On this page
Atomicorp WAF Rule 390709
Rule Summary
- Rule ID: 390709
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Attempt to access protected file remotely
- Observed CWEs: CWE-20 (7), CWE-22 (487), CWE-23 (7), CWE-24 (1), CWE-29 (5), CWE-36 (2), CWE-50 (1), CWE-59 (1), CWE-73 (22), CWE-74 (4), CWE-78 (3), CWE-79 (2), CWE-89 (5), CWE-94 (3), CWE-98 (8), CWE-116 (1), CWE-180 (1), CWE-200 (25), CWE-206 (1), CWE-269 (1), CWE-284 (10), CWE-285 (2), CWE-287 (2), CWE-288 (1), CWE-306 (5), CWE-327 (1), CWE-345 (1), CWE-346 (1), CWE-352 (1), CWE-400 (1), CWE-425 (1), CWE-434 (4), CWE-441 (1), CWE-472 (1), CWE-473 (1), CWE-538 (1), CWE-552 (7), CWE-644 (1), CWE-665 (1), CWE-668 (3), CWE-669 (1), CWE-706 (2), CWE-732 (1), CWE-770 (1), CWE-824 (1), CWE-829 (6), CWE-862 (4), CWE-863 (2), CWE-913 (1), CWE-918 (3), CWE-1220 (1), CWE-1391 (1)
- Revision: 30
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request filename, Request argument names, Request arguments, JSON request data, SOAP request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects when a protected file is accessed remotely. This rule specifically protects sensitive OS and application configuration files, such as webserver configuration files, operating system configuration files, password files, and command history files.
Troubleshooting
False Positives
A false positive can occur when an application legitimately requires access to these files. The rules contain a large library of known web applications and safe methods for access these highly sensitive files, and can detect known safe methods and ignore them. However it is possible for a new or custom application to do this in an unknown manner and incorrectly trigger this rule.
It is not recommended that you disable this rule if you have a false positive. If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.
Tuning Guidance
If you know that this behavior is acceptable for your application, you can either disable the rule for the domain, or you can disable it for the application. Please see the Tuning the Atomicorp WAF Rules page for basic information.
Additional Information
Similar Rules
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2009-0545 | ZeroShell <= 1.0beta11 Remote Code Execution | zeroshell | 10.0 (v2.0) | High |
| CVE-2010-5286 | Joomla! Component Jstore - 'Controller' Local File Inclusion | com jstore | 10.0 (v2.0) | High |
| CVE-2026-51027 | FileThingie v.2.5.7 Information Disclosure Vulnerability | - | 9.9 (v3.1) | Critical |
| CVE-2010-2861 | Adobe ColdFusion - Directory Traversal | coldfusion | 9.8 (v3.1) | Critical |
| CVE-2014-9148 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 9.8 (v3.0) | Critical |
| CVE-2018-12031 | Eaton Intelligent Power Manager 1.6 - Directory Traversal | intelligent power manager | 9.8 (v3.0) | Critical |
| CVE-2018-16283 | WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusion | wechat brodcast | 9.8 (v3.0) | Critical |
| CVE-2018-17246 | Kibana - Local File Inclusion | kibana | 9.8 (v3.0) | Critical |
| CVE-2019-9618 | WordPress GraceMedia Media Player 1.0 - Local File Inclusion | gracemedia media player | 9.8 (v3.0) | Critical |
| CVE-2020-10148 | SolarWinds Orion API - Auth Bypass | orion platform | 9.8 (v3.1) | Critical |
| CVE-2020-17496 | vBulletin 5.5.4 - 5.6.2- Remote Command Execution | vbulletin | 9.8 (v3.1) | Critical |
| CVE-2020-29227 | Car Rental Management System 1.0 - Local File Inclusion | car rental management system | 9.8 (v3.1) | Critical |
| CVE-2020-5902 | F5 BIG-IP TMUI - Remote Code Execution | big-ip access policy manager | 9.8 (v3.1) | Critical |
| CVE-2021-40960 | Galera WebTemplate 1.0 Directory Traversal | galera webtemplate | 9.8 (v3.1) | Critical |
| CVE-2022-0679 | WordPress Narnoo Distributor <=2.5.1 - Local File Inclusion | narnoo distributor | 9.8 (v3.1) | Critical |
| CVE-2022-1390 | WordPress Admin Word Count Column 2.2 - Local File Inclusion | admin word count column | 9.8 (v3.1) | Critical |
| CVE-2022-1391 | WordPress Cab fare calculator < 1.0.4 - Local File Inclusion | cab fare calculator | 9.8 (v3.1) | Critical |
| CVE-2022-32409 | Portal do Software Publico Brasileiro i3geo 7.0.5 - Local File Inclusion | i3geo | 9.8 (v3.1) | Critical |
| CVE-2022-41840 | Welcart eCommerce <=2.7.7 - Local File Inclusion | welcart e-commerce | 9.8 (v3.1) | Critical |
| CVE-2022-47615 | LearnPress Plugin < 4.2.0 - Local File Inclusion | learnpress | 9.8 (v3.1) | Critical |
| CVE-2023-3643 | CAREL Boss Mini <= 1.4.0 - Local File Inclusion | boss-mini | 9.8 (v3.1) | Critical |
| CVE-2023-36845 | Juniper J-Web - Remote Code Execution | junos | 9.8 (v3.1) | Critical |
| CVE-2023-5991 | Hotel Booking Lite < 4.8.5 - Arbitrary File Download & Deletion | hotel booking lite | 9.8 (v3.1) | Critical |
| CVE-2024-12209 | WP Umbrella Update Backup Restore & Monitoring <= 2.17.0 - Local File Inclusion | wp-umbrella | 9.8 (v3.1) | Critical |
| CVE-2024-51978 | Brother Printers – Authentication Bypass via Default Admin Password | DCP-J928N-W/B | 9.8 (v3.1) | Critical |
| CVE-2025-2294 | Kubio AI Page Builder <= 2.5.1 - Local File Inclusion | Kubio AI Page Builder | 9.8 (v3.1) | Critical |
| CVE-2025-4524 | WordPress Madara - Local File Inclusion | Madara – Responsive and modern WordPress theme for manga sites | 9.8 (v3.1) | Critical |
| CVE-2025-47445 | WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download | eventin | 9.8 (v3.1) | Critical |
| CVE-2026-35471 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs | goshs | 9.8 (v3.0) | Critical |
| CVE-2026-75337 | The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 Path Traversal Vulnerability | - | 9.8 (v3.1) | Critical |
| CVE-2026-11419 | Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Write | on-prem enterprise server | 9.4 (v4.0) | Critical |
| CVE-2026-11423 | Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege Escalation | Altium Enterprise Server | 9.4 (v4.0) | Critical |
| CVE-2026-72850 | Budibase before 3.40.0 Arbitrary File Write via Path Traversal | server | 9.4 (v4.0) | Critical |
| CVE-2026-77086 | SiYuan before v3.7.4 Path Traversal via packageName | siyuan | 9.4 (v4.0) | Critical |
| CVE-2019-25727 | WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download | Ad Manager WD | 9.3 (v4.0) | Critical |
| CVE-2026-23734 | XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash | xwiki-commons | 9.3 (v4.0) | Critical |
| CVE-2026-44343 | WGDashboard < 4.3.2 - Unauthenticated File Read | wgdashboard | 9.3 (v4.0) | Critical |
| CVE-2026-45668 | Trilium Notes : Note Import to RCE via #docName Path Traversal (Safe Import Enabled) | Trilium | 9.3 (v4.0) | Critical |
| CVE-2026-47669 | DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE | dbgate | 9.3 (v4.0) | Critical |
| CVE-2026-47754 | unauthenticated path traversal in Metacat 2.x | metacat | 9.3 (v3.1) | Critical |
| CVE-2026-53976 | OpenChamber <1.13.0 - Unauthenticated Arbitrary File Read | OpenChamber | 9.3 (v4.0) | Critical |
| CVE-2026-65700 | h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API | h2ogpt | 9.3 (v4.0) | Critical |
| CVE-2026-65701 | SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route | so-vits-svc | 9.3 (v4.0) | Critical |
| CVE-2026-69110 | OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music | opencode-studio | 9.3 (v4.0) | Critical |
| CVE-2026-74798 | SiYuan kernel Path Traversal via database_clean MCP tool | siyuan | 9.3 (v4.0) | Critical |
| CVE-2026-80104 | DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload Filename | DB-GPT | 9.3 (v4.0) | Critical |
| CVE-2026-86189 | WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php | AVideo | 9.3 (v4.0) | Critical |
| CVE-2026-65760 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0 | Easy Store extension for Joomla | 9.2 (v4.0) | Critical |
| CVE-2018-14916 | Loytec LGATE-902 <6.4.2 - Local File Inclusion | lgate-902 | 9.1 (v3.0) | Critical |
| CVE-2018-16716 | NCBI ToolBox - Directory Traversal | ncbi toolbox | 9.1 (v3.0) | Critical |
| CVE-2018-19365 | Wowza Streaming Engine Manager 4.7.4.01 - Directory Traversal | streaming engine | 9.1 (v3.1) | Critical |
| CVE-2022-26960 | elFinder <=2.1.60 - Local File Inclusion | elfinder | 9.1 (v3.1) | Critical |
| CVE-2024-3673 | Web Directory Free < 1.7.3 - Local File Inclusion | web directory free | 9.1 (v3.1) | Critical |
| CVE-2024-40422 | Devika v1 - Path Traversal | devika | 9.1 (v3.1) | Critical |
| CVE-2025-55526 | n8n workflow collection Path Traversal Vulnerability | n8n workflow collection | 9.1 (v3.1) | Critical |
| CVE-2026-34745 | Unauthenticated Path Traversal Arbitrary File Write in /api/uploadChunked/public | fireshare | 9.1 (v3.1) | Critical |
