The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize multiple internal "../" sequences that can resolve to a location that is outside of that directory.
Volume of CVEs assigned to CWE-27 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23897CRITICAL Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with t | Jan 24, 2024 | 9.8 | 99 | YES | YES |
CVE-2024-24809HIGH Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type. Since the system allows r | Apr 10, 2024 | 8.5 | 75 | NO | YES |
CVE-2023-34125MEDIUM Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem with root privileges. This issue affects G | Jul 13, 2023 | 6.5 | 34 | NO | NO |
CVE-2026-24457CRITICAL An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the Op | Mar 5, 2026 | 9.8 | 30 | NO | NO |
CVE-2025-10438HIGH Path Traversal: 'dir/../../filename' vulnerability in Yordam Information Technology Consulting Education and Electrical Systems Industry Trade Inc. Yordam Katalog allows Path Trave | Sep 25, 2025 | 8.6 | 28 | NO | NO |
CVE-2024-21896CRITICAL The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be treated as a Buffer, the implemen | Feb 20, 2024 | 9.8 | 28 | NO | NO |
CVE-2025-66518HIGH Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not | Jan 5, 2026 | 8.8 | 27 | NO | NO |
CVE-2024-7458CRITICAL A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload of | Aug 4, 2024 | 9.8 | 27 | NO | NO |
CVE-2022-24785HIGH Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between v | Apr 4, 2022 | 7.5 | 27 | NO | NO |
CVE-2025-52237MEDIUM An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal. | Aug 5, 2025 | 6.5 | 25 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.