Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)

1,121
CRITICAL
3,545
HIGH
2,893
MEDIUM
199
LOW
8,040 CVEs · Page 44/161
9.1
CVE-2025-65792

DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.

9.1
CVE-2020-36898

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint t

9.1
CVE-2025-68145

In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operat

9.1
CVE-2025-68398

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration re

9.1
CVE-2025-68916

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload wi

9.0
CVE-2025-27590

In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain contr

9.0
CVE-2025-48017

Improper limitation of pathname in Circuit Provisioning and File Import applications allows modification and uploading o

8.8
CVE-2025-22130

Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing

8.8
CVE-2024-13720

The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida

8.8
CVE-2025-27142

LocalSend is a free, open-source app that allows users to securely share files and messages with nearby devices over the

8.8
CVE-2025-1282

The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to arbitrary file deletion due

8.8
CVE-2024-12035

The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation

8.8
CVE-2025-2449

NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows

8.8
CVE-2025-1770

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File In

8.8
CVE-2024-9415

A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. Th

8.8
CVE-2025-2328

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion

8.8
CVE-2025-27718

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process o

8.8
CVE-2025-22923

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sendin

8.8
CVE-2025-3404

The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat

8.8
CVE-2025-2817

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by man

8.8
CVE-2025-32820

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal

8.8
CVE-2025-2158

The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to L

8.8
CVE-2025-47273

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path tr

8.8
CVE-2025-3486

Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attac

8.8
CVE-2025-31359

A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac vers

8.8
CVE-2025-3485

Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote att

8.8
CVE-2025-4613

Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to ac

8.8
CVE-2025-6379

The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu

8.8
CVE-2025-6755

The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path

8.8
CVE-2025-5014

The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuff

8.8
CVE-2025-2932

The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t

8.8
CVE-2025-40737

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly valid

8.8
CVE-2025-40738

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly valid

8.8
CVE-2025-53513

The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on t

8.8
CVE-2025-3740

The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up

8.8
CVE-2025-51480

Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrit

8.8
CVE-2025-54453

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi

8.8
CVE-2025-3671

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions u

8.8
CVE-2025-8141

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil

8.8
CVE-2024-13986

Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload an

8.8
CVE-2025-58158

Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Develope

8.8
CVE-2025-58755

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extracta

8.8
CVE-2025-41714

The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an

8.8
CVE-2025-56816

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attack

8.8
CVE-2025-11020

An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly ex

8.8
CVE-2025-11221

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangero

8.8
CVE-2025-35055

Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrar

8.8
CVE-2025-9713

Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve re

8.8
CVE-2025-11746

The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via the

8.8
CVE-2025-64107

Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may

Frequently Asked Questions

What is CWE-22?

CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-22?

There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.

How can I protect against CWE-22 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.

Detect CWE-22 Vulnerabilities

CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.

Get Started