| CVE-2026-47731 | NASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by u | AIT-Core | 9.1 (v3.1) | Critical |
| CVE-2026-48024 | Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager | wazuh | 9.1 (v3.1) | Critical |
| CVE-2026-48162 | Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file pa | wazuh | 9.1 (v3.1) | Critical |
| CVE-2026-52610 | reportico-web <= 8.1.0 Path Traversal Vulnerability | reportico-web <= 8.1.0 | 9.1 (v3.1) | Critical |
| CVE-2008-4668 | Joomla! Image Browser 0.1.5 rc2 - Local File Inclusion | com imagebrowser | 9.0 (v2.0) | High |
| CVE-2026-53581 | ntp: write path traversal | core | 9.0 (v3.1) | Critical |
| CVE-2018-12613 | PhpMyAdmin <4.8.2 - Local File Inclusion | phpmyadmin | 8.8 (v3.1) | High |
| CVE-2018-15142 | OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions | openemr | 8.8 (v3.0) | High |
| CVE-2019-14530 | OpenEMR <5.0.2 - Local File Inclusion | openemr | 8.8 (v3.1) | High |
| CVE-2020-8641 | Lotus Core CMS 1.0.1 - Local File Inclusion | lotus core cms | 8.8 (v3.1) | High |
| CVE-2023-52163 | Digiever DS-2105 Pro - Command Injection | ds-2105 pro firmware | 8.8 (v3.1) | High |
| CVE-2025-32614 | EventON Lite <= 2.4 - Authenticated Local File Inclusion | flavor | 8.8 (v3.1) | High |
| CVE-2026-17623 | Langflow is affected OS Command Injection in Model Context Protocol features | langflow | 8.8 (v3.1) | High |
| CVE-2026-17625 | Langflow is affected by OS Command Injection in Model Context Protocol features | langflow | 8.8 (v3.1) | High |
| CVE-2026-34524 | SillyTavern: Path traversal in /api/chats/export and /api/chats/delete allows arbitrary file read/delete within user | sillytavern | 8.8 (v3.1) | High |
| CVE-2026-36723 | the /api/create-user component of bookcars v8.3 Arbitrary Code Execution Vulnerability | the /api/create-user component of bookcars v8.3 | 8.8 (v3.1) | High |
| CVE-2026-42605 | AzuraCast: Path Traversal in currentDirectory Parameter Enables Remote Code Execution via Media Upload | azuracast | 8.8 (v3.1) | High |
| CVE-2026-43624 | F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project() | F5-TTS | 8.8 (v4.0) | High |
| CVE-2026-44829 | Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filename | gotenberg | 8.8 (v3.1) | High |
| CVE-2026-50186 | 4gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Board Export | 4gaBoards | 8.8 (v3.1) | High |
| CVE-2026-62677 | Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUN | omnigent | 8.8 (v3.1) | High |
| CVE-2026-65702 | Vanna 2.0.2 Path Traversal via FileSystemConversationStore | vanna | 8.8 (v4.0) | High |
| CVE-2026-76842 | Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment Clients | mercadopago | 8.8 (v4.0) | High |
| CVE-2026-81730 | Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filename | dolibarr erp/crm | 8.8 (v4.0) | High |
| CVE-2026-82286 | gpt-crawler Arbitrary File Write via outputFileName Parameter | gpt-crawler | 8.8 (v4.0) | High |
| CVE-2026-85199 | Eclipse aeriOS Path Traversal Vulnerability | Eclipse aeriOS | 8.8 (v4.0) | High |
| CVE-2026-86542 | knowns before 0.30.0 Path Traversal via Import Name | knowns | 8.8 (v4.0) | High |
| CVE-2026-86775 | knowns before 0.30.0 Path Traversal via Document API | knowns | 8.8 (v4.0) | High |
| CVE-2026-87927 | MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher | MaxSite CMS | 8.8 (v4.0) | High |
| CVE-2017-20248 | WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download | Apptha Slider Gallery | 8.7 (v4.0) | High |
| CVE-2017-20250 | WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download | Mac Photo Gallery | 8.7 (v4.0) | High |
| CVE-2018-25374 | Softneta MedDream PACS Server Premium 6.7.1.1 Directory Traversal | MedDream PACS Server Premium | 8.7 (v4.0) | High |
| CVE-2021-4463 | Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File Download | BEMS API | 8.7 (v4.0) | High |
| CVE-2024-26291 | Avid NEXIS Agent - Arbitrary File Read | nexis | 8.7 (v4.0) | High |
| CVE-2026-10108 | xiaomusic 0.5.7 Path Traversal via GET /music endpoint | xiaomusic | 8.7 (v4.0) | High |
| CVE-2026-17524 | zip-lib Path Traversal Vulnerability | zip-lib | 8.7 (v4.0) | High |
| CVE-2026-25559 | OpenBullet2 0.3.2 Path Traversal via Wordlist Endpoint | openbullet2 | 8.7 (v4.0) | High |
| CVE-2026-25855 | OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload | openbullet2 | 8.7 (v4.0) | High |
| CVE-2026-25856 | OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface | openbullet2 | 8.7 (v4.0) | High |
| CVE-2026-35029 | LiteLLM - Arbitrary File Read | litellm | 8.7 (v4.0) | High |
| CVE-2026-35214 | Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write | budibase | 8.7 (v3.1) | High |
| CVE-2026-39352 | Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path Traversal | frappe | 8.7 (v4.0) | High |
| CVE-2026-43982 | Algernon: Path traversal file write via savein() | algernon | 8.7 (v4.0) | High |
| CVE-2026-47394 | PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate | PraisonAI | 8.7 (v4.0) | High |
| CVE-2026-47659 | Pathling has path traversal in $import-pnp manifest that enables read-capable SSRF via /jobs/{jobId}/{filename} | pathling | 8.7 (v4.0) | High |
| CVE-2026-47661 | Pathling has path traversal in $result endpoint that allows arbitrary warehouse file read | pathling | 8.7 (v4.0) | High |
| CVE-2026-57863 | Crater Invoice 6.0.6 Path Traversal RCE via update/unzip endpoint | crater | 8.7 (v4.0) | High |
| CVE-2026-62865 | TypeBot: Arbitrary server file read via Send Email block attachment path | typebot.io | 8.7 (v4.0) | High |
| CVE-2026-65694 | Microweber CMS <= 2.0.20 - Unauthenticated Arbitrary File Read | microweber | 8.7 (v4.0) | High |
| CVE-2026-65759 | Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 | Easy Store extension for Joomla | 8.7 (v4.0) | High |
| CVE-2026-65919 | Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload | meshery | 8.7 (v4.0) | High |
| CVE-2026-67200 | Perspective 5.0.0 Path Traversal via cwd_static_file_handler | perspective | 8.7 (v4.0) | High |
| CVE-2026-67281 | Unauthenticated file read in Mikrotik RouterOS | RouterOS | 8.7 (v4.0) | High |
| CVE-2026-69089 | Grav CMS before 2.0.11 Path Traversal via watermark | grav | 8.7 (v4.0) | High |
| CVE-2026-69095 | OpenWrt luci-app-bmx7 Path Traversal via bmx7-info | luci | 8.7 (v4.0) | High |
| CVE-2026-72713 | XAgent Path Traversal Arbitrary File Read via /workspace/file | XAgent | 8.7 (v4.0) | High |
| CVE-2026-75111 | Evidently UI Path Traversal via Dataset Materialization Filename | evidently | 8.7 (v4.0) | High |
| CVE-2026-75482 | SWE-agent Trajectory Inspector Path Traversal File Disclosure | SWE-agent | 8.7 (v4.0) | High |
| CVE-2026-75914 | CodeWhale before 0.8.64 Path Traversal via image_analyze symlink | CodeWhale | 8.7 (v4.0) | High |
| CVE-2026-85685 | AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skill | agentscope | 8.7 (v4.0) | High |
| CVE-2026-86538 | knowns before 0.30.0 Path Traversal via templateFile parameter | knowns | 8.7 (v4.0) | High |
| CVE-2026-9506 | Path Traversal Vulnerability in Bagisto | Bagisto | 8.7 (v4.0) | High |
| CVE-2015-4694 | WordPress Zip Attachments <= 1.1.4 - Arbitrary File Retrieval | zip attachments | 8.6 (v3.0) | High |
| CVE-2021-32820 | Express-handlebars - Local File Inclusion | express handlebars | 8.6 (v3.1) | High |
| CVE-2022-24900 | Piano LED Visualizer 1.3 - Local File Inclusion | piano led visualizer | 8.6 (v3.1) | High |
| CVE-2023-26360 | Adobe ColdFusion - Local File Read | coldfusion | 8.6 (v3.1) | High |
| CVE-2024-34470 | HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusion | mailinspector | 8.6 (v3.1) | High |
| CVE-2025-2558 | WordPress The Wound Theme <= 0.0.1 - Local File Inclusion | the wound | 8.6 (v3.1) | High |
| CVE-2026-11974 | Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download | wp-media-folder-addon | 8.6 (v3.1) | High |
| CVE-2026-46491 | SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditi | simplesamlphp-module-casserver | 8.6 (v3.1) | High |
| CVE-2026-50553 | Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) | note-mark | 8.6 (v4.0) | High |
| CVE-2026-7412 | Eclipse BaSyx SSRF Vulnerability | Eclipse BaSyx | 8.6 (v3.1) | High |
| CVE-2015-2996 | SysAid Help Desk <15.2 - Local File Inclusion | sysaid | 8.5 (v2.0) | High |
| CVE-2025-34023 | Karel IP Phone IP1211 Web Management Panel - Local File Inclusion | Karel IP Phone IP1211 | 8.5 (v4.0) | High |
| CVE-2026-16033 | Arbitrary file read+write on host via templates/ symlink in malicious image | LXD | 8.5 (v3.1) | High |
| CVE-2026-44881 | Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update | portainer | 8.5 (v4.0) | High |
