CVE-2026-18274Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution VulnerabilityDatabase Proxy7.2 (v3.0)High
CVE-2026-20297Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprisesplunk7.2 (v3.1)High
CVE-2026-34968Adminer before 5.4.3 Arbitrary File Deletion via SQLite Dropadminer7.2 (v4.0)High
CVE-2026-35174Chyrp Lite has a Path Traversal to Remote Code Executionchyrp lite7.2 (v3.1)High
CVE-2026-39387BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameterboidcms7.2 (v3.1)High
CVE-2026-85160AVideo through c91b5975d CSRF and Path Traversal via stopLive.phpAVideo7.2 (v4.0)High
CVE-2018-25393Navigate CMS 2.8.5 Path Traversal via navigate_download.phpNavigate CMS7.1 (v4.0)High
CVE-2018-25421Open STA Manager 2.3 Arbitrary File Download via Path TraversalOpen STA Manager7.1 (v4.0)High
CVE-2019-25246BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File DisclosureN100 H.264 VGA IP Camera7.1 (v4.0)High
CVE-2026-40526Volmarg Personal Management System Path Traversal via get-file Endpointpersonal-management-system7.1 (v4.0)High
CVE-2026-46555WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltrationwhatsapp mcp server7.1 (v3.1)High
CVE-2026-47735Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checksarc7.1 (v4.0)High
CVE-2026-64826rConfig < 8.2.13 Path Traversal File Read via FileDownloadControllerrConfig7.1 (v4.0)High
CVE-2026-76210phpMyFAQ before v4.1.6 Local File Disclosure via PDF Exportphpmyfaq7.1 (v4.0)High
CVE-2026-81030Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items Endpointmage-ai7.1 (v4.0)High
CVE-2026-82877ILIAS before 9.22 Arbitrary File Read via SOAP addFileILIAS7.1 (v4.0)High
CVE-2026-40506OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.phpopenemr7.0 (v4.0)High
CVE-2026-54134OctoPrint: File exfiltration possible via query parameters on upload endpointsOctoPrint7.0 (v4.0)High
CVE-2026-73033Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.phpsucuri-wordpress-plugin7.0 (v4.0)High
CVE-2019-25760Joomla! Component Easy Shop 1.2.3 Local File Inclusioneasy shop6.9 (v4.0)Medium
CVE-2022-50954WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusioncab-fare-calculator6.9 (v4.0)Medium
CVE-2022-50956WordPress Plugin amministrazione-aperta 3.7.3 Local File Readamministrazione-aperta6.9 (v4.0)Medium
CVE-2026-45731WWBN AVideo: Authenticated Arbitrary File Read in view/update.phpavideo6.9 (v4.0)Medium
CVE-2026-45774compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversalcompliance-trestle6.9 (v4.0)Medium
CVE-2026-46337WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in view/img/image404Raw.phpavideo6.9 (v4.0)Medium
CVE-2026-71932DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFileVigorSwitch G2540xs6.9 (v4.0)Medium
CVE-2026-74235GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download HandlerGFI Exinda AI6.9 (v4.0)Medium
CVE-2026-75592Kirby: Access to image files outside of the site root via path traversal in the media handlingkirby6.9 (v4.0)Medium
CVE-2026-79743MCPHub: Path Traversal via Malicious MCPB Manifest Namemcphub6.9 (v4.0)Medium
CVE-2026-79773Winter CMS before 1.2.13 Local File Inclusion via JavaScriptwinter6.9 (v4.0)Medium
CVE-2026-79781rclone serve s3 Path Traversal via dot-dot object keysrclone6.9 (v4.0)Medium
CVE-2026-82233SiYuan before v3.8.1 Path Traversal via asset.uploadsiyuan6.9 (v4.0)Medium
CVE-2008-2650CMSimple 3.1 - Local File Inclusioncmsimple6.8 (v2.0)Medium
CVE-2008-6172Joomla! Component RWCards 3.0.11 - Local File Inclusionrwcards6.8 (v2.0)Medium
CVE-2009-3053Joomla! Agora 3.0.0b - Local File InclusionJoomla!6.8 (v2.0)Medium
CVE-2010-1056Joomla! Component com_rokdownloads - Local File Inclusioncom rokdownloads6.8 (v2.0)Medium
CVE-2010-1219Joomla! Component com_janews - Local File Inclusioncom janews6.8 (v2.0)Medium
CVE-2010-1469Joomla! Component JProject Manager 1.0 - Local File Inclusioncom jprojectmanager6.8 (v2.0)Medium
CVE-2010-1473Joomla! Component Advertising 0.25 - Local File Inclusioncom advertising6.8 (v2.0)Medium
CVE-2010-1474Joomla! Component Sweetykeeper 1.5 - Local File Inclusioncom sweetykeeper6.8 (v2.0)Medium
CVE-2010-1475Joomla! Component Preventive And Reservation 1.0.5 - Local File Inclusioncom preventive6.8 (v2.0)Medium
CVE-2010-1476Joomla! Component AlphaUserPoints 1.5.5 - Local File Inclusioncom alphauserpoints6.8 (v2.0)Medium
CVE-2010-1478Joomla! Component Jfeedback 1.2 - Local File Inclusioncom jfeedback6.8 (v2.0)Medium
CVE-2010-1607Joomla! Component WMI 1.5.0 - Local File Inclusioncom wmi6.8 (v2.0)Medium
CVE-2010-1715Joomla! Component Online Exam 1.5.0 - Local File Inclusioncom onlineexam6.8 (v2.0)Medium
