CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
A vulnerability was discovered in the filename parameter in pathindex.php?r=cms-backend/attachment/delete&sub=&filename=
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal
Synerion TimeNet version 9.21 contains a directory traversal vulnerability where, on the "Name" parameter, the attacker
A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authent
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ in conjunction with a loginLess or login.htm URI (
MERCUSYS Mercury X18G 1.0.5 devices allow Directory Traversal via ../ to the UPnP server, as demonstrated by the /../../
Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks aga
In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "
The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 befor
Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write
Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involvin
In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via up
OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task.
Directory traversal vulnerability in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running
Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that
Directory Traversal in the fileDownload function in com/java2nb/common/controller/FileController.java in Novel-plus (小说精
MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 doe
Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded pat
Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword.
Directory Traversal vulnerability in WebPort <=1.19.1 in tags of system settings.
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Between versions 2.3.0 an
The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once()
The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attack
isomorphic-git before 1.8.2 allows Directory Traversal via a crafted repository.
An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths fo
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.ph
A path traversal vulnerability on Pardus Software Center's "extractArchive" function could allow anyone on the same netw
e7d Speed Test (aka speedtest) 0.5.3 allows a path-traversal attack that results in information disclosure via the "GET
In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArch
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially inc
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially inc
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files fr
There is a Directory traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affe
S3Scanner before 2.0.2 allows Directory Traversal via a crafted bucket, as demonstrated by a <Key>../ substring in a Lis
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). A zip slip vulnerability could be trigg
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in PDF Viewer component in
Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that
Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to
Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector
Dell EMC OpenManage Server Administrator (OMSA) versions 9.5 and prior contain a path traversal vulnerability. A remote
The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the sp
The specific function in ASUS BMC’s firmware Web management page (Record video file function) does not filter the specif
The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific p
The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific
The specific function in ASUS BMC’s firmware Web management page (Delete video file function) does not filter the specif
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an
IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in a way that may be v
Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.a
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started