| CVE-2026-73079 | Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstrea | sub2api | 8.5 (v3.1) | High |
| CVE-2026-75855 | ArcadeDB before 26.8.1 Path Traversal via create/drop database | arcadedb | 8.4 (v4.0) | High |
| CVE-2026-48105 | Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path | arc | 8.3 (v4.0) | High |
| CVE-2026-69086 | SiYuan before v3.7.3 Path Traversal via unvalidated avID | siyuan | 8.3 (v4.0) | High |
| CVE-2026-75842 | ArcadeDB before 26.8.1 Arbitrary File Read via LOAD CSV | arcadedb | 8.3 (v4.0) | High |
| CVE-2026-82673 | Path traversal in AshAdmin file uploads via unsanitized client filename | ash admin | 8.3 (v4.0) | High |
| CVE-2025-44137 | MapTiler Tileserver-php v2.0 - Unauthenticated File Read | tileserver php | 8.2 (v3.1) | High |
| CVE-2026-39363 | Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket | vite | 8.2 (v4.0) | High |
| CVE-2026-39364 | Vite Dev Server - Directory Traversal | vite | 8.2 (v4.0) | High |
| CVE-2026-40075 | OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServlet | openmrs | 8.2 (v4.0) | High |
| CVE-2026-45711 | Mailpit: Path traversal & arbitrary file write in mailpit dump –http via attacker-controlled message IDs | mailpit | 8.2 (v3.1) | High |
| CVE-2026-48126 | Algernon: Host header path traversal in –domain mode reads files and runs Lua from parent dir | algernon | 8.2 (v3.1) | High |
| CVE-2026-74907 | Grav before 2.0.15 Path Traversal via plugin-asset-map.php | grav | 8.2 (v4.0) | High |
| CVE-2023-6831 | mlflow - Path Traversal | mlflow | 8.1 (v3.1) | High |
| CVE-2024-38473 | Apache HTTP Server - ACL Bypass | Apache HTTP Server | 8.1 (v3.1) | High |
| CVE-2025-48157 | WordPress Formality Plugin <= 1.5.9 - Local File Inclusion | Formality | 8.1 (v3.1) | High |
| CVE-2026-19303 | Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing c | langflow | 8.1 (v3.1) | High |
| CVE-2026-33236 | NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite | nltk | 8.1 (v3.1) | High |
| CVE-2026-34522 | SillyTavern: Path traversal in /api/chats/import allows arbitrary file write outside intended chat directory | sillytavern | 8.1 (v3.1) | High |
| CVE-2026-46484 | Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/user | headplane | 8.1 (v3.1) | High |
| CVE-2026-54083 | Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletion | wazuh | 8.1 (v3.1) | High |
| CVE-2026-64679 | Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creation | atlantis | 8.1 (v3.1) | High |
| CVE-2026-73659 | Trigger.dev: Cross-tenant object read/write via path traversal in packet presign API | trigger.dev | 8.1 (v3.1) | High |
| CVE-2009-1558 | Cisco Linksys WVC54GCA 1.00R22/1.00R24 - Local File Inclusion | wvc54gca | 7.8 (v2.0) | High |
| CVE-2011-3315 | Cisco CUCM, UCCX, and Unified IP-IVR- Directory Traversal | unified ip interactive voice response | 7.8 (v2.0) | High |
| CVE-2014-2962 | Belkin N150 Router 1.00.08/1.00.09 - Path Traversal | n150 f9k1009 firmware | 7.8 (v2.0) | High |
| CVE-2022-25485 | Cuppa CMS v1.0 - Local File Inclusion | cuppacms | 7.8 (v3.1) | High |
| CVE-2022-25486 | Cuppa CMS v1.0 - Local File Inclusion | cuppacms | 7.8 (v3.1) | High |
| CVE-2026-65600 | Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex | traefik | 7.8 (v4.0) | High |
| CVE-2026-67309 | Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass | traefik | 7.8 (v4.0) | High |
| CVE-2020-35749 | WordPress Simple Job Board <2.9.4 - Local File Inclusion | simple board job | 7.7 (v3.1) | High |
| CVE-2021-21234 | Spring Boot Actuator Logview Directory Traversal | spring-boot-actuator-logview | 7.7 (v3.1) | High |
| CVE-2026-47179 | Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in Arcane | arcane | 7.7 (v3.1) | High |
| CVE-2026-53553 | Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise | goploy | 7.7 (v3.1) | High |
| CVE-2026-54910 | FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files | filebrowser | 7.7 (v3.1) | High |
| CVE-2026-73498 | MCP Atlassian is a Model Context Protocol (MCP): Arbitrary file read via missing path validation in confluence_upload_at | mcp-atlassian | 7.7 (v3.1) | High |
| CVE-2026-8183 | Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement | langflow | 7.7 (v3.1) | High |
| CVE-2026-39369 | WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs | avideo | 7.6 (v3.1) | High |
| CVE-2026-44239 | FreePBX: Authenticated Local File Inclusion in Dashboard Module | freepbx | 7.6 (v4.0) | High |
| CVE-2026-65695 | Office-Word-MCP-Server 1.1.11 Path Traversal via document tools | Office-Word-MCP-Server | 7.6 (v4.0) | High |
| CVE-2006-2842 | Squirrelmail <=1.4.6 - Local File Inclusion | squirrelmail | 7.5 (v2.0) | High |
| CVE-2009-1479 | boxalino 09.05.25-0421 - Directory Traversal | boxalino | 7.5 (v2.0) | High |
| CVE-2009-2015 | Joomla! MooFAQ 1.0 - Local File Inclusion | Joomla! | 7.5 (v2.0) | High |
| CVE-2009-3318 | Joomla! Roland Breedveld Album 1.14 - Local File Inclusion | Joomla! | 7.5 (v2.0) | High |
| CVE-2009-4202 | Joomla! Omilen Photo Gallery 0.5b - Local File Inclusion | joomla! | 7.5 (v2.0) | High |
| CVE-2009-4679 | Joomla! Portfolio Nexus - Remote File Inclusion | com if nexus | 7.5 (v2.0) | High |
| CVE-2010-0157 | Joomla! Component com_biblestudy - Local File Inclusion | joomla! | 7.5 (v2.0) | High |
| CVE-2010-0759 | Joomla! Plugin Core Design Scriptegrator - Local File Inclusion | scriptegrator plugin | 7.5 (v2.0) | High |
| CVE-2010-0972 | Joomla! Component com_gcalendar Suite 2.1.5 - Local File Inclusion | com gcalendar | 7.5 (v2.0) | High |
| CVE-2010-0985 | Joomla! Component com_abbrev - Local File Inclusion | com abbrev | 7.5 (v2.0) | High |
| CVE-2010-1306 | Joomla! Component Picasa 2.0 - Local File Inclusion | com joomlapicasa2 | 7.5 (v2.0) | High |
| CVE-2010-1470 | Joomla! Component Web TV 1.0 - Local File Inclusion | com webtv | 7.5 (v2.0) | High |
| CVE-2010-1471 | Joomla! Component Address Book 1.5.0 - Local File Inclusion | com addressbook | 7.5 (v2.0) | High |
| CVE-2010-1472 | Joomla! Component Horoscope 1.5.0 - Local File Inclusion | com horoscope | 7.5 (v2.0) | High |
| CVE-2010-1495 | Joomla! Component Matamko 1.01 - Local File Inclusion | com matamko | 7.5 (v2.0) | High |
| CVE-2010-1531 | Joomla! Component redSHOP 1.0 - Local File Inclusion | com redshop | 7.5 (v2.0) | High |
| CVE-2010-1533 | Joomla! Component TweetLA 1.0.1 - Local File Inclusion | com tweetla | 7.5 (v2.0) | High |
| CVE-2010-1535 | Joomla! Component TRAVELbook 1.0.1 - Local File Inclusion | com travelbook | 7.5 (v2.0) | High |
| CVE-2010-1602 | Joomla! Component ZiMB Comment 0.8.1 - Local File Inclusion | com zimbcomment | 7.5 (v2.0) | High |
| CVE-2010-1603 | Joomla! Component ZiMBCore 0.1 - Local File Inclusion | com zimbcore | 7.5 (v2.0) | High |
| CVE-2010-1653 | Joomla! Component Graphics 1.0.6 - Local File Inclusion | com graphics | 7.5 (v2.0) | High |
| CVE-2010-1717 | Joomla! Component iF surfALERT 1.2 - Local File Inclusion | if surfalert | 7.5 (v2.0) | High |
| CVE-2010-1875 | Joomla! Component Property - Local File Inclusion | com properties | 7.5 (v2.0) | High |
| CVE-2010-1878 | Joomla! Component OrgChart 1.0.0 - Local File Inclusion | com orgchart | 7.5 (v2.0) | High |
| CVE-2010-1952 | Joomla! Component BeeHeard 1.0 - Local File Inclusion | com beeheard | 7.5 (v2.0) | High |
| CVE-2010-1953 | Joomla! Component iNetLanka Multiple Map 1.0 - Local File Inclusion | com multimap | 7.5 (v2.0) | High |
| CVE-2010-1954 | Joomla! Component iNetLanka Multiple root 1.0 - Local File Inclusion | com multiroot | 7.5 (v2.0) | High |
| CVE-2010-1955 | Joomla! Component Deluxe Blog Factory 1.1.2 - Local File Inclusion | com blogfactory | 7.5 (v2.0) | High |
| CVE-2010-1956 | Joomla! Component Gadget Factory 1.0.0 - Local File Inclusion | com gadgetfactory | 7.5 (v2.0) | High |
| CVE-2010-1957 | Joomla! Component Love Factory 1.3.4 - Local File Inclusion | com lovefactory | 7.5 (v2.0) | High |
| CVE-2010-1977 | Joomla! Component J!WHMCS Integrator 1.5.0 - Local File Inclusion | com jwhmcs | 7.5 (v2.0) | High |
| CVE-2010-1980 | Joomla! Component Joomla! Flickr 1.0 - Local File Inclusion | com joomlaflickr | 7.5 (v2.0) | High |
| CVE-2010-1983 | Joomla! Component redTWITTER 1.0 - Local File Inclusion | com redtwitter | 7.5 (v2.0) | High |
| CVE-2010-2033 | Joomla! Percha Categories Tree 0.6 - Local File Inclusion | com perchacategoriestree | 7.5 (v2.0) | High |
| CVE-2010-2034 | Joomla! Component Percha Image Attach 1.1 - Directory Traversal | com perchaimageattach | 7.5 (v2.0) | High |
| CVE-2010-2035 | Joomla! Component Percha Gallery 1.6 Beta - Directory Traversal | com perchagallery | 7.5 (v2.0) | High |
