CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the application
The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-si
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp
The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary f
PrinterLogic Windows Client through 25.0.0.676 allows attackers to execute directory traversal. Authenticated users with
Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote au
Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories
This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also i
Dell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi an
This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of ce
Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in
A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This i
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when buildi
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno
A path traversal vulnerability in KubeVirt versions up to 0.56 (and 0.55.1) on all platforms allows a user able to confi
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.
Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and com
The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file f
Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allo
MelisAssetManager provides deliveries of Melis Platform's assets located in every module's public folder. Attackers can
QTIWorks is a software suite for standards-based assessment delivery. Prior to version 1.0-beta15, the QTIWorks Engine a
Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due
Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not p
In some non-default installations of Esri Portal for ArcGIS versions 10.9.1 and below, a directory traversal issue may a
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with
Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr
OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. L
iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered
Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitra
Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when
Tauri is a framework for building binaries for all major desktop platforms. Due to missing canonicalization when `readDi
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. W
DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui
Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb man
Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function.
Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-upd
Multiple authenticated remote path traversal vulnerabilities were discovered in the AOS-CX command line interface in Aru
There is a path traversal vulnerability in CAMS for HIS Log Server contained in the following Yokogawa Electric products
ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.
ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special charac
ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special charac
LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile
There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30
Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php.
Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php.
HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.
dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/
Path Traversal in GitHub repository filegator/filegator prior to 7.8.0.
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started