CVE-2010-1718Joomla! Component Archery Scores 1.0.6 - Local File Inclusioncom archeryscores6.8 (v2.0)Medium
CVE-2010-1719Joomla! Component MT Fire Eagle 1.2 - Local File Inclusioncom mtfireeagle6.8 (v2.0)Medium
CVE-2010-1722Joomla! Component Online Market 2.x - Local File Inclusioncom market6.8 (v2.0)Medium
CVE-2010-1723Joomla! Component iNetLanka Contact Us Draw Root Map 1.1 - Local File Inclusioncom drawroot6.8 (v2.0)Medium
CVE-2010-1979Joomla! Component Affiliate Datafeeds 880 - Local File Inclusioncom datafeeds6.8 (v2.0)Medium
CVE-2010-1981Joomla! Component Fabrik 2.0 - Local File Inclusionfabrik6.8 (v2.0)Medium
CVE-2010-2122Joomla! Component simpledownload <=0.9.5 - Arbitrary File Retrievalcom simpledownload6.8 (v2.0)Medium
CVE-2010-2507Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusioncom picasa2gallery6.8 (v2.0)Medium
CVE-2010-2680Joomla! Component jesectionfinder - Local File Inclusioncom jesectionfinder6.8 (v2.0)Medium
CVE-2010-2857Joomla! Component Music Manager - Local File Inclusioncom music6.8 (v2.0)Medium
CVE-2010-2920Joomla! Component Foobla Suggestions 1.5.1.2 - Local File Inclusioncom foobla suggestions6.8 (v2.0)Medium
CVE-2010-4617Joomla! Component JotLoader 2.2.1 - Local File Inclusioncom jotloader6.8 (v2.0)Medium
CVE-2011-2744Chyrp 2.x - Local File Inclusionchyrp6.8 (v2.0)Medium
CVE-2026-35593Trilium Notes has Local File Inclusion via upload modified file API endpointTrilium6.8 (v3.1)Medium
CVE-2026-71475Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url pathadvanced cluster management for kubernetes6.8 (v3.1)Medium
CVE-2016-6435Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusionsecure firewall management center6.5 (v3.0)Medium
CVE-2017-14537Trixbox 2.8.0 - Path Traversaltrixbox6.5 (v3.1)Medium
CVE-2018-15140OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actionsopenemr6.5 (v3.0)Medium
CVE-2018-15141OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actionsopenemr6.5 (v3.0)Medium
CVE-2019-14312Aptana Jaxer 1.0.3.4547 - Local File inclusionjaxer6.5 (v3.0)Medium
CVE-2019-3799Spring Cloud Config Server - Local File Inclusionspring cloud config6.5 (v3.1)Medium
CVE-2020-5405Spring Cloud Config - Local File Inclusionspring cloud config6.5 (v3.1)Medium
CVE-2021-24947WordPress Responsive Vector Maps < 6.4.2 - Arbitrary File Readresponsive vector maps6.5 (v3.1)Medium
CVE-2021-28149Hongdian H8922 3.0.5 Devices - Local File Inclusionh8922 firmware6.5 (v3.1)Medium
CVE-2021-29006rConfig 3.9.6 - Local File Inclusionrconfig6.5 (v3.1)Medium
CVE-2021-40651OS4Ed OpenSIS Community 8.0 - Local File Inclusionopensis6.5 (v3.1)Medium
CVE-2024-55457MasterSAM Star Gate v11 - Local File Inclusion-6.5 (v3.1)Medium
CVE-2025-28367mojoPortal <=2.9.0.1 - Directory Traversalmojoportal6.5 (v3.1)Medium
CVE-2025-32815NetMRI < 7.6.1 - Authentication Bypass via Hardcoded Credentialsnetmri6.5 (v3.1)Medium
CVE-2025-45870LogicalDOC Enterprise up to and for v9.1.1 Path Traversal Vulnerability-6.5 (v3.1)Medium
CVE-2026-11442Allegra exportReport Directory Traversal Information Disclosure VulnerabilityAllegra6.5 (v3.0)Medium
CVE-2026-12898All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Writeall-in-one-wp-migration6.5 (v3.1)Medium
CVE-2026-14470Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base componelangflow6.5 (v3.1)Medium
CVE-2026-36227Easy Chat Server 3.1 Arbitrary Code Execution VulnerabilityEasy Chat Server 3.16.5 (v3.1)Medium
CVE-2026-46397haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0haxcms-php6.5 (v3.1)Medium
CVE-2026-52607reportico-web <= 8.1.0 Path Traversal Vulnerabilityreportico-web <= 8.1.06.5 (v3.1)Medium
CVE-2026-63667ApostropheCMS: Arbitrary file read via import-export attachment-name path traversalapostrophe6.5 (v3.1)Medium
CVE-2026-73255Mongoose: Path traversal in SSI #include directives enables arbitrary file readmongoose6.5 (v3.1)Medium
CVE-2026-73573zimbra collaboration suite Path Traversal Vulnerabilityzimbra collaboration suite6.5 (v3.1)Medium
CVE-2026-73574zimbra collaboration suite Incorrect Resource Transfer Between Spheres Vulnerabilityzimbra collaboration suite6.5 (v3.1)Medium
CVE-2026-75602OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download toolOpenList6.5 (v3.1)Medium
CVE-2026-7646Langflow is affected by security vulnerabilities in Model Context Protocol featureslangflow6.5 (v3.1)Medium
CVE-2026-7658Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcementlangflow6.5 (v3.1)Medium
CVE-2026-9138Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing clangflow6.5 (v3.1)Medium
CVE-2009-0932Horde/Horde Groupware - Local File Inclusionhorde6.4 (v2.0)Medium
