CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete
Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by man
A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.
An unauthenticated attacker can exploit this vulnerability by manipulating URL to achieve arbitrary file read access.Thi
Bullwark Momentum Series JAWS 1.0 contains a directory traversal vulnerability that allows unauthenticated attackers to
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability
Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vul
Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system
gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by m
Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user c
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText™ XM Fax allows
OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendM
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files An
GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature th
Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remo
The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart S
The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elix
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Win
The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenam
A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple Cor
OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves stati
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Robert Seyfriedsberger i
An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.
OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal
OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplie
Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871, a Path Traversal vulnerability was identified i
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to vers
Easyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensi
Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary direct
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file rea
An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discov
The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.
liquidjs is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.0, the layout, render
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in gleam-wisp wisp allows a
ARMBot contains an unrestricted file upload vulnerability in upload.php that allows unauthenticated attackers to upload
Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes
Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi en
IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attacke
Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of
A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due t
Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for function
A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF ver
There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud
OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that accep
A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated r
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated f
phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbit
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started