The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "/../" sequences that can resolve to a location that is outside of that directory.
Volume of CVEs assigned to CWE-25 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-20775HIGH A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges.
This vulnerability is due to improper access contro | Sep 30, 2022 | 7.8 | 73 | YES | NO |
CVE-2025-68916HIGH Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution. | Dec 24, 2025 | 7.2 | 27 | NO | NO |
CVE-2023-52138CRITICAL Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged to achieve full Remote Command E | Feb 5, 2024 | 9.6 | 26 | NO | NO |
CVE-2022-20818HIGH Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper acc | Sep 30, 2022 | 7.8 | 26 | NO | NO |
CVE-2023-6118HIGH Path Traversal: '/../filedir' vulnerability in Neutron IP Camera allows Absolute Path Traversal.
This issue affects IP Camera: before b1130.1.0.1. | Nov 23, 2023 | 7.5 | 25 | NO | NO |
CVE-2023-52076HIGH Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril | Jan 25, 2024 | 7.8 | 24 | NO | NO |
CVE-2023-6947HIGH The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for au | Dec 10, 2024 | 7.7 | 22 | NO | NO |
CVE-2024-2442HIGH
Franklin Fueling System EVO 550 and EVO 5000 are vulnerable to a Path Traversal vulnerability that could allow an attacker to access sensitive files on the system.
| Mar 19, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-58286MEDIUM Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | Oct 11, 2025 | 5.5 | 20 | NO | NO |
CVE-2023-6919HIGH Path Traversal: '/../filedir' vulnerability in Biges Safe Life Technologies Electronics Inc. VGuard allows Absolute Path Traversal.
This issue affects VGuard: before V500.0003.R00 | Jan 26, 2024 | 7.5 | 20 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.