Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)

1,121
CRITICAL
3,545
HIGH
2,893
MEDIUM
199
LOW
8,040 CVEs · Page 59/161
4.9
CVE-2024-47264

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functional

4.9
CVE-2024-13791

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the down

4.9
CVE-2025-26779

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Fahad Mahmood Keep Backu

4.9
CVE-2025-27274

Path Traversal: '.../...//' vulnerability in axelkeller GPX Viewer gpx-viewer allows Path Traversal.This issue affects G

4.9
CVE-2024-51958

There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allo

4.9
CVE-2024-51966

There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allo

4.9
CVE-2025-21095

Path traversal may lead to arbitrary file download. The score without least privilege principle violation is as calcula

4.9
CVE-2025-23416

Path traversal may lead to arbitrary file deletion. The score without least privilege principle violation is as calcula

4.9
CVE-2024-13920

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all version

4.9
CVE-2025-1973

The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, an

4.9
CVE-2025-1769

The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Direct

4.9
CVE-2025-31825

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pixelgrade Category Icon

4.9
CVE-2025-31827

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vlad.olaru Fonto fonto a

4.9
CVE-2025-27085

Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conducto

4.9
CVE-2025-3295

The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. T

4.9
CVE-2025-3577

**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B f

4.9
CVE-2025-46433

In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible

4.9
CVE-2025-46486

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Nomupay

4.9
CVE-2025-47513

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in James Laforge Infocob CR

4.9
CVE-2025-5741

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c

4.9
CVE-2025-53298

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in gioni Plugin Inspector p

4.9
CVE-2023-39339

A vulnerability exists on all versions of Ivanti Policy Secure below 22.6R1 where an authenticated administrator can per

4.9
CVE-2025-7518

The RSFirewall! plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.1.42 via th

4.9
CVE-2025-8081

The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via

4.9
CVE-2025-54715

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR S

4.9
CVE-2025-54927

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c

4.9
CVE-2025-9345

The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versio

4.9
CVE-2025-33032

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

4.9
CVE-2025-47211

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker

4.9
CVE-2025-9950

The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and

4.9
CVE-2025-37144

Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobilit

4.9
CVE-2025-37145

Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobilit

4.9
CVE-2025-54755

A directory traversal vulnerability exists in TMUI that allows a highly privileged authenticated attacker to access file

4.9
CVE-2025-11466

Allegra DatabaseBackupBL Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote atta

4.9
CVE-2025-20374

A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory

4.9
CVE-2025-13677

The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2

4.9
CVE-2025-13972

The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file read via the 'wht_download_big_object_origin' para

4.9
CVE-2025-67819

An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer

4.9
CVE-2025-12496

The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin

4.7
CVE-2025-2215

A vulnerability classified as critical was found in Doufox up to 0.2.0. Affected by this vulnerability is an unknown fun

4.7
CVE-2025-7566

A vulnerability has been found in jshERP up to 3.5 and classified as critical. This vulnerability affects the function e

4.7
CVE-2025-7575

A vulnerability has been found in Zavy86 WikiDocs up to 1.0.77 and classified as critical. Affected by this vulnerabilit

4.7
CVE-2025-48394

An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the

4.7
CVE-2025-48395

An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the

4.7
CVE-2025-10986

Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authent

4.7
CVE-2025-11939

A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/Chu

4.7
CVE-2025-12250

A flaw has been found in OpenWGA 7.11.12 Build 737. This affects an unknown function of the file WGA.File of the compone

4.7
CVE-2025-15138

A flaw has been found in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of

4.6
CVE-2025-54292

Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attac

4.5
CVE-2025-24889

The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on

Frequently Asked Questions

What is CWE-22?

CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-22?

There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.

How can I protect against CWE-22 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.

Detect CWE-22 Vulnerabilities

CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.

Get Started