The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
Volume of CVEs assigned to CWE-23 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
457 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64446CRITICAL A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWe | Nov 14, 2025 | 9.8 | 99 | YES | YES |
CVE-2024-27199HIGH In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible | Mar 4, 2024 | 7.3 | 97 | YES | YES |
CVE-2021-40870CRITICAL An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to ex | Sep 13, 2021 | 9.8 | 97 | YES | YES |
CVE-2020-5410HIGH Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through | Jun 2, 2020 | 7.5 | 97 | YES | YES |
CVE-2026-34926MEDIUM A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code | May 21, 2026 | 6.7 | 80 | YES | NO |
CVE-2020-5405MEDIUM Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through | Mar 5, 2020 | 6.5 | 71 | NO | YES |
CVE-2022-23854HIGH AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on th | Dec 23, 2022 | 7.5 | 69 | NO | YES |
CVE-2025-55752HIGH Relative Path Traversal vulnerability in Apache Tomcat.
The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This intr | Oct 27, 2025 | 7.5 | 67 | NO | NO |
CVE-2020-17518HIGH Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER | Jan 5, 2021 | 7.5 | 62 | NO | YES |
CVE-2023-34990CRITICAL A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted we | Dec 18, 2024 | 9.8 | 60 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.