CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesyste
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated
IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/i
OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows
A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file wri
WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php all
4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an
Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users t
Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authe
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to san
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename hand
In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the
A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerabil
An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory travers
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loa
Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests
The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.9.0 via t
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wikimedia Foundation Med
In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to
In Eptura Archibus 2024.03.01.109, the "Run script" and "Server File" components of the "Database Update Wizard" are vul
CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse
Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers t
Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attack
A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working d
Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrar
Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read fil
esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925
A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and
SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted s
Mini Mouse 9.2.0 contains a path traversal vulnerability that allows remote attackers to access arbitrary system files a
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Anona anona
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AivahThemes Hostme v2 ho
C++ HTTP Server is an HTTP/1.1 server built to handle client connections and serve HTTP requests. Versions 1.0 and below
Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary
A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthentic
The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0
The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthent
HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by
OpenCTI 3.3.1 is vulnerable to a directory traversal attack via the static/css endpoint. An unauthenticated attacker can
School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary file
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1
Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configur
NavigaTUM is a website and API to search for rooms, buildings and other places. Prior to commit 86f34c7, there is a path
NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filen
An unauthenticated remote attacker can bypass authentication by exploiting insufficient URI validation and using path tr
SiYuan is a personal knowledge management system. Prior to 3.5.5, the /api/file/getFile endpoint uses case-sensitive str
MiniGal Nano versions 0.3.5 and prior contain a path traversal vulnerability in index.php via the dir parameter. The app
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started