| CVE-2010-2036 | Joomla! Component Percha Fields Attach 1.0 - Directory Traversal | com perchafieldsattach | 7.5 (v2.0) | High |
| CVE-2010-2037 | Joomla! Component Percha Downloads Attach 1.1 - Directory Traversal | com perchadownloadsattach | 7.5 (v2.0) | High |
| CVE-2010-2045 | Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusion | com dioneformwizard | 7.5 (v2.0) | High |
| CVE-2010-2050 | Joomla! Component MS Comment 0.8.0b - Local File Inclusion | com mscomment | 7.5 (v2.0) | High |
| CVE-2010-2128 | Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusion | com jequoteform | 7.5 (v2.0) | High |
| CVE-2010-2259 | Joomla! Component com_bfsurvey - Local File Inclusion | com bfsurvey profree | 7.5 (v2.0) | High |
| CVE-2010-2682 | Joomla! Component Realtyna Translator 1.0.15 - Local File Inclusion | com realtyna | 7.5 (v2.0) | High |
| CVE-2010-2918 | Joomla! Component Visites 1.1 - MosConfig_absolute_path Remote File Inclusion | com joomla visites | 7.5 (v2.0) | High |
| CVE-2010-3426 | Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusion | com jphone | 7.5 (v2.0) | High |
| CVE-2010-4282 | Pandora Fms < 3.1.1 - Directory Traversal | pandora fms | 7.5 (v2.0) | High |
| CVE-2010-4719 | Joomla! Component JRadio - Local File Inclusion | com jradio | 7.5 (v2.0) | High |
| CVE-2010-4769 | Joomla! Component Jimtawl 1.0.2 - Local File Inclusion | com jimtawl | 7.5 (v2.0) | High |
| CVE-2010-4977 | Joomla! Component Canteen 1.0 - Local File Inclusion | com canteen | 7.5 (v2.0) | High |
| CVE-2010-5028 | Joomla! Component JE Job 1.0 - Local File Inclusion | com jejob | 7.5 (v2.0) | High |
| CVE-2012-1226 | Dolibarr ERP/CRM 3.2 Alpha - Multiple Directory Traversal Vulnerabilities | dolibarr erp/crm | 7.5 (v2.0) | High |
| CVE-2014-10037 | DomPHP 0.83 - Directory Traversal | domphp | 7.5 (v2.0) | High |
| CVE-2014-9145 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 7.5 (v2.0) | High |
| CVE-2014-9147 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 7.5 (v3.0) | High |
| CVE-2015-1000005 | WordPress Candidate Application Form <= 1.3 - Local File Inclusion | candidate-application-form | 7.5 (v3.0) | High |
| CVE-2015-1000010 | WordPress Simple Image Manipulator < 1.0 - Local File Inclusion | simple-image-manipulator | 7.5 (v3.0) | High |
| CVE-2015-1000012 | WordPress MyPixs <=0.3 - Local File Inclusion | mypixs | 7.5 (v3.0) | High |
| CVE-2015-1503 | IceWarp Mail Server < 11.1.1 - Directory Traversal | mail server | 7.5 (v3.0) | High |
| CVE-2015-3648 | ResourceSpace - Local File inclusion | resourcespace | 7.5 (v2.0) | High |
| CVE-2015-4074 | Joomla! Helpdesk Pro plugin <1.4.0 - Local File Inclusion | helpdesk pro | 7.5 (v3.0) | High |
| CVE-2015-4632 | Koha 3.20.1 - Directory Traversal | koha | 7.5 (v3.0) | High |
| CVE-2015-5469 | WordPress MDC YouTube Downloader 2.1.0 - Local File Inclusion | mdc youtube downloader | 7.5 (v3.0) | High |
| CVE-2016-10367 | Opsview Monitor Pro - Local File Inclusion | opsview | 7.5 (v3.0) | High |
| CVE-2016-10956 | WordPress Mail Masta 1.0 - Local File Inclusion | mail-masta | 7.5 (v3.1) | High |
| CVE-2016-2389 | SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File Inclusion | netweaver | 7.5 (v3.0) | High |
| CVE-2016-6601 | WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities | webnms framework | 7.5 (v3.0) | High |
| CVE-2017-15647 | FiberHome Routers - Local File Inclusion | routerfiberhome firmware | 7.5 (v3.0) | High |
| CVE-2017-16806 | Ulterius Server < 1.9.5.0 - Directory Traversal | ulterius server | 7.5 (v3.0) | High |
| CVE-2017-16894 | Laravel <5.5.21 - Information Disclosure | laravel | 7.5 (v3.0) | High |
| CVE-2017-9833 | BOA Web Server 0.94.14 - Arbitrary File Access | boa | 7.5 (v3.1) | High |
| CVE-2018-12909 | Webgrind <= 1.5 - Local File Inclusion | webgrind | 7.5 (v3.0) | High |
| CVE-2018-14912 | cgit < 1.2.1 - Directory Traversal | cgit | 7.5 (v3.0) | High |
| CVE-2018-14918 | LOYTEC LGATE-902 6.3.2 - Local File Inclusion | lgate-902 firmware | 7.5 (v3.0) | High |
| CVE-2018-15138 | LG-Ericsson iPECS NMS 30M - Local File Inclusion | ipecs nms | 7.5 (v3.0) | High |
| CVE-2018-15535 | Responsive FileManager < 9.13.4 - Directory Traversal | responsive filemanager | 7.5 (v3.0) | High |
| CVE-2018-16299 | WordPress Localize My Post 1.0 - Local File Inclusion | localize my post | 7.5 (v3.0) | High |
| CVE-2018-19753 | Tarantella Enterprise <3.11 - Local File Inclusion | tarantella enterprise | 7.5 (v3.0) | High |
| CVE-2018-6008 | Joomla! Jtag Members Directory 5.3.7 - Local File Inclusion | jtag members directory | 7.5 (v3.0) | High |
| CVE-2018-7422 | WordPress Site Editor <=1.1.1 - Local File Inclusion | site editor | 7.5 (v3.0) | High |
| CVE-2018-9205 | Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusion | avatar uploader | 7.5 (v3.0) | High |
| CVE-2019-12276 | GrandNode 4.40 - Local File Inclusion | grandnode | 7.5 (v3.0) | High |
| CVE-2019-14251 | T24 Web Server - Local File Inclusion | t24 | 7.5 (v3.1) | High |
| CVE-2019-16123 | PilusCart <=1.4.1 - Local File Inclusion | piluscart | 7.5 (v3.1) | High |
| CVE-2019-18371 | Xiaomi Mi WiFi R3G Routers - Local file Inclusion | millet router 3g firmware | 7.5 (v3.1) | High |
| CVE-2019-18665 | DOMOS 5.5 - Local File Inclusion | domos | 7.5 (v3.1) | High |
| CVE-2019-7254 | eMerge E3 1.00-06 - Local File Inclusion | linear emerge essential firmware | 7.5 (v3.1) | High |
| CVE-2019-9922 | Joomla! Harmis Messenger 1.2.2 - Local File Inclusion | je messenger | 7.5 (v3.1) | High |
| CVE-2020-11738 | WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusion | duplicator | 7.5 (v3.1) | High |
| CVE-2020-13158 | Artica Proxy Community Edition <4.30.000000 - Local File Inclusion | artica proxy | 7.5 (v3.1) | High |
| CVE-2020-14864 | Oracle Fusion - Directory Traversal/Local File Inclusion | business intelligence | 7.5 (v3.1) | High |
| CVE-2020-17519 | Apache Flink - Local File Inclusion | flink | 7.5 (v3.1) | High |
| CVE-2020-19360 | FHEM 6.0 - Local File Inclusion | fhem | 7.5 (v3.1) | High |
| CVE-2020-24285 | INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusion | tip200 | 7.5 (v3.1) | High |
| CVE-2020-27467 | Processwire CMS <2.7.1 - Local File Inclusion | processwire | 7.5 (v3.1) | High |
| CVE-2020-35580 | SearchBlox <9.2.2 - Local File Inclusion | searchblox | 7.5 (v3.1) | High |
| CVE-2020-35598 | Advanced Comment System 1.0 - Local File Inclusion | advanced comment system | 7.5 (v3.1) | High |
| CVE-2020-5410 | Spring Cloud Config Server - Local File Inclusion | spring cloud config | 7.5 (v3.1) | High |
| CVE-2020-8209 | Citrix XenMobile Server - Local File Inclusion | xenmobile server | 7.5 (v3.1) | High |
| CVE-2021-20123 | Draytek VigorConnect 1.6.0-B - Local File Inclusion | vigorconnect | 7.5 (v3.1) | High |
| CVE-2021-20124 | Draytek VigorConnect 6.0-B3 - Local File Inclusion | vigorconnect | 7.5 (v3.1) | High |
| CVE-2021-24227 | Patreon WordPress <1.7.0 - Unauthenticated Local File Inclusion | patreon wordpress | 7.5 (v3.1) | High |
| CVE-2021-39316 | WordPress DZS Zoomsounds <=6.50 - Local File Inclusion | zoomsounds | 7.5 (v3.1) | High |
| CVE-2021-39433 | BIQS IT Biqs-drive v1.83 Local File Inclusion | biqsdrive | 7.5 (v3.1) | High |
| CVE-2021-41291 | ECOA Building Automation System - Directory Traversal Content Disclosure | ecs router controller-ecs firmware | 7.5 (v3.1) | High |
| CVE-2021-43287 | Pre-Auth Takeover of Build Pipelines in GoCD | gocd | 7.5 (v3.1) | High |
| CVE-2021-43778 | GLPI plugin Barcode < 2.6.1 - Path Traversal Vulnerability. | barcode | 7.5 (v3.1) | High |
| CVE-2021-46104 | webp_server_go 0.4.0 - Path Traversal | webp server go | 7.5 (v3.1) | High |
| CVE-2021-46381 | DLINK DAP-1620 A1 v1.01 - Directory Traversal | dap-1620 firmware | 7.5 (v3.1) | High |
| CVE-2022-0656 | uDraw <3.3.3 - Local File Inclusion | [web to print shop](/vendors/webtoprint/web-to-print-shop/) | 7.5 (v3.1) | High |
| CVE-2022-27043 | Yearning - Directory Traversal | yearning | 7.5 (v3.1) | High |
| CVE-2022-29298 | SolarView Compact 6.00 - Local File Inclusion | sv-cpt-mc310 firmware | 7.5 (v3.1) | High |
| CVE-2022-31474 | BackupBuddy - Local File Inclusion | backupbuddy | 7.5 (v3.1) | High |
| CVE-2022-33901 | WordPress MultiSafepay for WooCommerce <=4.13.1 - Arbitrary File Read | multisafepay plugin for woocommerce | 7.5 (v3.1) | High |
| CVE-2022-34121 | CuppaCMS v1.0 - Local File Inclusion | cuppacms | 7.5 (v3.1) | High |
| CVE-2022-37122 | Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Path Traversal | pcoweb hvac bacnet gateway | 7.5 (v3.1) | High |
| CVE-2022-4140 | WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Access | welcart e-commerce | 7.5 (v3.1) | High |
