Vulnerabilities (CVE)

Filtered by CWE-35
Total 137 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-52712 2026-04-23 N/A 4.2 MEDIUM
Path Traversal: '.../...//' vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Path Traversal.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.8.
CVE-2025-49297 1 Qodeinteractive 1 Grill And Chow 2026-04-23 N/A 8.1 HIGH
Path Traversal: '.../...//' vulnerability in Mikado-Themes Grill and Chow grillandchow allows PHP Local File Inclusion.This issue affects Grill and Chow: from n/a through <= 1.6.
CVE-2025-49296 1 Qodeinteractive 1 Grandprix 2026-04-23 N/A 8.1 HIGH
Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issue affects GrandPrix: from n/a through <= 1.6.
CVE-2025-49295 1 Qodeinteractive 1 Mediclinic 2026-04-23 N/A 8.1 HIGH
Path Traversal: '.../...//' vulnerability in Mikado-Themes MediClinic mediclinic allows PHP Local File Inclusion.This issue affects MediClinic: from n/a through <= 2.1.
CVE-2025-48317 2026-04-23 N/A 7.5 HIGH
Path Traversal: '.../...//' vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay woocommerce-payment-gateway-for-saferpay allows Path Traversal.This issue affects WooCommerce Payment Gateway for Saferpay: from n/a through <= 0.4.9.
CVE-2025-47636 2026-04-23 N/A 7.5 HIGH
Path Traversal: '.../...//' vulnerability in Fernando Briano List category posts list-category-posts allows PHP Local File Inclusion.This issue affects List category posts: from n/a through <= 0.91.0.
CVE-2025-46441 2026-04-23 N/A 5.3 MEDIUM
Path Traversal: '.../...//' vulnerability in ctltwp Section Widget section-widget allows Path Traversal.This issue affects Section Widget: from n/a through <= 3.3.1.
CVE-2025-39598 2026-04-23 N/A 4.9 MEDIUM
Path Traversal: '.../...//' vulnerability in Quý Lê 91 Administrator Z administrator-z allows Path Traversal.This issue affects Administrator Z: from n/a through <= 2025.03.28.
CVE-2025-39475 2026-04-23 N/A 8.1 HIGH
Path Traversal: '.../...//' vulnerability in Frenify Arlo arlo allows PHP Local File Inclusion.This issue affects Arlo: from n/a through <= 6.0.3.
CVE-2025-39470 2026-04-23 N/A 8.1 HIGH
Path Traversal: '.../...//' vulnerability in ThimPress Ivy School ivy-school allows PHP Local File Inclusion.This issue affects Ivy School: from n/a through <= 1.6.0.
CVE-2025-32585 2026-04-23 N/A 7.5 HIGH
Path Traversal: '.../...//' vulnerability in Trusty Plugins Shop Products Filter trusty-woo-products-filter allows PHP Local File Inclusion.This issue affects Shop Products Filter: from n/a through <= 1.2.
CVE-2025-30834 2026-04-23 N/A 7.5 HIGH
Path Traversal: '.../...//' vulnerability in Bit Apps Bit Assist bit-assist allows Path Traversal.This issue affects Bit Assist: from n/a through <= 1.5.4.
CVE-2025-27274 1 Axelkeller 1 Gpx Viewer 2026-04-23 N/A 4.9 MEDIUM
Path Traversal: '.../...//' vulnerability in axelkeller GPX Viewer gpx-viewer allows Path Traversal.This issue affects GPX Viewer: from n/a through <= 2.2.11.
CVE-2025-27010 2026-04-23 N/A 8.1 HIGH
Path Traversal: '.../...//' vulnerability in bslthemes Tastyc tastyc allows PHP Local File Inclusion.This issue affects Tastyc: from n/a through < 2.5.2.
CVE-2025-26935 1 Wpjobportal 1 Wp Job Portal 2026-04-23 N/A 7.5 HIGH
Path Traversal: '.../...//' vulnerability in wpjobportal WP Job Portal wp-job-portal allows PHP Local File Inclusion.This issue affects WP Job Portal: from n/a through <= 2.2.8.
CVE-2025-26876 1 Codemanas 1 Search With Typesense 2026-04-23 N/A 6.8 MEDIUM
Path Traversal: '.../...//' vulnerability in CodeManas Search with Typesense search-with-typesense allows Path Traversal.This issue affects Search with Typesense: from n/a through <= 2.0.8.
CVE-2025-25122 2026-04-23 N/A 8.1 HIGH
Path Traversal: '.../...//' vulnerability in hashshop WizShop wizshop allows Path Traversal.This issue affects WizShop: from n/a through <= 3.0.2.
CVE-2025-24685 2026-04-23 N/A 8.1 HIGH
Path Traversal: '.../...//' vulnerability in Ihor Kit Morkva UA Shipping morkva-ua-shipping allows PHP Local File Inclusion.This issue affects Morkva UA Shipping: from n/a through <= 1.0.18.
CVE-2025-22786 1 Elementinvader 1 Elementinvader Addons For Elementor 2026-04-23 N/A 7.5 HIGH
Path Traversal: '.../...//' vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows PHP Local File Inclusion.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.2.6.
CVE-2024-56214 2026-04-23 N/A 8.3 HIGH
Path Traversal: '.../...//' vulnerability in DeluxeThemes Userpro userpro allows Path Traversal.This issue affects Userpro: from n/a through <= 5.1.9.