CWE-25: Path Traversal: '/../filedir'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "/../" sequences that can resolve to a location that is outside of that directory.
13 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-68916 — Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload wi
- CVE-2026-23877 — Directory Traversal & Filesystem can be accessed by a non-admin user
- CVE-2025-0225 — Tsinghua Unigroup Electronic Archives System exampleDownload.html path traversal
- CVE-2026-68959 — SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an
- CVE-2025-58286 — Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av
Recently published
- CVE-2026-68959 — SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an
- CVE-2026-23877 — Directory Traversal & Filesystem can be accessed by a non-admin user
- CVE-2025-68916 — Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload wi
- CVE-2025-58286 — Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect av
- CVE-2025-0225 — Tsinghua Unigroup Electronic Archives System exampleDownload.html path traversal