CVE-2026-34371LibreChat Affected by Arbitrary File Write via execute_code Artifact Filename Traversallibrechat6.3 (v3.1)Medium
CVE-2026-39365Vite has a Path Traversal in Optimized Deps .map Handlingvite6.3 (v4.0)Medium
CVE-2026-56722Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URIdompdf6.3 (v4.0)Medium
CVE-2026-65012InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folderInvokeAI6.3 (v4.0)Medium
CVE-2026-72814actix-web before 0.6.10 Information Disclosure via Filesactix-web6.3 (v4.0)Medium
CVE-2026-78886liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversalTREK6.3 (v4.0)Medium
CVE-2014-8727F5 BIG-IP 10.1.0 - Directory Traversalbig-ip local traffic manager6.2 (v2.0)Medium
CVE-2026-29066TinaCMS - Path Traversaltinacms6.2 (v3.1)Medium
CVE-2025-46565Vite Dev Server - Information Exposurevite6.0 (v4.0)Medium
CVE-2026-41363OpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image Parameteropenclaw6.0 (v4.0)Medium
CVE-2026-65698Void 1.3.4 Path Traversal via AI Agent File-Reading Toolsvoid6.0 (v4.0)Medium
CVE-2026-66004BlenderMCP Path Traversal via download_polyhaven_asset APIblender-mcp6.0 (v4.0)Medium
CVE-2026-79653Eclipse SW360 Path Traversal VulnerabilityEclipse SW3606.0 (v4.0)Medium
CVE-2026-13693Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path TraversalBit Form5.9 (v3.1)Medium
CVE-2026-49244SFTPGo: Path confinement bypass in public browsable share partial ZIP downloadsftpgo5.9 (v3.1)Medium
CVE-2026-82650SiYuan before v3.8.1 Path Traversal via /api/template/rendersiyuan5.9 (v4.0)Medium
CVE-2010-0467Joomla! Component CCNewsLetter - Local File Inclusioncom ccnewsletter5.8 (v3.1)Medium
CVE-2025-1035KLog Server - Path TraversalKLog Server5.7 (v3.1)Medium
CVE-2026-40605Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion APITautulli5.7 (v4.0)Medium
CVE-2018-13980Zeta Producer Desktop CMS <14.2.1 - Local File Inclusionzeta producer5.5 (v3.1)Medium
CVE-2018-15536Responsive FileManager < 9.13.4 - Directory Traversalresponsive filemanager5.5 (v3.0)Medium
CVE-2025-13810jsnjfz WebStack-Guns KaptchaController.java renderPicture path traversalwebstack-guns5.5 (v4.0)Medium
CVE-2026-10694SourceCodester Online Food Ordering System index.php include file inclusionOnline Food Ordering System5.5 (v4.0)Medium
CVE-2026-16252Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injectionMultimedia Integrated Business Display System5.5 (v4.0)Medium
CVE-2026-19758dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversallamp-cloud5.5 (v4.0)Medium
CVE-2026-19762DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversalTaier5.5 (v4.0)Medium
CVE-2026-19827alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversalalldata5.5 (v4.0)Medium
CVE-2026-68922MobSF: Arbitrary File Read via Path Traversal in ZIP UploadsMobile-Security-Framework-MobSF5.5 (v3.1)Medium
CVE-2026-7205duartium papers-mcp-server main.py search_papers path traversalpapers-mcp-server5.5 (v4.0)Medium
CVE-2026-7206dubydu sqlite-mcp entry.py extract_to_json sql injectionsqlite-mcp5.5 (v4.0)Medium
CVE-2026-7212edvardlindelof notes-mcp notes_mcp.py path traversalnotes-mcp5.5 (v4.0)Medium
CVE-2026-7214eghuzefa engineer-your-data server.py file_inf path traversalengineer-your-data5.5 (v4.0)Medium
CVE-2026-7216donchelo processing-claude-mcp-bridge create_sketch Tool processing_server.py path traversalprocessing-claude-mcp-bridge5.5 (v4.0)Medium
CVE-2026-7217Deepractice PromptX Document File index.ts read_pdf absolute path traversalPromptX5.5 (v4.0)Medium
CVE-2026-7314eiceblue spire-doc-mcp-server base.py get_doc_path path traversalspire-doc-mcp-server5.5 (v4.0)Medium
CVE-2026-7315eiceblue spire-pdf-mcp-server PDF File server.py get_pdf_path path traversalspire-pdf-mcp-server5.5 (v4.0)Medium
CVE-2026-81486bsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversalmcp-file-context-server5.5 (v4.0)Medium
CVE-2026-81491boxpositron with-context-mcp index.ts project_folder path traversalwith-context-mcp5.5 (v4.0)Medium
CVE-2026-84441Piwigo Image Derivative i.php path traversalPiwigo5.5 (v4.0)Medium
CVE-2026-17621Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base componelangflow5.4 (v3.1)Medium
CVE-2026-7869Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcementlangflow5.4 (v3.1)Medium
CVE-2014-8676SO Planning 1.32 - Multiple Vulnerabilitiessoplanning5.3 (v3.0)Medium
CVE-2014-9609Netsweeper 4.0.8 - Directory Traversalnetsweeper5.3 (v3.1)Medium
CVE-2015-5471Swim Team <= v1.44.10777 - Local File Inclusionswim team5.3 (v3.0)Medium
CVE-2020-13886Intelbras TIP 200/200 LITE/300 - Local File Inclusiontip200 firmware5.3 (v3.1)Medium
CVE-2021-28377Joomla! ChronoForums 2.0.11 - Local File Inclusionchronoforums5.3 (v3.1)Medium
