CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a special
A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/dow
The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for Wor
Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary fil
The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to i
The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Download of Code Without Integrity Check
Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attacker
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information.
A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, mak
Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows auth
This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain
Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated atta
An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi
Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsControlle
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, a vulnerability was discovered
The WPFunnels plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in
The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i
Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authori
The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient
alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality all
STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary fi
A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attacker
A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attack
Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames
The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up t
The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0
WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Ser
WebsiteBaker 2.13.3 contains a directory traversal vulnerability that allows authenticated attackers to delete arbitrary
Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logg
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RomanCode MapSVG mapsvg
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Tuturn allows
EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access fi
VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows atta
A path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files via a specially craft
In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution.
Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Rad
Sending a crafted SOAP "provision" operation message PlanId field within the Mobile Network Operator (MNO) internal Radi
An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in uninte
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskF
Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedP
Directory Traversal in File Upload in Gleamtech FileVista 9.2.0.0 allows remote attackers to achieve Code Execution, Inf
A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. Affected is the function uploadImg of
A vulnerability, which was classified as critical, was found in zhangyanbo2007 youkefu 4.2.0. This affects an unknown pa
A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and
A vulnerability classified as critical was found in frdel Agent-Zero 0.8.1.2. This vulnerability affects unknown code of
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into inclu
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started