CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Jenkins visualexpert Plugin 1.3 and earlier does not restrict the names of files in methods implementing form validation
An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of
Qaelum DOSE 18.08 through 21.1 before 21.2 allows Directory Traversal via the loadimages name parameter. It allows a use
A vulnerability, which was classified as problematic, has been found in MuYuCMS 2.2. This issue affects some unknown pro
A vulnerability was found in MuYuCMS 2.2. It has been classified as problematic. Affected is an unknown function of the
A vulnerability was found in MuYuCMS 2.2. It has been declared as problematic. Affected by this vulnerability is an unkn
IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the syst
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote attacker to traverse dir
The WP Dark Mode WordPress plugin before 4.0.8 does not properly sanitize the style parameter in shortcodes before using
gatsby-plugin-sharp is a plugin for the gatsby framework which exposes functions built on the Sharp image processing lib
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the over
Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can li
A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an
Jenkins Sidebar Link Plugin 2.2.1 and earlier does not restrict the path of files in a method implementing form validati
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Item/Read permission to che
Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private brows
Gatsby is a free and open source framework based on React. The Gatsby framework prior to versions 4.25.7 and 5.9.1 conta
Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP,
A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warn
Pyramid is an open source Python web framework. A path traversal vulnerability in Pyramid versions 2.0.0 and 2.0.1 impac
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict the 'name' query parameter wh
In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path trav
Path traversal vulnerability in Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or higher privilege
Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Linux allows an auth
A vulnerability was found in Byzoro PatrolFlow 2530Pro up to 20231126. It has been rated as problematic. This issue affe
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK) and classified as proble
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Schweitzer Engine
The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2
GitPython is a python library used to interact with Git repositories. In order to resolve some git references, GitPython
sbt is a build tool for Scala, Java, and others. Given a specially crafted zip or JAR file, `IO.unzip` allows writing of
A vulnerability was found in MuYuCMS 2.2. It has been rated as problematic. Affected by this issue is some unknown funct
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connec
A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200,
A vulnerability was found in rails-cv-app. It has been rated as problematic. Affected by this issue is some unknown func
Path-Traversal in MKP storing in Tribe29 Checkmk <=2.0.0p32 and <= 2.1.0p18 allows an administrator to write mkp files t
A vulnerability, which was classified as problematic, was found in SiteFusion Application Server up to 6.6.6. This affec
A vulnerability was found in OTCMS up to 6.62 and classified as problematic. Affected by this issue is some unknown func
A vulnerability was found in WhiteHSBG JNDIExploit 1.4 on Windows. It has been rated as problematic. Affected by this is
A vulnerability was found in SATO CL4NX-J Plus 1.13.2-u455_r2. It has been rated as problematic. Affected by this issue
A vulnerability was found in ระบบบัญชีออนไลน์ Online Accounting System up to 1.4.0 and classified as problematic. This i
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path informa
In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git
Relative path traversal in the Zoom Client SDK before version 5.15.0 may allow an unauthorized user to enable informatio
Graylog is a free and open log management platform. A partial path traversal vulnerability exists in Graylog's `Support
Sudo-rs, a memory safe implementation of sudo and su, allows users to not have to enter authentication at every sudo att
The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to Directory Traversal in versions
Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker F
BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vuln
It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a m
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started