CVE-2022-25497Cuppa CMS v1.0 - Local File Inclusioncuppacms5.3 (v3.1)Medium
CVE-2023-41599JFinalCMS v5.0.0 - Directory Traversaljfinalcms5.3 (v3.1)Medium
CVE-2024-51977Brother MFC-L9570CDW - Information DisclosureHL-L8260CDN5.3 (v3.1)Medium
CVE-2025-31486Vite server.fs.deny Bypass - Local File Inclusionvite5.3 (v3.1)Medium
CVE-2025-4078Wangshen SecGate 3600 Path Traversal VulnerabilitySecGate 36005.3 (v4.0)Medium
CVE-2026-15932Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path TraversalSupport Genix5.3 (v3.1)Medium
CVE-2026-16531Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servletRed Hat Enterprise Linux 105.3 (v3.1)Medium
CVE-2026-34523SillyTavern: Path traversal allows file existence oraclesillytavern5.3 (v3.1)Medium
CVE-2026-34967Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Writeadminer5.3 (v4.0)Medium
CVE-2026-36726the /api/delete-temp-license/{file} endpoint of bookcars v8.3 Path Traversal Vulnerabilitythe /api/delete-temp-license/{file} endpoint of bookcars v8.35.3 (v3.1)Medium
CVE-2026-53452Ground Station: Unauthenticated out-of-containment file read via sigmfplayback recordingPathground-station5.3 (v3.1)Medium
CVE-2026-73244kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listingkkFileView5.3 (v3.1)Medium
CVE-2026-76614OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restoreopenemr5.3 (v4.0)Medium
CVE-2026-19761DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename path traversalTaier5.1 (v4.0)Medium
CVE-2026-19763DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversalTaier5.1 (v4.0)Medium
CVE-2026-82112houtini-ai houtini-lm code_task_files index.ts path traversalhoutini-lm5.1 (v4.0)Medium
CVE-2007-4504Joomla! RSfiles <=1.0.2 - Local File Inclusionrsfiles5.0 (v2.0)Medium
CVE-2008-4764Joomla! <=2.0.0 RC2 - Local File Inclusioncom extplorer5.0 (v2.0)Medium
CVE-2008-6080Joomla! ionFiles 4.4.2 - Local File Inclusioncom ionfiles5.0 (v2.0)Medium
CVE-2008-6222Joomla! ProDesk 1.0/1.2 - Local File Inclusionpro desk support center5.0 (v2.0)Medium
CVE-2008-6668nweb2fax <=0.2.7 - Local File Inclusionnweb2fax5.0 (v2.0)Medium
CVE-2009-1496Joomla! Cmimarketplace 0.1 - Local File InclusionJoomla!5.0 (v2.0)Medium
CVE-2009-2100Joomla! JoomlaPraise Projectfork 2.0.10 - Local File InclusionJoomla!5.0 (v2.0)Medium
CVE-2009-5114WebGlimpse 2.18.7 - Directory Traversalwebglimpse5.0 (v2.0)Medium
CVE-2010-0696Joomla! Component Jw_allVideos - Arbitrary File Retrievaljw allvideos5.0 (v2.0)Medium
CVE-2010-0942Joomla! Component com_jvideodirect - Directory Traversalcom jvideodirect5.0 (v2.0)Medium
CVE-2010-0943Joomla! Component com_jashowcase - Directory Traversalcom jashowcase5.0 (v2.0)Medium
CVE-2010-0944Joomla! Component com_jcollection - Directory Traversalcom jcollection5.0 (v2.0)Medium
CVE-2010-1081Joomla! Component com_communitypolls 1.5.2 - Local File Inclusioncom communitypolls5.0 (v2.0)Medium
CVE-2010-1302Joomla! Component DW Graph - Local File Inclusioncom dwgraphs5.0 (v2.0)Medium
CVE-2010-1304Joomla! Component User Status - Local File Inclusioncom userstatus5.0 (v2.0)Medium
CVE-2010-1305Joomla! Component JInventory 1.23.02 - Local File Inclusioncom jinventory5.0 (v2.0)Medium
CVE-2010-1307Joomla! Component Magic Updater - Local File Inclusioncom joomlaupdater5.0 (v2.0)Medium
CVE-2010-1308Joomla! Component SVMap 1.1.1 - Local File Inclusioncom svmap5.0 (v2.0)Medium
CVE-2010-1312Joomla! Component News Portal 1.5.x - Local File Inclusioncom news portal5.0 (v2.0)Medium
CVE-2010-1314Joomla! Component Highslide 1.5 - Local File Inclusioncom hsconfig5.0 (v2.0)Medium
CVE-2010-1315Joomla! Component webERPcustomer - Local File Inclusioncom weberpcustomer5.0 (v2.0)Medium
CVE-2010-1340Joomla! Component com_jresearch - 'Controller' Local File Inclusioncom jresearch5.0 (v2.0)Medium
CVE-2010-1345Joomla! Component Cookex Agency CKForms - Local File Inclusioncom ckforms5.0 (v2.0)Medium
CVE-2010-1352Joomla! Component Juke Box 1.7 - Local File Inclusioncom jukebox5.0 (v2.0)Medium
CVE-2010-1353Joomla! Component LoginBox - Local File Inclusioncom loginbox5.0 (v2.0)Medium
CVE-2010-1354Joomla! Component VJDEO 1.0 - Local File Inclusioncom vjdeo5.0 (v2.0)Medium
CVE-2010-1461Joomla! Component Photo Battle 1.0.1 - Local File Inclusioncom photobattle5.0 (v2.0)Medium
CVE-2010-1491Joomla! Component MMS Blog 2.3.0 - Local File Inclusioncom mmsblog5.0 (v2.0)Medium
CVE-2010-1494Joomla! Component AWDwall 1.5.4 - Local File Inclusioncom awdwall5.0 (v2.0)Medium
CVE-2010-1532Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusioncom powermail5.0 (v2.0)Medium
