CWE-36


Absolute Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.


We have discovered 6,931 live websites that are affected by CWE-36.

Contact us to get more info









CVEs

  • Count - 6



Website Distribution by Country

Number of websites using CWE-36
United States1,395 websites



Germany793 websites
Netherlands437 websites
France415 websites
Brazil344 websites
Russia267 websites
GB263 websites
Spain239 websites
Italy228 websites
Bulgaria184 websites

Website Distribution by TLD

Number of websites using CWE-36
.com2,389 websites
.de429 websites
.nl392 websites
.org303 websites
.com.br272 websites
.ru226 websites
.fr197 websites
.it183 websites
.co.uk143 websites
.net138 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-36
DiscoveredCVEDescriptionWebsites
Apr, 2026CVE-2026-34515 AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows181
Mar, 2026CVE-2026-4373 JetFormBuilder <= 3.5.6.2 - Unauthenticated Arbitrary File Read via Media Field5,414
Oct, 2025CVE-2025-7846 WordPress User Extra Fields <= 16.7 - Authenticated (Subscriber+) Arbitrary File Deletion via save_fields Function1
Jun, 2025CVE-2025-6381 BeeTeam368 Extensions <= 2.3.4 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Deletion18
Jun, 2025CVE-2025-5927 Everest Forms (Pro) <= 1.9.4 - Unauthenticated Path Traversal to Arbitrary File Deletion442
Jun, 2025CVE-2025-4799 WP-DownloadManager <= 1.68.10 - Authenticated (Administrator+) Arbitrary File Deletion875
List of the most common CVEs that are part of CWE-36
DiscoveredCVEDescriptionWebsites
Mar, 2026CVE-2026-4373 JetFormBuilder <= 3.5.6.2 - Unauthenticated Arbitrary File Read via Media Field5,414
Jun, 2025CVE-2025-4799 WP-DownloadManager <= 1.68.10 - Authenticated (Administrator+) Arbitrary File Deletion875
Jun, 2025CVE-2025-5927 Everest Forms (Pro) <= 1.9.4 - Unauthenticated Path Traversal to Arbitrary File Deletion442
Apr, 2026CVE-2026-34515 AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows181
Jun, 2025CVE-2025-6381 BeeTeam368 Extensions <= 2.3.4 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Deletion18
Oct, 2025CVE-2025-7846 WordPress User Extra Fields <= 16.7 - Authenticated (Subscriber+) Arbitrary File Deletion via save_fields Function1

Websites affected by CWE-36

Top websites that are affected by CWE-36. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.org United States**,***
*********.com United States**,***
*********.com United States**,***
**********.com United States**,***
*********.com Germany**,***
*******.com United States**,***
************.ru Russia**,***
*****.cz Czech Republic**,***
*****.org United States**,***
****.********.edu United States**,***
See full domain list