| CVE-2023-23063 | Cellinx NVT Web Server - Local File Disclosure | nvt web server | 7.5 (v3.1) | High |
| CVE-2023-26256 | STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion | stagil navigation | 7.5 (v3.1) | High |
| CVE-2023-29887 | Nuovo Spreadsheet Reader 0.5.11 - Local File Inclusion | spreadsheet-reader | 7.5 (v3.1) | High |
| CVE-2023-33510 | Jeecg P3 Biz Chat - Local File Inclusion | jeecg p3 biz chat | 7.5 (v3.1) | High |
| CVE-2023-34092 | Vite Dev Server - Information Exposure | vite | 7.5 (v3.1) | High |
| CVE-2023-38879 | openSIS v9.0 - Path Traversal | opensis | 7.5 (v3.1) | High |
| CVE-2023-40924 | SolarView Compact < 6.00 - Directory Traversal | solarview compact firmware | 7.5 (v3.1) | High |
| CVE-2023-6023 | VertaAI ModelDB - Path Traversal | modeldb | 7.5 (v3.1) | High |
| CVE-2023-6038 | H2O ImportFiles - Local File Inclusion | h2o | 7.5 (v3.1) | High |
| CVE-2024-12849 | Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Arbitrary File Read | error-log-viewer-wp | 7.5 (v3.1) | High |
| CVE-2024-1483 | Mlflow < 2.9.2 - Path Traversal | mlflow | 7.5 (v3.1) | High |
| CVE-2024-27292 | Docassemble - Local File Inclusion | docassemble | 7.5 (v3.1) | High |
| CVE-2024-2928 | MLflow < 2.11.3 - Path Traversal | mlflow | 7.5 (v3.1) | High |
| CVE-2024-36420 | Flowise 1.4.3 - Arbitrary File Read | flowise | 7.5 (v3.1) | High |
| CVE-2024-3848 | Mlflow < 2.11.0 - Path Traversal | mlflow | 7.5 (v3.1) | High |
| CVE-2024-38819 | Spring Framework Path Traversal in Functional Web Frameworks | spring framework | 7.5 (v3.1) | High |
| CVE-2024-45388 | Hoverfly < 1.10.3 - Arbitrary File Read | hoverfly | 7.5 (v3.1) | High |
| CVE-2024-46938 | Sitecore Experience Platform <= 10.4 - Arbitrary File Read | experience commerce | 7.5 (v3.1) | High |
| CVE-2024-5334 | Devika - Local File Inclusion | devika | 7.5 (v3.0) | High |
| CVE-2024-9362 | Polyaxon - Unauthenticated Directory Traversal | polyaxon/polyaxon | 7.5 (v3.0) | High |
| CVE-2024-9935 | PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Download | pdf-generator-addon-for-elementor-page-builder | 7.5 (v3.1) | High |
| CVE-2025-13339 | Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File Read | Hippoo Mobile App for WooCommerce | 7.5 (v3.1) | High |
| CVE-2025-13801 | Yoco Payments <= 3.8.8 - Path Traversal | Yoco Payments | 7.5 (v3.1) | High |
| CVE-2025-24963 | Vitest Browser Mode - Local File Read | vitest | 7.5 (v3.1) | High |
| CVE-2025-2539 | File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read | file away | 7.5 (v3.1) | High |
| CVE-2025-30208 | Vite - Arbitrary File Read | vite | 7.5 (v3.1) | High |
| CVE-2025-30567 | WordPress WP01 - Path Traversal | WP01 | 7.5 (v3.1) | High |
| CVE-2025-31125 | Vite Development Server - Path Traversal | vite | 7.5 (v3.1) | High |
| CVE-2025-31131 | Yeswiki < 4.5.2 - Unauthenticated Path Traversal | yeswiki | 7.5 (v3.1) | High |
| CVE-2025-45145 | Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 Path Traversal Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2025-69411 | ionCube Tester Plus <= 1.3 - Local File Inclusion | ionCube tester plus | 7.5 (v3.1) | High |
| CVE-2026-23536 | Feast Feature Server <=0.58.0 - Arbitrary File Read | feast | 7.5 (v3.1) | High |
| CVE-2026-32820 | dataCycle Public Markdown Path Traversal Via /docs/*path | dataCycle-CORE | 7.5 (v3.1) | High |
| CVE-2026-36851 | UnPoller 2.33.0 password field Path Traversal Vulnerability | UnPoller 2.33.0 password field | 7.5 (v3.1) | High |
| CVE-2026-39359 | Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name | wazuh | 7.5 (v3.1) | High |
| CVE-2026-39844 | NiceGUI has a Path Traversal in NiceGUI Upload Filename on Windows via Backslash Bypass of PurePosixPath Sanitization | nicegui | 7.5 (v3.1) | High |
| CVE-2026-39847 | Emmett has a path traversal in internal assets handler | emmett | 7.5 (v3.1) | High |
| CVE-2026-50776 | Pronis Loisirs Billetterie CSE - < 04/2026 Arbitrary Code Execution Vulnerability | Pronis Loisirs Billetterie CSE - < 04/2026 | 7.5 (v3.1) | High |
| CVE-2026-5487 | DriveLock Directory Traversal Information Disclosure Vulnerability | DriveLock | 7.5 (v3.0) | High |
| CVE-2026-5491 | DriveLock Directory Traversal Information Disclosure Vulnerability | DriveLock | 7.5 (v3.0) | High |
| CVE-2026-55552 | Yamcs: Unauthenticated Directory Traversal | yamcs | 7.5 (v3.1) | High |
| CVE-2026-56671 | ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read | ComfyUI | 7.5 (v3.1) | High |
| CVE-2026-61891 | theia Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | theia | 7.5 (v3.1) | High |
| CVE-2026-71209 | audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Trave | audiobookshelf | 7.5 (v3.1) | High |
| CVE-2026-75328 | In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java Path Traversal Vulnerability | In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java | 7.5 (v3.1) | High |
| CVE-2026-75333 | yx-image-recognition v1.0 Path Traversal Vulnerability | - | 7.5 (v3.1) | High |
| CVE-2026-15244 | HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search | HUSKY | 7.2 (v3.1) | High |
| CVE-2026-18274 | Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability | Database Proxy | 7.2 (v3.0) | High |
| CVE-2026-20297 | Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise | splunk | 7.2 (v3.1) | High |
| CVE-2026-34968 | Adminer before 5.4.3 Arbitrary File Deletion via SQLite Drop | adminer | 7.2 (v4.0) | High |
| CVE-2026-35174 | Chyrp Lite has a Path Traversal to Remote Code Execution | chyrp lite | 7.2 (v3.1) | High |
| CVE-2026-39387 | BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameter | boidcms | 7.2 (v3.1) | High |
| CVE-2026-85160 | AVideo through c91b5975d CSRF and Path Traversal via stopLive.php | AVideo | 7.2 (v4.0) | High |
| CVE-2018-25393 | Navigate CMS 2.8.5 Path Traversal via navigate_download.php | Navigate CMS | 7.1 (v4.0) | High |
| CVE-2018-25421 | Open STA Manager 2.3 Arbitrary File Download via Path Traversal | Open STA Manager | 7.1 (v4.0) | High |
| CVE-2019-25246 | BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File Disclosure | N100 H.264 VGA IP Camera | 7.1 (v4.0) | High |
| CVE-2026-40526 | Volmarg Personal Management System Path Traversal via get-file Endpoint | personal-management-system | 7.1 (v4.0) | High |
| CVE-2026-46555 | WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration | whatsapp mcp server | 7.1 (v3.1) | High |
| CVE-2026-47735 | Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks | arc | 7.1 (v4.0) | High |
| CVE-2026-64826 | rConfig < 8.2.13 Path Traversal File Read via FileDownloadController | rConfig | 7.1 (v4.0) | High |
| CVE-2026-76210 | phpMyFAQ before v4.1.6 Local File Disclosure via PDF Export | phpmyfaq | 7.1 (v4.0) | High |
| CVE-2026-81030 | Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items Endpoint | mage-ai | 7.1 (v4.0) | High |
| CVE-2026-82877 | ILIAS before 9.22 Arbitrary File Read via SOAP addFile | ILIAS | 7.1 (v4.0) | High |
| CVE-2026-40506 | OpenEMR Path Traversal Arbitrary Directory Deletion via standard_tables_manage.php | openemr | 7.0 (v4.0) | High |
| CVE-2026-54134 | OctoPrint: File exfiltration possible via query parameters on upload endpoints | OctoPrint | 7.0 (v4.0) | High |
| CVE-2026-73033 | Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php | sucuri-wordpress-plugin | 7.0 (v4.0) | High |
| CVE-2019-25760 | Joomla! Component Easy Shop 1.2.3 Local File Inclusion | easy shop | 6.9 (v4.0) | Medium |
| CVE-2022-50954 | WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusion | cab-fare-calculator | 6.9 (v4.0) | Medium |
| CVE-2022-50956 | WordPress Plugin amministrazione-aperta 3.7.3 Local File Read | amministrazione-aperta | 6.9 (v4.0) | Medium |
| CVE-2026-45731 | WWBN AVideo: Authenticated Arbitrary File Read in view/update.php | avideo | 6.9 (v4.0) | Medium |
| CVE-2026-45774 | compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal | compliance-trestle | 6.9 (v4.0) | Medium |
| CVE-2026-46337 | WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in view/img/image404Raw.php | avideo | 6.9 (v4.0) | Medium |
| CVE-2026-71932 | DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile | VigorSwitch G2540xs | 6.9 (v4.0) | Medium |
| CVE-2026-74235 | GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download Handler | GFI Exinda AI | 6.9 (v4.0) | Medium |
| CVE-2026-75592 | Kirby: Access to image files outside of the site root via path traversal in the media handling | kirby | 6.9 (v4.0) | Medium |
| CVE-2026-79743 | MCPHub: Path Traversal via Malicious MCPB Manifest Name | mcphub | 6.9 (v4.0) | Medium |
| CVE-2026-79773 | Winter CMS before 1.2.13 Local File Inclusion via JavaScript | winter | 6.9 (v4.0) | Medium |