CVE-2010-1534Joomla! Component Shoutbox Pro - Local File Inclusioncom shoutbox5.0 (v2.0)Medium
CVE-2010-1540Joomla! Component com_blog - Directory Traversalcom myblog5.0 (v2.0)Medium
CVE-2010-1601Joomla! Component JA Comment - Local File Inclusioncom jacomment5.0 (v2.0)Medium
CVE-2010-1657Joomla! Component SmartSite 1.0.0 - Local File Inclusioncom smartsite5.0 (v2.0)Medium
CVE-2010-1658Joomla! Component NoticeBoard 1.3 - Local File Inclusioncom noticeboard5.0 (v2.0)Medium
CVE-2010-1659Joomla! Component Ultimate Portfolio 1.0 - Local File Inclusioncom ultimateportfolio5.0 (v2.0)Medium
CVE-2010-1714Joomla! Component Arcade Games 1.0 - Local File Inclusioncom arcadegames5.0 (v2.0)Medium
CVE-2010-1858Joomla! Component SMEStorage - Local File Inclusioncom smestorage5.0 (v2.0)Medium
CVE-2010-1982Joomla! Component JA Voice 2.0 - Local File Inclusioncom javoice5.0 (v2.0)Medium
CVE-2010-2018Lokomedia CMS - Local File Inclusionlokomedia cms5.0 (v2.0)Medium
CVE-2011-0049Majordomo2 - SMTP/HTTP Directory Traversalmajordomo 25.0 (v2.0)Medium
CVE-2011-1669WP Custom Pages 0.5.0.1 - Local File Inclusion (LFI)wp custom pages5.0 (v2.0)Medium
CVE-2011-2780Chyrp 2.x - Local File Inclusionchyrp5.0 (v2.0)Medium
CVE-2011-4804Joomla! Component com_kp - 'Controller' Local File Inclusioncom obsuggest5.0 (v2.0)Medium
CVE-2012-0896Count Per Day <= 3.1 - download.php f Parameter Traversal Arbitrary File Accesscount per day5.0 (v2.0)Medium
CVE-2012-0981phpShowtime 2.0 - Directory Traversalphpshowtime5.0 (v2.0)Medium
CVE-2012-099611in1 CMS 1.2.1 - Local File Inclusion (LFI)11in15.0 (v2.0)Medium
CVE-2013-5979Xibo 1.2.2/1.4.1 - Directory Traversalxibo5.0 (v2.0)Medium
CVE-2013-7091Zimbra Collaboration Server 7.2.2/8.0.2 Local File Inclusionzimbra collaboration suite5.0 (v2.0)Medium
CVE-2014-4577WP AmASIN – The Amazon Affiliate Shop - Local File Inclusionwp amasin - the amazon affiliate shop5.0 (v2.0)Medium
CVE-2014-4940WordPress Plugin Tera Charts - Local File Inclusiontera-charts5.0 (v2.0)Medium
CVE-2014-4941Cross RSS 1.7 - Local File Inclusionwp-cross-rss5.0 (v2.0)Medium
CVE-2014-5111Fonality trixbox - Local File Inclusiontrixbox5.0 (v2.0)Medium
CVE-2014-5181Last.fm Rotation 1.0 - Path Traversallastfm-rotation plugin5.0 (v2.0)Medium
CVE-2014-5187Tom M8te (tom-m8te) Plugin 1.5.3 - Directory Traversaltom-m8te plugin5.0 (v2.0)Medium
CVE-2014-6308Osclass Security Advisory 3.4.1 - Local File Inclusionosclass5.0 (v2.0)Medium
CVE-2015-2067Magento Server MAGMI - Directory Traversalmagmi5.0 (v2.0)Medium
CVE-2015-4414WordPress SE HTML5 Album Audio Player 1.1.0 - Directory Traversalse html5 album audio player5.0 (v2.0)Medium
CVE-2026-16955AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio TranscriptionAI Engine5.0 (v3.1)Medium
CVE-2025-15673Import and export users and customers < 2.4.3 - Admin+ Arbitrary File ReadImport and export users and customers4.9 (v3.1)Medium
CVE-2026-52832Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard containernuclio4.9 (v3.1)Medium
CVE-2026-53594FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Pathfreescout4.9 (v3.1)Medium
CVE-2026-71283Fledge IoT Gateway Backup Restore Tar Path Traversalfledge4.9 (v3.1)Medium
CVE-2008-5587phpPgAdmin <=4.2.1 - Local File Inclusionphppgadmin4.3 (v2.0)Medium
CVE-2010-0982Joomla! Component com_cartweberp - Local File Inclusioncom cartweberp4.3 (v2.0)Medium
CVE-2010-1217Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusionje form creator4.3 (v2.0)Medium
CVE-2010-1313Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusioncom sebercart4.3 (v2.0)Medium
CVE-2012-4253MySQLDumper 1.24.4 - Directory Traversalmysqldumper4.3 (v2.0)Medium
CVE-2014-9146Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesfiyo cms4.3 (v2.0)Medium
CVE-2018-18777Microstrategy Web 7 - Local File Inclusionmicrostrategy web4.3 (v3.0)Medium
CVE-2024-7631Openshift-console: openshift console: path traversalRed Hat OpenShift Container Platform 3.114.3 (v3.1)Medium
CVE-2026-26477dokuwiki Denial of Service Vulnerabilitydokuwiki4.3 (v3.1)Medium
CVE-2026-55495Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Accountcloudreve4.3 (v3.1)Medium
CVE-2011-4640WebTitan < 3.60 - Local File Inclusionwebtitan4.0 (v2.0)Medium
CVE-2013-5528Cisco Unified Communications Manager 7/8/9 - Directory Traversalunified communications manager4.0 (v2.0)Medium
CVE-2014-1222Fiyo CMS 2.0.1.8 - Multiple Vulnerabilitiesvtiger crm4.0 (v2.0)Medium
CVE-2014-5258webEdition 6.3.8.0 - Directory Traversalwebedition cms4.0 (v2.0)Medium
CVE-2019-19411Huawei Firewall - Local File Inclusionusg95003.7 (v3.1)Low
CVE-2012-0991OpenEMR 4.1 - Local File Inclusionopenemr3.5 (v2.0)Low
