Security Risk Category

Path Traversal Security Risks — Page 5

Published vulnerability pages connected to Path Traversal. Each page keeps one canonical URL and focused remediation guidance.

167 published Path Traversal risks

Path Traversal risks

Showing 145–167 of 167 published risks.

highEPSS 0.004

CVE-2026-59221 Open WebUI vulnerability

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitize_proxy_path in backend/open_webui/routers/terminals.py decoded proxy paths only eight times, allowing a nine-times percent-encoded ../ traversal value to pass normalization checks and be decoded by the upstream terminal server. This issue is fixed in version 0.10.0.

CVE-2026-59221network-securityapi-securityweb-applicationpath-traversal

Updated Jul 12, 2026

criticalEPSS 0.004

CVE-2026-59792 JetBrains IntelliJ IDEA vulnerability

In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible

CVE-2026-59792devopsremote-code-executionpath-traversal

Updated Jul 12, 2026

highEPSS 0.003

CVE-2026-59793 JetBrains TeamCity vulnerability

In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration

CVE-2026-59793devopsinformation-disclosurepath-traversalfile-write

Updated Jul 12, 2026

highEPSS 0.003

CVE-2026-55474 Snipe-IT vulnerability

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to traverse outside the intended directory and read arbitrary files accessible to the web server process. This issue is fixed in version 8.5.0.

CVE-2026-55474phpweb-applicationinformation-disclosurepath-traversal

Updated Jul 12, 2026

criticalEPSS 0.006

CVE-2026-53481 Dell PowerProtect Data Domain vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to the system. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.

CVE-2026-53481network-securityauthentication-bypasspath-traversal

Updated Jul 12, 2026

mediumEPSS 0.002

CVE-2026-59996 openssh vulnerability

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

CVE-2026-59996network-securitypath-traversal

Updated Jul 12, 2026

lowEPSS 0.003

CVE-2026-53480 data domain operating system vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized file modification.

CVE-2026-53480network-securitypath-traversal

Updated Jul 11, 2026

lowEPSS 0.003

mcp-text-editor Path Traversal Vulnerability

A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2. This issue affects the function _validate_file_path of the file mcp_text_editor/text_editor.py. Such manipulation of the argument file_path leads to path traversal. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor closed the GitHub issue for this vulnerability without any explanation.

CVE-2026-15138pythonpath-traversal

Updated Jul 10, 2026

highEPSS 0.003

BOSH CLI blobs.yml Path Traversal Vulnerability

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

CVE-2026-47826cloud-securityinformation-disclosurepath-traversalfile-write

Updated Jul 10, 2026

mediumEPSS 0.007

WPFunnels WordPress Plugin Local File Inclusion Vulnerability

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.12.7 via the 'logKey' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

CVE-2026-13080wordpresswoocommercephpauthorization-bypass

Updated Jul 10, 2026

high

Bit Form WordPress Plugin Arbitrary File Deletion Vulnerability

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteFiles function in all versions up to, and including, 3.1.1 This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config).

CVE-2026-14372wordpressremote-code-executionpath-traversalfile-write

Updated Jul 10, 2026

criticalCISA KEVEPSS 0.032

Adobe ColdFusion Path Traversal Vulnerability

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

CVE-2026-48282remote-code-executionpath-traversal

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.023

Ubiquiti UniFi OS Path Traversal Vulnerability

Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.

CVE-2026-34909network-securitypath-traversal

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.013

LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS.

CVE-2026-54420path-traversal

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.077

Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.

CVE-2026-20262network-securitypath-traversal

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.127

Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

CVE-2026-34926supply-chainpath-traversal

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.046

Microsoft Windows Link Following Vulnerability

Microsoft Windows contains a link following vulnerability that allows for privilege escalation

CVE-2025-60710windowsmicrosoftpath-traversalprivilege-escalation

Updated Jul 9, 2026

criticalCISA KEVEPSS 1.000

JetBrains TeamCity Relative Path Traversal Vulnerability

JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.

CVE-2024-27199devopspath-traversal

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.075

SimpleHelp Path Traversal Vulnerability

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

CVE-2024-57728remote-code-executionpath-traversalfile-write

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.876

ConnectWise ScreenConnect Path Traversal Vulnerability

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

CVE-2024-1708path-traversal

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.919

Samsung MagicINFO 9 Server Path Traversal Vulnerability

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.

CVE-2024-7399path-traversalfile-uploadfile-write

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.039

Kentico Xperience Path Traversal Vulnerability

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

CVE-2025-2749path-traversalfile-upload

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.084

Microsoft Defender Link Following Vulnerability

Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.

CVE-2026-41091microsoftpath-traversal

Updated Jul 9, 2026