The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
CWE-22
CVE-2019-15596
A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.
CVE-2019-15600
A Path traversal exists in http_server which allows an attacker to read arbitrary system files.
CVE-2019-15516
Cuberite before 2019-06-11 allows webadmin directory traversal via ….// because the protection mechanism simply removes one ../ substring.
CVE-2019-15517
jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.
CVE-2019-15518
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.