CVE-2025-55523Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Downloadagent-zero3.5 (v3.1)Low
CVE-2026-9062Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path TraversalStore Locator WordPress3.4 (v3.1)Low
CVE-2026-55825Contao: Possible path traversal in job download URIscontao3.1 (v3.1)Low
CVE-2023-2252Directorist < 7.5.4 - Local File Inclusiondirectorist2.7 (v3.1)Low
CVE-2024-55550Mitel MiCollab - Arbitary File Readcmg suite2.7 (v3.1)Low
CVE-2026-16434Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypassadminer2.3 (v4.0)Low
CVE-2026-55554Dompdf: Chroot Validation Bypassdompdf2.3 (v4.0)Low
CVE-2025-13816moxi159753 Mogu Blog v2 ZIP File unzipFile FileOperation.unzip path traversalmogublog2.1 (v4.0)Low
CVE-2025-13875Yohann0617 oci-helper OCI Configuration Upload OciServiceImpl.java addCfg path traversaloci-helper2.1 (v4.0)Low
CVE-2026-10278ishayoyo excel-mcp read_file/write_file index.ts path traversalexcel-mcp2.1 (v4.0)Low
CVE-2026-10559SourceCodester Pizzafy Ecommerce System index.php file inclusionPizzafy Ecommerce System2.1 (v4.0)Low
CVE-2026-11467jishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadService.java path traversaljshERP2.1 (v4.0)Low
CVE-2026-18959yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversalInnoShop2.1 (v4.0)Low
CVE-2026-19756Dromara lamp-cloud Code Generator DefGenProjectController.java path traversallamp-cloud2.1 (v4.0)Low
CVE-2026-19828648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversalwvp-GB28181-pro2.1 (v4.0)Low
CVE-2026-19829648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversalwvp-GB28181-pro2.1 (v4.0)Low
CVE-2026-76576yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversalRuoYi-Vue2.1 (v4.0)Low
CVE-2026-81845arben-adm mcp-sequential-thinking Import Session/Export Session server.py export_session path traversalmcp-sequential-thinking2.1 (v4.0)Low
CVE-2026-82599SeaCMS Avatar Upload member.php unlink path traversalSeaCMS2.1 (v4.0)Low
CVE-2026-82603SeaCMS Comment Cache member.php del_pl path traversalSeaCMS2.1 (v4.0)Low
CVE-2026-82656Admidio before 5.0.12 Path Traversal via Photo ZIP Downloadadmidio2.1 (v4.0)Low
CVE-2026-9473c-rick jimeng-mcp api.ts generateVideo path traversaljimeng-mcp2.1 (v4.0)Low
CVE-2026-12211Intelbras iNVU 7016 FT Web syslog path traversaliNVU 7016 FT2.0 (v4.0)Low
CVE-2026-16088halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversalhalo2.0 (v4.0)Low
CVE-2026-81847MAA-AI MaaMCP pipeline_tools.py load_pipeline path traversalMaaMCP2.0 (v4.0)Low

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-20CVE-2009-0545 , CVE-2026-44343 , CVE-2026-50553 , CVE-2016-10956 , CVE-2026-56722 , CVE-2026-16434 , CVE-2026-55554
CWE-22CVE-2010-5286 , CVE-2010-2861 , CVE-2018-12031 , CVE-2018-16283 , CVE-2019-9618 , CVE-2020-5902 , CVE-2021-40960 , CVE-2022-0679 , CVE-2022-1390 , CVE-2022-1391 , CVE-2022-32409 , CVE-2022-41840 , CVE-2023-5991 , CVE-2025-2294 , CVE-2025-4524 , CVE-2026-35471 , CVE-2026-75337 , CVE-2026-11419 , CVE-2026-11423 , CVE-2026-72850 , CVE-2026-77086 , CVE-2019-25727 , CVE-2026-45668 , CVE-2026-47669 , CVE-2026-47754 , CVE-2026-53976 , CVE-2026-65700 , CVE-2026-65701 , CVE-2026-69110 , CVE-2026-74798 , CVE-2026-80104 , CVE-2018-16716 , CVE-2018-19365 , CVE-2022-26960 , CVE-2024-40422 , CVE-2025-55526 , CVE-2026-34745 , CVE-2026-47731 , CVE-2026-48024 , CVE-2026-52610 , CVE-2008-4668 , CVE-2026-53581 , CVE-2018-15142 , CVE-2019-14530 , CVE-2020-8641 , CVE-2026-34524 , CVE-2026-36723 , CVE-2026-42605 , CVE-2026-43624 , CVE-2026-44829 , CVE-2026-50186 , CVE-2026-62677 , CVE-2026-65702 , CVE-2026-76842 , CVE-2026-81730 , CVE-2026-82286 , CVE-2026-85199 , CVE-2026-86542 , CVE-2026-86775 , CVE-2017-20248 , CVE-2017-20250 , CVE-2018-25374 , CVE-2021-4463 , CVE-2026-10108 , CVE-2026-17524 , CVE-2026-25559 , CVE-2026-35214 , CVE-2026-39352 , CVE-2026-43982 , CVE-2026-47394 , CVE-2026-47659 , CVE-2026-47661 , CVE-2026-57863 , CVE-2026-65694 , CVE-2026-65919 , CVE-2026-67200 , CVE-2026-67281 , CVE-2026-69089 , CVE-2026-69095 , CVE-2026-72713 , CVE-2026-75111 , CVE-2026-75482 , CVE-2026-75914 , CVE-2026-85685 , CVE-2026-86538 , CVE-2026-9506 , CVE-2015-4694 , CVE-2022-24900 , CVE-2026-11974 , CVE-2026-46491 , CVE-2026-50553 , CVE-2015-2996 , CVE-2025-34023 , CVE-2026-16033 , CVE-2026-73079 , CVE-2026-75855 , CVE-2026-48105 , CVE-2026-69086 , CVE-2026-75842 , CVE-2026-82673 , CVE-2025-44137 , CVE-2026-40075 , CVE-2026-45711 , CVE-2026-48126 , CVE-2026-74907 , CVE-2023-6831 , CVE-2026-19303 , CVE-2026-33236 , CVE-2026-34522 , CVE-2026-46484 , CVE-2026-54083 , CVE-2026-64679 , CVE-2026-73659 , CVE-2009-1558 , CVE-2011-3315 , CVE-2014-2962 , CVE-2026-65600 , CVE-2026-67309 , CVE-2020-35749 , CVE-2021-21234 , CVE-2026-47179 , CVE-2026-53553 , CVE-2026-54910 , CVE-2026-73498 , CVE-2026-8183 , CVE-2026-39369 , CVE-2026-65695 , CVE-2009-1479 , CVE-2009-2015 , CVE-2009-3318 , CVE-2009-4202 , CVE-2009-4679 , CVE-2010-0157 , CVE-2010-0759 , CVE-2010-0972 , CVE-2010-0985 , CVE-2010-1306 , CVE-2010-1470 , CVE-2010-1471 , CVE-2010-1472 , CVE-2010-1495 , CVE-2010-1531 , CVE-2010-1533 , CVE-2010-1535 , CVE-2010-1602 , CVE-2010-1603 , CVE-2010-1653 , CVE-2010-1717 , CVE-2010-1875 , CVE-2010-1878 , CVE-2010-1952 , CVE-2010-1953 , CVE-2010-1954 , CVE-2010-1955 , CVE-2010-1956 , CVE-2010-1957 , CVE-2010-1977 , CVE-2010-1980 , CVE-2010-1983 , CVE-2010-2033 , CVE-2010-2034 , CVE-2010-2035 , CVE-2010-2036 , CVE-2010-2037 , CVE-2010-2045 , CVE-2010-2050 , CVE-2010-2128 , CVE-2010-2259 , CVE-2010-2682 , CVE-2010-3426 , CVE-2010-4282 , CVE-2010-4719 , CVE-2010-4769 , CVE-2012-1226 , CVE-2014-10037 , CVE-2015-1000005 , CVE-2015-1503 , CVE-2015-3648 , CVE-2015-4074 , CVE-2015-4632 , CVE-2015-5469 , CVE-2016-10367 , CVE-2016-2389 , CVE-2016-6601 , CVE-2017-15647 , CVE-2017-16806 , CVE-2017-9833 , CVE-2018-12909 , CVE-2018-14912 , CVE-2018-14918 , CVE-2018-15138 , CVE-2018-15535 , CVE-2018-16299 , CVE-2018-19753 , CVE-2018-7422 , CVE-2018-9205 , CVE-2019-12276 , CVE-2019-14251 , CVE-2019-16123 , CVE-2019-18371 , CVE-2019-18665 , CVE-2019-7254 , CVE-2019-9922 , CVE-2020-11738 , CVE-2020-13158 , CVE-2020-14864 , CVE-2020-19360 , CVE-2020-27467 , CVE-2020-35580 , CVE-2020-35598 , CVE-2020-5410 , CVE-2020-8209 , CVE-2021-20123 , CVE-2021-20124 , CVE-2021-39316 , CVE-2021-41291 , CVE-2021-43778 , CVE-2021-46104 , CVE-2021-46381 , CVE-2022-27043 , CVE-2022-29298 , CVE-2022-31474 , CVE-2022-37122 , CVE-2023-23063 , CVE-2023-26256 , CVE-2023-29887 , CVE-2023-33510 , CVE-2023-38879 , CVE-2023-40924 , CVE-2023-6023 , CVE-2024-12849 , CVE-2024-1483 , CVE-2024-2928 , CVE-2024-3848 , CVE-2024-38819 , CVE-2024-45388 , CVE-2024-9362 , CVE-2024-9935 , CVE-2025-13339 , CVE-2025-13801 , CVE-2025-24963 , CVE-2025-30567 , CVE-2025-31131 , CVE-2025-45145 , CVE-2025-69411 , CVE-2026-23536 , CVE-2026-32820 , CVE-2026-36851 , CVE-2026-39359 , CVE-2026-39844 , CVE-2026-39847 , CVE-2026-50776 , CVE-2026-5487 , CVE-2026-5491 , CVE-2026-55552 , CVE-2026-56671 , CVE-2026-61891 , CVE-2026-71209 , CVE-2026-75328 , CVE-2026-75333 , CVE-2026-15244 , CVE-2026-18274 , CVE-2026-20297 , CVE-2026-34968 , CVE-2026-35174 , CVE-2018-25393 , CVE-2018-25421 , CVE-2019-25246 , CVE-2026-40526 , CVE-2026-46555 , CVE-2026-47735 , CVE-2026-64826 , CVE-2026-81030 , CVE-2026-82877 , CVE-2026-40506 , CVE-2026-73033 , CVE-2022-50956 , CVE-2026-45731 , CVE-2026-45774 , CVE-2026-46337 , CVE-2026-71932 , CVE-2026-74235 , CVE-2026-75592 , CVE-2026-79743 , CVE-2026-79773 , CVE-2026-79781 , CVE-2026-82233 , CVE-2008-2650 , CVE-2008-6172 , CVE-2009-3053 , CVE-2010-1056 , CVE-2010-1219 , CVE-2010-1469 , CVE-2010-1473 , CVE-2010-1474 , CVE-2010-1475 , CVE-2010-1476 , CVE-2010-1478 , CVE-2010-1607 , CVE-2010-1715 , CVE-2010-1718 , CVE-2010-1719 , CVE-2010-1722 , CVE-2010-1723 , CVE-2010-1979 , CVE-2010-1981 , CVE-2010-2122 , CVE-2010-2507 , CVE-2010-2680 , CVE-2010-2857 , CVE-2010-2920 , CVE-2010-4617 , CVE-2011-2744 , CVE-2026-35593 , CVE-2026-71475 , CVE-2017-14537 , CVE-2018-15140 , CVE-2018-15141 , CVE-2019-14312 , CVE-2019-3799 , CVE-2020-5405 , CVE-2021-28149 , CVE-2021-29006 , CVE-2021-40651 , CVE-2024-55457 , CVE-2025-45870 , CVE-2026-11442 , CVE-2026-12898 , CVE-2026-14470 , CVE-2026-36227 , CVE-2026-46397 , CVE-2026-52607 , CVE-2026-63667 , CVE-2026-73255 , CVE-2026-75602 , CVE-2026-7646 , CVE-2026-7658 , CVE-2026-9138 , CVE-2009-0932 , CVE-2026-34371 , CVE-2026-39365 , CVE-2026-72814 , CVE-2026-78886 , CVE-2014-8727 , CVE-2025-46565 , CVE-2026-41363 , CVE-2026-65698 , CVE-2026-66004 , CVE-2026-79653 , CVE-2026-13693 , CVE-2026-49244 , CVE-2010-0467 , CVE-2025-1035 , CVE-2026-40605 , CVE-2018-13980 , CVE-2018-15536 , CVE-2025-13810 , CVE-2026-19758 , CVE-2026-19762 , CVE-2026-19827 , CVE-2026-68922 , CVE-2026-7205 , CVE-2026-7212 , CVE-2026-7214 , CVE-2026-7216 , CVE-2026-7217 , CVE-2026-7314 , CVE-2026-7315 , CVE-2026-81486 , CVE-2026-81491 , CVE-2026-84441 , CVE-2026-17621 , CVE-2026-7869 , CVE-2014-8676 , CVE-2014-9609 , CVE-2015-5471 , CVE-2020-13886 , CVE-2021-28377 , CVE-2023-41599 , CVE-2025-4078 , CVE-2026-15932 , CVE-2026-16531 , CVE-2026-34523 , CVE-2026-36726 , CVE-2026-53452 , CVE-2026-73244 , CVE-2026-76614 , CVE-2026-19761 , CVE-2026-19763 , CVE-2026-82112 , CVE-2008-4764 , CVE-2008-6080 , CVE-2008-6222 , CVE-2008-6668 , CVE-2009-1496 , CVE-2009-2100 , CVE-2009-5114 , CVE-2010-0696 , CVE-2010-0942 , CVE-2010-0943 , CVE-2010-0944 , CVE-2010-1081 , CVE-2010-1302 , CVE-2010-1304 , CVE-2010-1305 , CVE-2010-1307 , CVE-2010-1308 , CVE-2010-1312 , CVE-2010-1314 , CVE-2010-1315 , CVE-2010-1340 , CVE-2010-1345 , CVE-2010-1352 , CVE-2010-1353 , CVE-2010-1354 , CVE-2010-1461 , CVE-2010-1491 , CVE-2010-1494 , CVE-2010-1532 , CVE-2010-1534 , CVE-2010-1540 , CVE-2010-1601 , CVE-2010-1657 , CVE-2010-1658 , CVE-2010-1659 , CVE-2010-1714 , CVE-2010-1858 , CVE-2010-1982 , CVE-2010-2018 , CVE-2011-0049 , CVE-2011-1669 , CVE-2011-2780 , CVE-2011-4804 , CVE-2012-0896 , CVE-2012-0981 , CVE-2012-0996 , CVE-2013-5979 , CVE-2013-7091 , CVE-2014-4577 , CVE-2014-4940 , CVE-2014-4941 , CVE-2014-5111 , CVE-2014-5181 , CVE-2014-5187 , CVE-2014-6308 , CVE-2015-2067 , CVE-2015-4414 , CVE-2026-16955 , CVE-2025-15673 , CVE-2026-52832 , CVE-2026-53594 , CVE-2026-71283 , CVE-2008-5587 , CVE-2010-0982 , CVE-2010-1217 , CVE-2010-1313 , CVE-2012-4253 , CVE-2018-18777 , CVE-2024-7631 , CVE-2026-55495 , CVE-2011-4640 , CVE-2013-5528 , CVE-2014-1222 , CVE-2014-5258 , CVE-2012-0991 , CVE-2025-55523 , CVE-2026-9062 , CVE-2026-55825 , CVE-2023-2252 , CVE-2024-55550 , CVE-2025-13816 , CVE-2025-13875 , CVE-2026-10278 , CVE-2026-11467 , CVE-2026-18959 , CVE-2026-19756 , CVE-2026-19828 , CVE-2026-19829 , CVE-2026-76576 , CVE-2026-81845 , CVE-2026-82599 , CVE-2026-82603 , CVE-2026-82656 , CVE-2026-9473 , CVE-2026-12211 , CVE-2026-16088 , CVE-2026-81847
CWE-23CVE-2025-47445 , CVE-2026-23734 , CVE-2026-85199 , CVE-2026-48126 , CVE-2026-54910 , CVE-2020-5410 , CVE-2020-5405
CWE-24CVE-2026-73573
CWE-29CVE-2024-34470 , CVE-2023-6831 , CVE-2023-6023 , CVE-2024-2928 , CVE-2024-3848
CWE-36CVE-2026-61891 , CVE-2026-7217
CWE-50CVE-2023-34092
CWE-59CVE-2026-44881
CWE-73CVE-2018-17246 , CVE-2023-3643 , CVE-2026-86189 , CVE-2026-48162 , CVE-2026-53581 , CVE-2026-62865 , CVE-2022-24900 , CVE-2026-34522 , CVE-2026-64679 , CVE-2024-5334 , CVE-2026-35174 , CVE-2026-85160 , CVE-2026-76210 , CVE-2026-54134 , CVE-2026-35593 , CVE-2026-46397 , CVE-2026-75602 , CVE-2026-79653 , CVE-2026-40605 , CVE-2026-10694 , CVE-2026-34967 , CVE-2026-10559
CWE-74CVE-2020-17496 , CVE-2024-36420 , CVE-2026-16252 , CVE-2026-7206
CWE-78CVE-2026-17623 , CVE-2026-17625 , CVE-2026-25855
CWE-79CVE-2026-45668 , CVE-2014-9146
CWE-89CVE-2010-4977 , CVE-2010-5028 , CVE-2014-9145 , CVE-2026-16252 , CVE-2026-7206
CWE-94CVE-2026-25856 , CVE-2021-32820 , CVE-2010-2918
CWE-98CVE-2024-12209 , CVE-2025-32614 , CVE-2026-87927 , CVE-2025-48157 , CVE-2026-44239 , CVE-2026-39387 , CVE-2019-25760 , CVE-2022-50954
CWE-116CVE-2024-38473
CWE-180CVE-2026-39364
CWE-200CVE-2026-51027 , CVE-2026-65760 , CVE-2026-47394 , CVE-2026-62865 , CVE-2021-32820 , CVE-2026-44881 , CVE-2026-39363 , CVE-2026-53553 , CVE-2014-9147 , CVE-2015-1000012 , CVE-2017-16894 , CVE-2018-6008 , CVE-2021-24227 , CVE-2021-43287 , CVE-2023-34092 , CVE-2024-45388 , CVE-2024-46938 , CVE-2025-30208 , CVE-2025-31125 , CVE-2026-61891 , CVE-2026-47735 , CVE-2016-6435 , CVE-2026-29066 , CVE-2025-31486 , CVE-2026-53452
CWE-206CVE-2026-85199
CWE-269CVE-2026-11423
CWE-284CVE-2014-9148 , CVE-2026-65760 , CVE-2026-65759 , CVE-2023-26360 , CVE-2026-39364 , CVE-2015-1000010 , CVE-2025-30208 , CVE-2025-31125 , CVE-2025-28367 , CVE-2025-31486
CWE-285CVE-2024-26291 , CVE-2026-46484
CWE-287CVE-2018-12613 , CVE-2025-32815
CWE-288CVE-2020-10148
CWE-306CVE-2020-10148 , CVE-2026-39363 , CVE-2026-61891 , CVE-2026-46555 , CVE-2026-65012
CWE-327CVE-2025-2539
CWE-345CVE-2026-48105
CWE-346CVE-2026-46555
CWE-352CVE-2021-24947
CWE-400CVE-2026-26477
CWE-425CVE-2026-35029
CWE-434CVE-2022-47615 , CVE-2026-11419 , CVE-2026-35174 , CVE-2021-24947
CWE-441CVE-2026-73079
CWE-472CVE-2026-39364
CWE-473CVE-2023-36845
CWE-538CVE-2024-51977
CWE-552CVE-2021-4463 , CVE-2020-17519 , CVE-2021-39316 , CVE-2022-0656 , CVE-2022-33901 , CVE-2026-29066 , CVE-2022-25497
CWE-644CVE-2026-48126
CWE-665CVE-2019-19411
CWE-668CVE-2022-24900 , CVE-2023-33510 , CVE-2026-82650
CWE-669CVE-2026-73574
CWE-706CVE-2023-34092 , CVE-2024-27292
CWE-732CVE-2018-14916
CWE-770CVE-2026-26477
CWE-824CVE-2026-67281
CWE-829CVE-2018-17246 , CVE-2026-45711 , CVE-2022-25485 , CVE-2022-25486 , CVE-2018-7422 , CVE-2022-34121
CWE-862CVE-2026-47754 , CVE-2023-52163 , CVE-2026-47394 , CVE-2023-6038
CWE-863CVE-2026-35029 , CVE-2021-24947
CWE-913CVE-2026-48105
CWE-918CVE-2026-47659 , CVE-2026-7412 , CVE-2026-47735
CWE-1220CVE-2026-39363
CWE-1391CVE-2024-51978

Documentation Source

  • Original wiki page: WAF 390709
  • Source revision: 2734
  • Source revision date: 2012-09-20