CWE-24


Path Traversal: '../filedir'

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.


We have discovered 438,935 live websites that are affected by CWE-24.

Contact us to get more info









CVEs

  • Count - 4



Website Distribution by Country

Number of websites using CWE-24
United States147,300 websites



France139,397 websites
Germany16,905 websites
Russia13,312 websites
Brazil9,990 websites
Japan9,279 websites
China8,403 websites
Italy7,761 websites
Spain7,461 websites
Poland7,056 websites

Website Distribution by TLD

Number of websites using CWE-24
.com208,807 websites
.fr58,373 websites
.org22,895 websites
.net13,142 websites
.ru10,799 websites
.de10,287 websites
.com.br8,660 websites
.it7,256 websites
.be7,205 websites
.pl6,644 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-24
DiscoveredCVEDescriptionWebsites
May, 2025CVE-2025-48050 In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is loca...39,043
Apr, 2025CVE-2025-43919 GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitra...821
May, 2022CVE-2022-29253 Path Traversal in XWiki Platform1
Oct, 2021CVE-2021-21706 ZipArchive::extractTo may extract outside of destination dir399,750
List of the most common CVEs that are part of CWE-24
DiscoveredCVEDescriptionWebsites
Oct, 2021CVE-2021-21706 ZipArchive::extractTo may extract outside of destination dir399,750
May, 2025CVE-2025-48050 In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is loca...39,043
Apr, 2025CVE-2025-43919 GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitra...821
May, 2022CVE-2022-29253 Path Traversal in XWiki Platform1

Websites affected by CWE-24

Top websites that are affected by CWE-24. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States***
*****.pl Poland*,***
*****.*********.com United States*,***
****.org GB*,***
**********.org United States*,***
*******.**.uk Netherlands*,***
******.com France*,***
**********.com France*,***
***********.ch Switzerland*,***
***********.com United States*,***
See full domain list