References https://www.cnvd.org.cn/flaw/show/CNVD-2020-68596 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cnvd/2020/CNVD-2020-68596.yaml https://vulncheck.com/advisories/weiphp-path-traversal-file-read https://github.com/advisories/GHSA-r2vv-r3xx-x6mh https://nvd.nist.gov/vuln/detail/CVE-2025-34045 https://peiqi.wgpsec.org/wiki/cms/WeiPHP/WeiPHP5.0%20download_imgage%20%E5%89%8D%E5%8F%B0%E6%96%87%E4%BB%B6%E4%BB%BB%E6%84%8F%E8%AF%BB%E5%8F%96%20CNVD-2020-68596.html https://zhuanlan.zhihu.com/p/464706022 https://github.com/ping-0day/templates/blob/main/CNVD-2020-68596.yaml https://beaglesecurity.com/blog/vulnerability/weiphp-5-0-path-traversal.html https://github.com/emadshanab/goby-poc/blob/main/WeiPHP-Arbitrary-File-Read-(CNVD-2020-68596).json
Related VulnerabilitiesPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalPoCCVE-2026-44177: Kirby CMS 5.3.0-5.4.0 - Path TraversalPoCCVE-2024-1708: ConnectWise ScreenConnect <= 23.9.7 - Path TraversalPoCCVE-2026-54917: SeaweedFS <= 4.29 - Path Traversal File WritePoCCVE-2026-25895: FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File WritePoCCVE-2026-55224: MineAdmin < 3.2.0-alpha.2 - Plugin Path Traversal to RCEPoCnodogsplash-lfi: Nodogsplash - Directory TraversalPoCCVE-2025-71324: Flowise - Path TraversalPoCCVE-2026-34908: UniFi OS - Authentication Bypass via Path Traversal (..%2f)PoCCVE-2026-53519: Nezha Dashboard < 2.0.13 - Path TraversalPoCCVE-2024-56511: DataEase < 2.10.4 - Authentication Bypass via Whitelist Path TraversalPoCCVE-2025-71334: Flowise - Path TraversalPoCCVE-2026-31831: Tautulli <= 2.16.1 - Path Traversal