CWE-35: Path Traversal: '.../...//'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
171 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-8088 — Path traversal vulnerability in WinRAR
- CVE-2025-24786 — Path traversal opening Sqlite3 database in WhoDB
- CVE-2025-42937 — Directory Traversal vulnerability in SAP Print Service
- CVE-2025-41723 — Sauter: Directory Traversal in importFile SOAP Method
- CVE-2025-30515 — CyberData 011209 SIP Emergency Intercom Path Traversal
- CVE-2025-53417 — File Parsing Deserialization of Untrusted Data in DTM Soft
- CVE-2025-5598 — WF Steuerungstechnik GmbH - airleader MASTER - Path Traversal
- CVE-2025-59099 — Unauthenticated Path Traversal in dormakaba access manager
- CVE-2025-47649 — WordPress Open Close WooCommerce Store <= 4.9.5 - Local File Inclusion Vulnerability
- CVE-2025-41736 — Possible arbitrary code execution
- CVE-2024-47169 — Agnai vulnerable to Remote Code Execution via JS Upload using Directory Traversal
- CVE-2025-53880 — susemanager-tftpsync-recv allows arbitrary file creation and deletion due to path traversal
- CVE-2026-45661 — Dokploy: Remote Code Execution through Path Traversal
- CVE-2025-52811 — WordPress Davenport - Versatile Blog and Magazine WordPress Theme <= 1.3 - Local File Inclusion Vulnerability
- CVE-2025-52810 — WordPress Katerio - Magazine theme <= 1.5.1 - Local File Inclusion Vulnerability
- CVE-2025-49296 — WordPress GrandPrix <= 1.6 - Local File Inclusion Vulnerability
- CVE-2025-39491 — WordPress WHMpress plugin <= 6.2-revision-9 - Local File Inclusion vulnerability
- CVE-2025-39475 — WordPress Arlo <= 6.0.3 - Local File Inclusion Vulnerability
- CVE-2025-39470 — WordPress Ivy School <= 1.6.0 - Local File Inclusion Vulnerability
- CVE-2024-41973 — WAGO: Remote Arbitrary File Write with Root Privileges in multiple Devices
Recently published
- CVE-2026-20513 — In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local info
- CVE-2026-56089 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with l
- CVE-2026-59909 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with l
- CVE-2026-28157 — WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability
- CVE-2026-69109 — A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is v
- CVE-2026-13716 — Path Traversal: '.../...//' in Crafty Controller
- CVE-2026-66695 — WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability
- CVE-2025-59181 — Path traversal Vulnerability
- CVE-2026-49779 — WordPress Tax Exempt for WooCommerce plugin < 1.9.5 - Path Traversal vulnerability
- CVE-2026-52707 — WordPress Kastell theme <= 2.0 - Local File Inclusion vulnerability
- CVE-2026-52703 — WordPress FastDup plugin <= 2.7.2 - Path Traversal vulnerability
- CVE-2026-49112 — WordPress Shared Files plugin <= 1.7.64 - Path Traversal vulnerability
- CVE-2026-42661 — WordPress WP Customer Area plugin <= 8.3.4 - Path Traversal vulnerability
- CVE-2026-40128 — Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)
- CVE-2026-24315 — Path Traversal Vulnerability in SAP Fiori (launchpad)
- CVE-2026-45661 — Dokploy: Remote Code Execution through Path Traversal
- CVE-2026-44933 — Path Traversal in Plugin Loading in libzypp
- CVE-2026-42930 — Appliance mode iControl REST vulnerability
- CVE-2026-24464 — Appliance mode iControl REST vulnerability
- CVE-2026-25705 — Rancher Extensions have arbitrary file access via path traversal