CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The impacted elem
A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/fram
An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.
A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0.
A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nos
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs
A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. The impacted element is the
A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82
A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market
Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote at
A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file c
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAn
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the fil
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file Fi
A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the file src/parsers/xd-
A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes
Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.8.7 has a path traversal vulner
e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to overrid
Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path s
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the restoreConfig function in vi
The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a dire
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginRunDatabaseScript
baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme
A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authentica
Emlog is an open source website building system. In versions 2.6.2 and prior, a path traversal vulnerability exists in t
The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/
Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS te
The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrator
ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacker
ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote a
Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted
A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacke
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below
An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbi
The HUSKY WordPress plugin before 1.4.1 does not sanitize a stored setting value against directory traversal before con
A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi
Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages/node_modules/@node-
The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to includ
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path t
In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can
Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This vulnerability allow
A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts
Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulner
Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilit
wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started