| CVE-2026-79781 | rclone serve s3 Path Traversal via dot-dot object keys | rclone | 6.9 (v4.0) | Medium |
| CVE-2026-82233 | SiYuan before v3.8.1 Path Traversal via asset.upload | siyuan | 6.9 (v4.0) | Medium |
| CVE-2008-2650 | CMSimple 3.1 - Local File Inclusion | cmsimple | 6.8 (v2.0) | Medium |
| CVE-2008-6172 | Joomla! Component RWCards 3.0.11 - Local File Inclusion | rwcards | 6.8 (v2.0) | Medium |
| CVE-2009-3053 | Joomla! Agora 3.0.0b - Local File Inclusion | Joomla! | 6.8 (v2.0) | Medium |
| CVE-2010-1056 | Joomla! Component com_rokdownloads - Local File Inclusion | com rokdownloads | 6.8 (v2.0) | Medium |
| CVE-2010-1219 | Joomla! Component com_janews - Local File Inclusion | com janews | 6.8 (v2.0) | Medium |
| CVE-2010-1469 | Joomla! Component JProject Manager 1.0 - Local File Inclusion | com jprojectmanager | 6.8 (v2.0) | Medium |
| CVE-2010-1473 | Joomla! Component Advertising 0.25 - Local File Inclusion | com advertising | 6.8 (v2.0) | Medium |
| CVE-2010-1474 | Joomla! Component Sweetykeeper 1.5 - Local File Inclusion | com sweetykeeper | 6.8 (v2.0) | Medium |
| CVE-2010-1475 | Joomla! Component Preventive And Reservation 1.0.5 - Local File Inclusion | com preventive | 6.8 (v2.0) | Medium |
| CVE-2010-1476 | Joomla! Component AlphaUserPoints 1.5.5 - Local File Inclusion | com alphauserpoints | 6.8 (v2.0) | Medium |
| CVE-2010-1478 | Joomla! Component Jfeedback 1.2 - Local File Inclusion | com jfeedback | 6.8 (v2.0) | Medium |
| CVE-2010-1607 | Joomla! Component WMI 1.5.0 - Local File Inclusion | com wmi | 6.8 (v2.0) | Medium |
| CVE-2010-1715 | Joomla! Component Online Exam 1.5.0 - Local File Inclusion | com onlineexam | 6.8 (v2.0) | Medium |
| CVE-2010-1718 | Joomla! Component Archery Scores 1.0.6 - Local File Inclusion | com archeryscores | 6.8 (v2.0) | Medium |
| CVE-2010-1719 | Joomla! Component MT Fire Eagle 1.2 - Local File Inclusion | com mtfireeagle | 6.8 (v2.0) | Medium |
| CVE-2010-1722 | Joomla! Component Online Market 2.x - Local File Inclusion | com market | 6.8 (v2.0) | Medium |
| CVE-2010-1723 | Joomla! Component iNetLanka Contact Us Draw Root Map 1.1 - Local File Inclusion | com drawroot | 6.8 (v2.0) | Medium |
| CVE-2010-1979 | Joomla! Component Affiliate Datafeeds 880 - Local File Inclusion | com datafeeds | 6.8 (v2.0) | Medium |
| CVE-2010-1981 | Joomla! Component Fabrik 2.0 - Local File Inclusion | fabrik | 6.8 (v2.0) | Medium |
| CVE-2010-2122 | Joomla! Component simpledownload <=0.9.5 - Arbitrary File Retrieval | com simpledownload | 6.8 (v2.0) | Medium |
| CVE-2010-2507 | Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusion | com picasa2gallery | 6.8 (v2.0) | Medium |
| CVE-2010-2680 | Joomla! Component jesectionfinder - Local File Inclusion | com jesectionfinder | 6.8 (v2.0) | Medium |
| CVE-2010-2857 | Joomla! Component Music Manager - Local File Inclusion | com music | 6.8 (v2.0) | Medium |
| CVE-2010-2920 | Joomla! Component Foobla Suggestions 1.5.1.2 - Local File Inclusion | com foobla suggestions | 6.8 (v2.0) | Medium |
| CVE-2010-4617 | Joomla! Component JotLoader 2.2.1 - Local File Inclusion | com jotloader | 6.8 (v2.0) | Medium |
| CVE-2011-2744 | Chyrp 2.x - Local File Inclusion | chyrp | 6.8 (v2.0) | Medium |
| CVE-2026-35593 | Trilium Notes has Local File Inclusion via upload modified file API endpoint | Trilium | 6.8 (v3.1) | Medium |
| CVE-2026-71475 | Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path | advanced cluster management for kubernetes | 6.8 (v3.1) | Medium |
| CVE-2016-6435 | Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion | secure firewall management center | 6.5 (v3.0) | Medium |
| CVE-2017-14537 | Trixbox 2.8.0 - Path Traversal | trixbox | 6.5 (v3.1) | Medium |
| CVE-2018-15140 | OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions | openemr | 6.5 (v3.0) | Medium |
| CVE-2018-15141 | OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions | openemr | 6.5 (v3.0) | Medium |
| CVE-2019-14312 | Aptana Jaxer 1.0.3.4547 - Local File inclusion | jaxer | 6.5 (v3.0) | Medium |
| CVE-2019-3799 | Spring Cloud Config Server - Local File Inclusion | spring cloud config | 6.5 (v3.1) | Medium |
| CVE-2020-5405 | Spring Cloud Config - Local File Inclusion | spring cloud config | 6.5 (v3.1) | Medium |
| CVE-2021-24947 | WordPress Responsive Vector Maps < 6.4.2 - Arbitrary File Read | responsive vector maps | 6.5 (v3.1) | Medium |
| CVE-2021-28149 | Hongdian H8922 3.0.5 Devices - Local File Inclusion | h8922 firmware | 6.5 (v3.1) | Medium |
| CVE-2021-29006 | rConfig 3.9.6 - Local File Inclusion | rconfig | 6.5 (v3.1) | Medium |
| CVE-2021-40651 | OS4Ed OpenSIS Community 8.0 - Local File Inclusion | opensis | 6.5 (v3.1) | Medium |
| CVE-2024-55457 | MasterSAM Star Gate v11 - Local File Inclusion | - | 6.5 (v3.1) | Medium |
| CVE-2025-28367 | mojoPortal <=2.9.0.1 - Directory Traversal | mojoportal | 6.5 (v3.1) | Medium |
| CVE-2025-32815 | NetMRI < 7.6.1 - Authentication Bypass via Hardcoded Credentials | netmri | 6.5 (v3.1) | Medium |
| CVE-2025-45870 | LogicalDOC Enterprise up to and for v9.1.1 Path Traversal Vulnerability | - | 6.5 (v3.1) | Medium |
| CVE-2026-11442 | Allegra exportReport Directory Traversal Information Disclosure Vulnerability | Allegra | 6.5 (v3.0) | Medium |
| CVE-2026-12898 | All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Write | all-in-one-wp-migration | 6.5 (v3.1) | Medium |
| CVE-2026-14470 | Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base compone | langflow | 6.5 (v3.1) | Medium |
| CVE-2026-36227 | Easy Chat Server 3.1 Arbitrary Code Execution Vulnerability | Easy Chat Server 3.1 | 6.5 (v3.1) | Medium |
| CVE-2026-46397 | haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0 | haxcms-php | 6.5 (v3.1) | Medium |
| CVE-2026-52607 | reportico-web <= 8.1.0 Path Traversal Vulnerability | reportico-web <= 8.1.0 | 6.5 (v3.1) | Medium |
| CVE-2026-63667 | ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal | apostrophe | 6.5 (v3.1) | Medium |
| CVE-2026-73255 | Mongoose: Path traversal in SSI #include directives enables arbitrary file read | mongoose | 6.5 (v3.1) | Medium |
| CVE-2026-73573 | zimbra collaboration suite Path Traversal Vulnerability | zimbra collaboration suite | 6.5 (v3.1) | Medium |
| CVE-2026-73574 | zimbra collaboration suite Incorrect Resource Transfer Between Spheres Vulnerability | zimbra collaboration suite | 6.5 (v3.1) | Medium |
| CVE-2026-75602 | OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool | OpenList | 6.5 (v3.1) | Medium |
| CVE-2026-7646 | Langflow is affected by security vulnerabilities in Model Context Protocol features | langflow | 6.5 (v3.1) | Medium |
| CVE-2026-7658 | Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement | langflow | 6.5 (v3.1) | Medium |
| CVE-2026-9138 | Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing c | langflow | 6.5 (v3.1) | Medium |
| CVE-2009-0932 | Horde/Horde Groupware - Local File Inclusion | horde | 6.4 (v2.0) | Medium |
| CVE-2026-34371 | LibreChat Affected by Arbitrary File Write via execute_code Artifact Filename Traversal | librechat | 6.3 (v3.1) | Medium |
| CVE-2026-39365 | Vite has a Path Traversal in Optimized Deps .map Handling | vite | 6.3 (v4.0) | Medium |
| CVE-2026-56722 | Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI | dompdf | 6.3 (v4.0) | Medium |
| CVE-2026-65012 | InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder | InvokeAI | 6.3 (v4.0) | Medium |
| CVE-2026-72814 | actix-web before 0.6.10 Information Disclosure via Files | actix-web | 6.3 (v4.0) | Medium |
| CVE-2026-78886 | liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversal | TREK | 6.3 (v4.0) | Medium |
| CVE-2014-8727 | F5 BIG-IP 10.1.0 - Directory Traversal | big-ip local traffic manager | 6.2 (v2.0) | Medium |
| CVE-2026-29066 | TinaCMS - Path Traversal | tinacms | 6.2 (v3.1) | Medium |
| CVE-2025-46565 | Vite Dev Server - Information Exposure | vite | 6.0 (v4.0) | Medium |
| CVE-2026-41363 | OpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image Parameter | openclaw | 6.0 (v4.0) | Medium |
| CVE-2026-65698 | Void 1.3.4 Path Traversal via AI Agent File-Reading Tools | void | 6.0 (v4.0) | Medium |
| CVE-2026-66004 | BlenderMCP Path Traversal via download_polyhaven_asset API | blender-mcp | 6.0 (v4.0) | Medium |
| CVE-2026-79653 | Eclipse SW360 Path Traversal Vulnerability | Eclipse SW360 | 6.0 (v4.0) | Medium |
| CVE-2026-13693 | Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal | Bit Form | 5.9 (v3.1) | Medium |
| CVE-2026-49244 | SFTPGo: Path confinement bypass in public browsable share partial ZIP download | sftpgo | 5.9 (v3.1) | Medium |
| CVE-2026-82650 | SiYuan before v3.8.1 Path Traversal via /api/template/render | siyuan | 5.9 (v4.0) | Medium |
