Skip to content
Threat Feed

Tag

Directory-Traversal

21 briefs RSS
high advisory

Path Traversal Vulnerability in AcyMailing WordPress Plugin

The AcyMailing WordPress plugin is vulnerable to unauthenticated directory traversal, allowing attackers to read arbitrary files on the server when the Embed images feature is enabled.

AcyMailing web-application vulnerability directory-traversal
1r 1t 1c
high advisory

Directory Traversal in Direct Download for WooCommerce Plugin

An unauthenticated directory traversal vulnerability in the Direct Download for WooCommerce plugin (v1.19 and below) allows attackers to read arbitrary files from the underlying server.

Direct Download for WooCommerce wordpress web-application cve directory-traversal
1t 1c
high threat

C-MOR Video Surveillance Directory Traversal Vulnerability

C-MOR Video Surveillance versions up to 6.0104 are vulnerable to an unauthenticated directory traversal attack in the show-movies.pml component, allowing remote attackers to read arbitrary files.

exploited C-MOR Video Surveillance webapps directory-traversal cve-2026-51134 surveillance web-application-vulnerability xss
2r 2t
critical advisory

Directory Traversal Vulnerability in Cloud Commander

Cloud Commander versions prior to 19.20.2 are vulnerable to a directory traversal flaw in REST file-operation and markdown endpoints, allowing unauthenticated attackers to read or write arbitrary files.

Cloud Commander directory-traversal web-vulnerability
1c
high advisory

Unauthenticated Directory Traversal in Yamcs

Yamcs versions prior to 5.11.13 contain an unauthenticated directory traversal vulnerability in the HTTP request handling components that allows remote attackers to read arbitrary files from the underlying host.

yamcs-core +2 web-vulnerability directory-traversal cve-2026-55552 privilege-escalation web-application-vulnerability
2r 3t 1c
high advisory

Arbitrary File Deletion in Atarim AI Agency for WordPress Plugin

The Atarim - AI Agency for WordPress plugin is vulnerable to arbitrary file deletion via directory traversal, enabling attackers with author-level access to delete sensitive files and potentially achieve remote code execution.

Atarim – AI Agency for WordPress wordpress plugin directory-traversal cve-2026-19942
1r 1t 1c
high advisory

Path Traversal in @rhinostone/swig Template Engine

The @rhinostone/swig template engine (CVE-2023-25345) contains a path traversal vulnerability in its filesystem loader, allowing unauthenticated attackers to read arbitrary local files via include or extends tags.

@rhinostone/swig +4 directory-traversal arbitrary-file-read template-injection cve-2023-25345
1t 1c
medium advisory

Grafana Improper Access Control Information Disclosure Vulnerability

An authenticated, remote attacker can exploit a flaw in Grafana to perform unauthorized information disclosure due to improper access control.

Grafana informational product-news directory-traversal vulnerability web-application xss security-advisory denial-of-service
3t 1c updated
high advisory

Directory Traversal and LFI in Ray 2.56.0

Ray 2.56.0 contains a directory traversal and local file inclusion vulnerability in the /api/v0/logs endpoint allowing unauthenticated attackers to read arbitrary files.

Ray webapps directory-traversal lfi
1r 2t
high advisory

Directory Traversal in W3 Total Cache WordPress Plugin (CVE-2026-9282)

An unauthenticated directory traversal vulnerability (CVE-2026-9282) in all versions up to 2.9.4 of the W3 Total Cache plugin for WordPress allows attackers to read arbitrary files by manipulating the minify filename when manual minify mode is enabled.

WordPress +1 plugin directory-traversal cve web-exploit
1r 3t 1c
critical advisory

CVE-2026-9181: Unauthenticated Directory Traversal in ArcGIS Server

An unauthenticated attacker can exploit CVE-2026-9181, a critical directory traversal vulnerability in ArcGIS Server versions 12.0 and prior, by sending crafted path parameters to access sensitive files, leading to unauthorized information disclosure.

ArcGIS Server +17 directory-traversal web-vulnerability esri cve
2t 1i updated
high threat

Softneta MedDream PACS Server Premium Directory Traversal Vulnerability (CVE-2018-25374)

Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability, tracked as CVE-2018-25374, allowing unauthenticated attackers to read arbitrary files by manipulating the path parameter in requests to nocache.php.

MedDream PACS Server Premium 6.7.1.1 directory-traversal web-application CVE-2018-25374
1r 1t 1c
critical advisory

Algernon handler.lua Discovery Leads to Remote Code Execution

Algernon is vulnerable to remote code execution due to unbounded upward directory traversal when searching for `handler.lua`, allowing attackers with write access to parent directories to execute arbitrary code.

Algernon rce directory-traversal
2r 1t
high advisory

WordPress Anti-Malware Security and Bruteforce Firewall Directory Traversal Vulnerability

WordPress Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability (CVE-2021-47977) that allows unauthenticated attackers to read arbitrary files by manipulating the file parameter in requests to admin-ajax.php.

Anti-Malware Security and Bruteforce Firewall 4.20.59 directory-traversal wordpress plugin cve-2021-47977
2r 1t 1c
medium advisory

Joomla com_fabrik Directory Traversal Vulnerability (CVE-2020-37219)

Joomla com_fabrik 3.9.11 is vulnerable to a directory traversal attack (CVE-2020-37219) where an unauthenticated attacker can list arbitrary files by manipulating the folder parameter in a GET request to the onAjax_files method, using path traversal sequences to access system directories outside the web root.

com_fabrik 3.9.11 directory-traversal web-application joomla
2r 1t 1c
high advisory

OpenClaw Arbitrary Directory Deletion Vulnerability

OpenClaw before 2026.4.2 is vulnerable to arbitrary directory deletion in mirror mode, enabling attackers to delete remote directories by manipulating remoteWorkspaceDir and remoteAgentWorkspaceDir configuration values.

OpenClaw cve-2026-41383 directory-traversal file-deletion
2r 1t 1c
critical advisory

compressing npm Package Symlink Bypass Vulnerability

A vulnerability in the `compressing` npm package (<=v2.1.0) allows for arbitrary file overwrite via symlink path traversal, bypassing a previous patch for CVE-2026-24884.

npm supply-chain symlink directory-traversal privilege-escalation arbitrary-file-overwrite
3r 5t 1c 1i
medium advisory

LORIS Directory Traversal Vulnerability

LORIS, a neuroimaging research data management web application, is vulnerable to directory traversal (CVE-2026-35446) due to an incorrect order of operations in the FilesDownloadHandler, allowing authenticated attackers to access unauthorized files.

directory-traversal web-application neuroimaging
2r 2t 1c
critical advisory

SiYuan Note Taking Application Directory Traversal Vulnerability

SiYuan note taking application is vulnerable to a directory traversal via the /api/file/readDir endpoint, which does not require authentication, allowing an attacker to enumerate the directory structure and retrieve file names, potentially leading to arbitrary document reading.

directory-traversal siyuan cve-2026-33670
2r 1t
high advisory

BuildKit Git URL Subdir Traversal Vulnerability

A vulnerability in BuildKit (fixed in v0.28.1) allows for potential file access outside the Git repository root due to insufficient validation of Git URL fragment subdirectories, potentially leading to privilege escalation.

BuildKit git directory-traversal privilege-escalation
2r 1t
medium advisory

Web Server Local File Inclusion Activity

This rule detects potential Local File Inclusion (LFI) exploitation on web servers by identifying HTTP GET requests attempting to access sensitive local files through directory traversal or known file paths, potentially leading to sensitive information disclosure.

Nginx +4 lfi web-server directory-traversal information-disclosure
2r 1t