CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknow
A vulnerability was found in xiaowei1118 java_server up to 11a5bac8f4ba1c17e4bc1b27cad6d24868500e3a on Windows and class
Misskey is an open source, federated social media platform. Starting in version 12.31.0 and prior to version 2025.4.1, m
A vulnerability was found in CTCMS Content Management System 2.1.2. It has been classified as critical. Affected is the
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This
A vulnerability has been found in SourceCodester Student Result Management System 1.0 and classified as critical. Affect
A vulnerability has been found in Kingdee Cloud Galaxy Private Cloud BBC System up to 9.0 Patch April 2025 and classifie
A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the functio
In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerabili
In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerabili
PHPGurukul Pre-School Enrollment System Project v1.0 is vulnerable to Directory Traversal in manage-classes.php.
A vulnerability classified as critical was found in risesoft-y9 Digital-Infrastructure up to 9.6.7. Affected by this vul
A vulnerability was found in letseeqiji gorobbs up to 1.0.8. It has been classified as critical. This affects the functi
A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. It has been
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been rated as critical. Affected by this issue is
A path traversal issue exists in file uploading feature of multiple versions of PowerCMS. Arbitrary files may be overwri
A vulnerability was found in code-projects Document Management System 1.0 and classified as critical. This issue affects
A vulnerability, which was classified as critical, has been found in linlinjava litemall up to 1.8.0. Affected by this i
A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This affects the func
A security vulnerability has been detected in SimStudioAI sim up to ed9b9ad83f1a7c61f4392787fb51837d34eeb0af. This affec
A weakness has been identified in 299ko up to 2.0.0. Affected by this issue is the function getSentDir/delete of the fil
A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functional
A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php
A vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.
A weakness has been identified in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. Impacted is an unknown fun
The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0
A vulnerability classified as critical has been found in 1902756969 reggie 1.0. Affected is the function download of the
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder
Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability could allow an attacker to modify a si
Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability allows an attacker to modify an email
BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to d
IBM Cloud Pak System 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could allow a remote att
Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows rem
An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a cra
Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted function
In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local t
The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal v
The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and inclu
The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all vers
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system.
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_sa
A vulnerability, which was classified as critical, was found in zyx0814 Pichome 2.1.0. This affects an unknown part of t
N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Custom
A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The i
A vulnerability, which was classified as critical, has been found in GuoMinJim PersonManage 1.0. This issue affects the
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Asia MyTicket Events
Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the cont
IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacke
The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started