CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerab
PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality allows an a
The Moving Media Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val
SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" paramete
gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the
A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the syste
A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass
The Jobs for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file/folder listing p
Xorcom CompletePBX is vulnerable to an authenticated path traversal, allowing for arbitrary file reads via the Backup an
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in samsk Include URL includ
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tstafford include-file i
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in publitio Publitio publit
The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. T
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Nomupay
E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. In versions before 5.5.0,
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rockgod100 Theme File Du
Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to
An issue in the Printer Manager Systm of Entrust Corp Printer Manager D3.18.4-3 and below allows attackers to execute a
Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Pa
A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LikeCoin Web3Press likec
IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, t
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticate
The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including,
A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to
Arbitrary file write as the OSV-SCALIBR user on the host system via a path traversal vulnerability when using OSV-SCALIB
kotaemon is an open-source RAG-based tool for document comprehension. From versions 0.10.6 and prior, in libs/ktem/ktem/
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an
Conjur provides secrets management and application identity for infrastructure. An authenticated attacker who is able to
An issue in 4C Strategies Exonaut before v22.4 allows attackers to execute a directory traversal.
Path Traversal vulnerability in API Endpoint in Mobile Industrial Robots (MiR) Software Versions prior to 3.0.0 on MiR R
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various vers
Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attacker
qBit Manage is a tool that helps manage tedious tasks in qBittorrent and automate them. A path traversal vulnerability e
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Infility Infility Global
IBM QRadar SOAR Plugin App 1.0.0 through 5.6.0 could allow a remote attacker to traverse directories on the system. An a
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Serve
The Custom Query Shortcode plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.
A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attack
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and ear
The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started