CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the
Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated a
** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via t
Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in Broadcom DX NetOps Spectru
A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitra
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7
The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includ
Path Traversal vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If this vu
The Gutenberg Thim Blocks – Page Builder, Gutenberg Blocks for the Block Editor plugin for WordPress is vulnerable to ar
SiYuan is a personal knowledge management system. Versions prior to 3.5.4 contain a logic vulnerability in the /api/file
Chainlit versions prior to 2.9.4 contain an arbitrary file read vulnerability in the /project/element update flow. An au
A path traversal vulnerability exists in TMS Management Console (version 6.3.7.27386.20250818) from TMS Global Software.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Buil
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows mali
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows
pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it f
A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode.
Umbraco Forms is a form builder that integrates with the Umbraco content management system. It's possible for an authent
Free Photo & Video Vault 0.0.2 contains a directory traversal web vulnerability that allows remote attackers to manipula
Webile 1.0.1 contains a directory traversal vulnerability that allows remote attackers to manipulate file system paths w
Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clo
Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows
An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing v11.4.0 allows attackers
OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allow
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via p
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in th
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, th
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, th
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, th
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to,
Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Di
Dell Avamar Server and Avamar Virtual Edition, versions prior to 19.10 SP1 with CHF338912, contain an Improper Limitatio
The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v
OpenClaw is a personal AI assistant. Prior to version 2026.2.14, authenticated attackers can read arbitrary files from t
This vulnerability allows authenticated attackers to read an arbitrary file by changing a filepath parameter into an int
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 100plugins Open User Map
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple F
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticat
Dagu is a workflow engine with a built-in Web user interface. In versions up to and including 1.16.7, the `CreateNewDAG`
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up
Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/c
IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API M
A path traversal vulnerability exists in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporatio
A vulnerability has been found in SourceCodester Modern Image Gallery App 1.0. Impacted is an unknown function of the fi
A low-privileged remote attacker can exploit the ubr-logread method in wwwubr.cgi to read arbitrary files on the system.
Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to
Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started