| CVE-2010-0467 | Joomla! Component CCNewsLetter - Local File Inclusion | com ccnewsletter | 5.8 (v3.1) | Medium |
| CVE-2025-1035 | KLog Server - Path Traversal | KLog Server | 5.7 (v3.1) | Medium |
| CVE-2026-40605 | Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API | Tautulli | 5.7 (v4.0) | Medium |
| CVE-2018-13980 | Zeta Producer Desktop CMS <14.2.1 - Local File Inclusion | zeta producer | 5.5 (v3.1) | Medium |
| CVE-2018-15536 | Responsive FileManager < 9.13.4 - Directory Traversal | responsive filemanager | 5.5 (v3.0) | Medium |
| CVE-2025-13810 | jsnjfz WebStack-Guns KaptchaController.java renderPicture path traversal | webstack-guns | 5.5 (v4.0) | Medium |
| CVE-2026-10694 | SourceCodester Online Food Ordering System index.php include file inclusion | Online Food Ordering System | 5.5 (v4.0) | Medium |
| CVE-2026-16252 | Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injection | Multimedia Integrated Business Display System | 5.5 (v4.0) | Medium |
| CVE-2026-19758 | dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal | lamp-cloud | 5.5 (v4.0) | Medium |
| CVE-2026-19762 | DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversal | Taier | 5.5 (v4.0) | Medium |
| CVE-2026-19827 | alldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversal | alldata | 5.5 (v4.0) | Medium |
| CVE-2026-68922 | MobSF: Arbitrary File Read via Path Traversal in ZIP Uploads | Mobile-Security-Framework-MobSF | 5.5 (v3.1) | Medium |
| CVE-2026-7205 | duartium papers-mcp-server main.py search_papers path traversal | papers-mcp-server | 5.5 (v4.0) | Medium |
| CVE-2026-7206 | dubydu sqlite-mcp entry.py extract_to_json sql injection | sqlite-mcp | 5.5 (v4.0) | Medium |
| CVE-2026-7212 | edvardlindelof notes-mcp notes_mcp.py path traversal | notes-mcp | 5.5 (v4.0) | Medium |
| CVE-2026-7214 | eghuzefa engineer-your-data server.py file_inf path traversal | engineer-your-data | 5.5 (v4.0) | Medium |
| CVE-2026-7216 | donchelo processing-claude-mcp-bridge create_sketch Tool processing_server.py path traversal | processing-claude-mcp-bridge | 5.5 (v4.0) | Medium |
| CVE-2026-7217 | Deepractice PromptX Document File index.ts read_pdf absolute path traversal | PromptX | 5.5 (v4.0) | Medium |
| CVE-2026-7314 | eiceblue spire-doc-mcp-server base.py get_doc_path path traversal | spire-doc-mcp-server | 5.5 (v4.0) | Medium |
| CVE-2026-7315 | eiceblue spire-pdf-mcp-server PDF File server.py get_pdf_path path traversal | spire-pdf-mcp-server | 5.5 (v4.0) | Medium |
| CVE-2026-81486 | bsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversal | mcp-file-context-server | 5.5 (v4.0) | Medium |
| CVE-2026-81491 | boxpositron with-context-mcp index.ts project_folder path traversal | with-context-mcp | 5.5 (v4.0) | Medium |
| CVE-2026-84441 | Piwigo Image Derivative i.php path traversal | Piwigo | 5.5 (v4.0) | Medium |
| CVE-2026-17621 | Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base compone | langflow | 5.4 (v3.1) | Medium |
| CVE-2026-7869 | Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement | langflow | 5.4 (v3.1) | Medium |
| CVE-2014-8676 | SO Planning 1.32 - Multiple Vulnerabilities | soplanning | 5.3 (v3.0) | Medium |
| CVE-2014-9609 | Netsweeper 4.0.8 - Directory Traversal | netsweeper | 5.3 (v3.1) | Medium |
| CVE-2015-5471 | Swim Team <= v1.44.10777 - Local File Inclusion | swim team | 5.3 (v3.0) | Medium |
| CVE-2020-13886 | Intelbras TIP 200/200 LITE/300 - Local File Inclusion | tip200 firmware | 5.3 (v3.1) | Medium |
| CVE-2021-28377 | Joomla! ChronoForums 2.0.11 - Local File Inclusion | chronoforums | 5.3 (v3.1) | Medium |
| CVE-2022-25497 | Cuppa CMS v1.0 - Local File Inclusion | cuppacms | 5.3 (v3.1) | Medium |
| CVE-2023-41599 | JFinalCMS v5.0.0 - Directory Traversal | jfinalcms | 5.3 (v3.1) | Medium |
| CVE-2024-51977 | Brother MFC-L9570CDW - Information Disclosure | HL-L8260CDN | 5.3 (v3.1) | Medium |
| CVE-2025-31486 | Vite server.fs.deny Bypass - Local File Inclusion | vite | 5.3 (v3.1) | Medium |
| CVE-2025-4078 | Wangshen SecGate 3600 Path Traversal Vulnerability | SecGate 3600 | 5.3 (v4.0) | Medium |
| CVE-2026-15932 | Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal | Support Genix | 5.3 (v3.1) | Medium |
| CVE-2026-16531 | Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet | Red Hat Enterprise Linux 10 | 5.3 (v3.1) | Medium |
| CVE-2026-34523 | SillyTavern: Path traversal allows file existence oracle | sillytavern | 5.3 (v3.1) | Medium |
| CVE-2026-34967 | Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Write | adminer | 5.3 (v4.0) | Medium |
| CVE-2026-36726 | the /api/delete-temp-license/{file} endpoint of bookcars v8.3 Path Traversal Vulnerability | the /api/delete-temp-license/{file} endpoint of bookcars v8.3 | 5.3 (v3.1) | Medium |
| CVE-2026-53452 | Ground Station: Unauthenticated out-of-containment file read via sigmfplayback recordingPath | ground-station | 5.3 (v3.1) | Medium |
| CVE-2026-73244 | kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listing | kkFileView | 5.3 (v3.1) | Medium |
| CVE-2026-76614 | OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore | openemr | 5.3 (v4.0) | Medium |
| CVE-2026-19761 | DTStack Taier Upload Controller UploadController.java MultipartFile.getOriginalFilename path traversal | Taier | 5.1 (v4.0) | Medium |
| CVE-2026-19763 | DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversal | Taier | 5.1 (v4.0) | Medium |
| CVE-2026-82112 | houtini-ai houtini-lm code_task_files index.ts path traversal | houtini-lm | 5.1 (v4.0) | Medium |
| CVE-2007-4504 | Joomla! RSfiles <=1.0.2 - Local File Inclusion | rsfiles | 5.0 (v2.0) | Medium |
| CVE-2008-4764 | Joomla! <=2.0.0 RC2 - Local File Inclusion | com extplorer | 5.0 (v2.0) | Medium |
| CVE-2008-6080 | Joomla! ionFiles 4.4.2 - Local File Inclusion | com ionfiles | 5.0 (v2.0) | Medium |
| CVE-2008-6222 | Joomla! ProDesk 1.0/1.2 - Local File Inclusion | pro desk support center | 5.0 (v2.0) | Medium |
| CVE-2008-6668 | nweb2fax <=0.2.7 - Local File Inclusion | nweb2fax | 5.0 (v2.0) | Medium |
| CVE-2009-1496 | Joomla! Cmimarketplace 0.1 - Local File Inclusion | Joomla! | 5.0 (v2.0) | Medium |
| CVE-2009-2100 | Joomla! JoomlaPraise Projectfork 2.0.10 - Local File Inclusion | Joomla! | 5.0 (v2.0) | Medium |
| CVE-2009-5114 | WebGlimpse 2.18.7 - Directory Traversal | webglimpse | 5.0 (v2.0) | Medium |
| CVE-2010-0696 | Joomla! Component Jw_allVideos - Arbitrary File Retrieval | jw allvideos | 5.0 (v2.0) | Medium |
| CVE-2010-0942 | Joomla! Component com_jvideodirect - Directory Traversal | com jvideodirect | 5.0 (v2.0) | Medium |
| CVE-2010-0943 | Joomla! Component com_jashowcase - Directory Traversal | com jashowcase | 5.0 (v2.0) | Medium |
| CVE-2010-0944 | Joomla! Component com_jcollection - Directory Traversal | com jcollection | 5.0 (v2.0) | Medium |
| CVE-2010-1081 | Joomla! Component com_communitypolls 1.5.2 - Local File Inclusion | com communitypolls | 5.0 (v2.0) | Medium |
| CVE-2010-1302 | Joomla! Component DW Graph - Local File Inclusion | com dwgraphs | 5.0 (v2.0) | Medium |
| CVE-2010-1304 | Joomla! Component User Status - Local File Inclusion | com userstatus | 5.0 (v2.0) | Medium |
| CVE-2010-1305 | Joomla! Component JInventory 1.23.02 - Local File Inclusion | com jinventory | 5.0 (v2.0) | Medium |
| CVE-2010-1307 | Joomla! Component Magic Updater - Local File Inclusion | com joomlaupdater | 5.0 (v2.0) | Medium |
| CVE-2010-1308 | Joomla! Component SVMap 1.1.1 - Local File Inclusion | com svmap | 5.0 (v2.0) | Medium |
| CVE-2010-1312 | Joomla! Component News Portal 1.5.x - Local File Inclusion | com news portal | 5.0 (v2.0) | Medium |
| CVE-2010-1314 | Joomla! Component Highslide 1.5 - Local File Inclusion | com hsconfig | 5.0 (v2.0) | Medium |
| CVE-2010-1315 | Joomla! Component webERPcustomer - Local File Inclusion | com weberpcustomer | 5.0 (v2.0) | Medium |
| CVE-2010-1340 | Joomla! Component com_jresearch - 'Controller' Local File Inclusion | com jresearch | 5.0 (v2.0) | Medium |
| CVE-2010-1345 | Joomla! Component Cookex Agency CKForms - Local File Inclusion | com ckforms | 5.0 (v2.0) | Medium |
| CVE-2010-1352 | Joomla! Component Juke Box 1.7 - Local File Inclusion | com jukebox | 5.0 (v2.0) | Medium |
| CVE-2010-1353 | Joomla! Component LoginBox - Local File Inclusion | com loginbox | 5.0 (v2.0) | Medium |
| CVE-2010-1354 | Joomla! Component VJDEO 1.0 - Local File Inclusion | com vjdeo | 5.0 (v2.0) | Medium |
| CVE-2010-1461 | Joomla! Component Photo Battle 1.0.1 - Local File Inclusion | com photobattle | 5.0 (v2.0) | Medium |
| CVE-2010-1491 | Joomla! Component MMS Blog 2.3.0 - Local File Inclusion | com mmsblog | 5.0 (v2.0) | Medium |
