CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.
QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint t
In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operat
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration re
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload wi
In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain contr
Improper limitation of pathname in Circuit Provisioning and File Import applications allows modification and uploading o
Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing
The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida
LocalSend is a free, open-source app that allows users to securely share files and messages with nearby devices over the
The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to arbitrary file deletion due
The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation
NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File In
A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. Th
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file upload process o
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sendin
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat
Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by man
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal
The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to L
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path tr
Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attac
A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac vers
Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote att
Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to ac
The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu
The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path
The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuff
The JKDEVKIT plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly valid
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly valid
The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on t
The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up
Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrit
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions u
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil
Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload an
Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Develope
MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extracta
The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an
Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attack
An attacker can obtain server information using Path Traversal vulnerability to conduct SQL Injection, which possibly ex
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangero
Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrar
Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve re
The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via the
Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started