CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files ou
zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Fl
The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based
SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inf
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attacker
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to de
OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and
A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to d
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with t
The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path va
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauth
Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when
An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 an
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing aut
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.
An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwri
PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vul
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to befo
In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backen
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content pa
Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.ses
The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic
A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validat
DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exis
An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.
OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, the application contains path traversal vulnerability
Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the a
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnera
Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Vers
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a p
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with
The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version
A low-privileged remote attacker can abuse the backup restore functionality of UBR (ubr-restore) which runs with elevate
A low-privileged remote attacker can exploit an arbitrary file write vulnerability in the wwupload.cgi endpoint. Due to
OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to writ
Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an
Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malic
Unraid Update Request Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar a
Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file direc
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In vers
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started