| CVE-2010-1494 | Joomla! Component AWDwall 1.5.4 - Local File Inclusion | com awdwall | 5.0 (v2.0) | Medium |
| CVE-2010-1532 | Joomla! Component PowerMail Pro 1.5.3 - Local File Inclusion | com powermail | 5.0 (v2.0) | Medium |
| CVE-2010-1534 | Joomla! Component Shoutbox Pro - Local File Inclusion | com shoutbox | 5.0 (v2.0) | Medium |
| CVE-2010-1540 | Joomla! Component com_blog - Directory Traversal | com myblog | 5.0 (v2.0) | Medium |
| CVE-2010-1601 | Joomla! Component JA Comment - Local File Inclusion | com jacomment | 5.0 (v2.0) | Medium |
| CVE-2010-1657 | Joomla! Component SmartSite 1.0.0 - Local File Inclusion | com smartsite | 5.0 (v2.0) | Medium |
| CVE-2010-1658 | Joomla! Component NoticeBoard 1.3 - Local File Inclusion | com noticeboard | 5.0 (v2.0) | Medium |
| CVE-2010-1659 | Joomla! Component Ultimate Portfolio 1.0 - Local File Inclusion | com ultimateportfolio | 5.0 (v2.0) | Medium |
| CVE-2010-1714 | Joomla! Component Arcade Games 1.0 - Local File Inclusion | com arcadegames | 5.0 (v2.0) | Medium |
| CVE-2010-1858 | Joomla! Component SMEStorage - Local File Inclusion | com smestorage | 5.0 (v2.0) | Medium |
| CVE-2010-1982 | Joomla! Component JA Voice 2.0 - Local File Inclusion | com javoice | 5.0 (v2.0) | Medium |
| CVE-2010-2018 | Lokomedia CMS - Local File Inclusion | lokomedia cms | 5.0 (v2.0) | Medium |
| CVE-2011-0049 | Majordomo2 - SMTP/HTTP Directory Traversal | majordomo 2 | 5.0 (v2.0) | Medium |
| CVE-2011-1669 | WP Custom Pages 0.5.0.1 - Local File Inclusion (LFI) | wp custom pages | 5.0 (v2.0) | Medium |
| CVE-2011-2780 | Chyrp 2.x - Local File Inclusion | chyrp | 5.0 (v2.0) | Medium |
| CVE-2011-4804 | Joomla! Component com_kp - 'Controller' Local File Inclusion | com obsuggest | 5.0 (v2.0) | Medium |
| CVE-2012-0896 | Count Per Day <= 3.1 - download.php f Parameter Traversal Arbitrary File Access | count per day | 5.0 (v2.0) | Medium |
| CVE-2012-0981 | phpShowtime 2.0 - Directory Traversal | phpshowtime | 5.0 (v2.0) | Medium |
| CVE-2012-0996 | 11in1 CMS 1.2.1 - Local File Inclusion (LFI) | 11in1 | 5.0 (v2.0) | Medium |
| CVE-2013-5979 | Xibo 1.2.2/1.4.1 - Directory Traversal | xibo | 5.0 (v2.0) | Medium |
| CVE-2013-7091 | Zimbra Collaboration Server 7.2.2/8.0.2 Local File Inclusion | zimbra collaboration suite | 5.0 (v2.0) | Medium |
| CVE-2014-4577 | WP AmASIN – The Amazon Affiliate Shop - Local File Inclusion | wp amasin - the amazon affiliate shop | 5.0 (v2.0) | Medium |
| CVE-2014-4940 | WordPress Plugin Tera Charts - Local File Inclusion | tera-charts | 5.0 (v2.0) | Medium |
| CVE-2014-4941 | Cross RSS 1.7 - Local File Inclusion | wp-cross-rss | 5.0 (v2.0) | Medium |
| CVE-2014-5111 | Fonality trixbox - Local File Inclusion | trixbox | 5.0 (v2.0) | Medium |
| CVE-2014-5181 | Last.fm Rotation 1.0 - Path Traversal | lastfm-rotation plugin | 5.0 (v2.0) | Medium |
| CVE-2014-5187 | Tom M8te (tom-m8te) Plugin 1.5.3 - Directory Traversal | tom-m8te plugin | 5.0 (v2.0) | Medium |
| CVE-2014-6308 | Osclass Security Advisory 3.4.1 - Local File Inclusion | osclass | 5.0 (v2.0) | Medium |
| CVE-2015-2067 | Magento Server MAGMI - Directory Traversal | magmi | 5.0 (v2.0) | Medium |
| CVE-2015-4414 | WordPress SE HTML5 Album Audio Player 1.1.0 - Directory Traversal | se html5 album audio player | 5.0 (v2.0) | Medium |
| CVE-2026-16955 | AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription | AI Engine | 5.0 (v3.1) | Medium |
| CVE-2025-15673 | Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read | Import and export users and customers | 4.9 (v3.1) | Medium |
| CVE-2026-52832 | Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container | nuclio | 4.9 (v3.1) | Medium |
| CVE-2026-53594 | FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path | freescout | 4.9 (v3.1) | Medium |
| CVE-2026-71283 | Fledge IoT Gateway Backup Restore Tar Path Traversal | fledge | 4.9 (v3.1) | Medium |
| CVE-2008-5587 | phpPgAdmin <=4.2.1 - Local File Inclusion | phppgadmin | 4.3 (v2.0) | Medium |
| CVE-2010-0982 | Joomla! Component com_cartweberp - Local File Inclusion | com cartweberp | 4.3 (v2.0) | Medium |
| CVE-2010-1217 | Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusion | je form creator | 4.3 (v2.0) | Medium |
| CVE-2010-1313 | Joomla! Component Saber Cart 1.0.0.12 - Local File Inclusion | com sebercart | 4.3 (v2.0) | Medium |
| CVE-2012-4253 | MySQLDumper 1.24.4 - Directory Traversal | mysqldumper | 4.3 (v2.0) | Medium |
| CVE-2014-9146 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | fiyo cms | 4.3 (v2.0) | Medium |
| CVE-2018-18777 | Microstrategy Web 7 - Local File Inclusion | microstrategy web | 4.3 (v3.0) | Medium |
| CVE-2024-7631 | Openshift-console: openshift console: path traversal | Red Hat OpenShift Container Platform 3.11 | 4.3 (v3.1) | Medium |
| CVE-2026-26477 | dokuwiki Denial of Service Vulnerability | dokuwiki | 4.3 (v3.1) | Medium |
| CVE-2026-55495 | Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account | cloudreve | 4.3 (v3.1) | Medium |
| CVE-2011-4640 | WebTitan < 3.60 - Local File Inclusion | webtitan | 4.0 (v2.0) | Medium |
| CVE-2013-5528 | Cisco Unified Communications Manager 7/8/9 - Directory Traversal | unified communications manager | 4.0 (v2.0) | Medium |
| CVE-2014-1222 | Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities | vtiger crm | 4.0 (v2.0) | Medium |
| CVE-2014-5258 | webEdition 6.3.8.0 - Directory Traversal | webedition cms | 4.0 (v2.0) | Medium |
| CVE-2019-19411 | Huawei Firewall - Local File Inclusion | usg9500 | 3.7 (v3.1) | Low |
| CVE-2012-0991 | OpenEMR 4.1 - Local File Inclusion | openemr | 3.5 (v2.0) | Low |
| CVE-2025-55523 | Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download | agent-zero | 3.5 (v3.1) | Low |
| CVE-2026-9062 | Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal | Store Locator WordPress | 3.4 (v3.1) | Low |
| CVE-2026-55825 | Contao: Possible path traversal in job download URIs | contao | 3.1 (v3.1) | Low |
| CVE-2023-2252 | Directorist < 7.5.4 - Local File Inclusion | directorist | 2.7 (v3.1) | Low |
| CVE-2024-55550 | Mitel MiCollab - Arbitary File Read | cmg suite | 2.7 (v3.1) | Low |
| CVE-2026-16434 | Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypass | adminer | 2.3 (v4.0) | Low |
| CVE-2026-55554 | Dompdf: Chroot Validation Bypass | dompdf | 2.3 (v4.0) | Low |
| CVE-2025-13816 | moxi159753 Mogu Blog v2 ZIP File unzipFile FileOperation.unzip path traversal | mogublog | 2.1 (v4.0) | Low |
| CVE-2025-13875 | Yohann0617 oci-helper OCI Configuration Upload OciServiceImpl.java addCfg path traversal | oci-helper | 2.1 (v4.0) | Low |
| CVE-2026-10278 | ishayoyo excel-mcp read_file/write_file index.ts path traversal | excel-mcp | 2.1 (v4.0) | Low |
| CVE-2026-10559 | SourceCodester Pizzafy Ecommerce System index.php file inclusion | Pizzafy Ecommerce System | 2.1 (v4.0) | Low |
| CVE-2026-11467 | jishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadService.java path traversal | jshERP | 2.1 (v4.0) | Low |
| CVE-2026-18959 | yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal | InnoShop | 2.1 (v4.0) | Low |
| CVE-2026-19756 | Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal | lamp-cloud | 2.1 (v4.0) | Low |
| CVE-2026-19828 | 648540858 wvp-GB28181-pro Snapshot Endpoint PlayController.java path traversal | wvp-GB28181-pro | 2.1 (v4.0) | Low |
| CVE-2026-19829 | 648540858 wvp-GB28181-pro Log File Download Endpoint LogController.java path traversal | wvp-GB28181-pro | 2.1 (v4.0) | Low |
| CVE-2026-76576 | yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversal | RuoYi-Vue | 2.1 (v4.0) | Low |
| CVE-2026-81845 | arben-adm mcp-sequential-thinking Import Session/Export Session server.py export_session path traversal | mcp-sequential-thinking | 2.1 (v4.0) | Low |
| CVE-2026-82599 | SeaCMS Avatar Upload member.php unlink path traversal | SeaCMS | 2.1 (v4.0) | Low |
| CVE-2026-82603 | SeaCMS Comment Cache member.php del_pl path traversal | SeaCMS | 2.1 (v4.0) | Low |
| CVE-2026-82656 | Admidio before 5.0.12 Path Traversal via Photo ZIP Download | admidio | 2.1 (v4.0) | Low |
| CVE-2026-9473 | c-rick jimeng-mcp api.ts generateVideo path traversal | jimeng-mcp | 2.1 (v4.0) | Low |
| CVE-2026-12211 | Intelbras iNVU 7016 FT Web syslog path traversal | iNVU 7016 FT | 2.0 (v4.0) | Low |
| CVE-2026-16088 | halo-dev halo Files Backup Endpoint MigrationEndpoint.java download path traversal | halo | 2.0 (v4.0) | Low |
| CVE-2026-81847 | MAA-AI MaaMCP pipeline_tools.py load_pipeline path traversal | MaaMCP | 2.0 (v4.0) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.
Documentation Source
- Original wiki page: WAF 390709
- Source revision: 2734
- Source revision date: 2012-09-20