CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to,
Powered BLUE Server versions 0.20130927 and prior contain a path traversal vulnerability. If this vulnerability is explo
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to sanitize file names
A security flaw has been discovered in lostvip-com ruoyi-go up to 2.1. Impacted is the function DownloadTmp/DownloadUplo
MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path ve
In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of direct
In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not sanitized of directory trav
A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the
A security flaw has been discovered in Display Painéis TGA up to 7.1.41. Affected by this issue is some unknown function
A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function Download of the file Event
A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected element is the function fileO
A vulnerability was found in Dibo Data Decision Making System up to 2.7.0. The affected element is the function download
A vulnerability has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this vulnerability is
A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this issue is the function
Dell Secure Connect Gateway (SCG) 5.0 Application and Appliance version(s) 5.26.00.00 - 5.30.00.00, contain a Relative P
A security flaw has been discovered in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This affects
A vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.
A vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.
A security vulnerability has been detected in ORICO CD3510 1.9.12. This affects an unknown function of the component Fil
A vulnerability was found in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this issue is some unknown
An unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1 allows a remote attacker
Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path va
A security vulnerability has been detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The affected e
Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence o
A vulnerability was detected in Edimax BR-6208AC 1.02. This impacts the function handle_retr of the component FTP Daemon
Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traver
The Lana Downloads Manager WordPress plugin before 1.10.0 does not validate user input used in a path, which could allow
Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in Vim’s tar.vim plug
Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plug
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14
Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document s
Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully val
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do
Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This
In JetBrains TeamCity before 2025.11 path traversal was possible via file upload
A vulnerability was found in GreenCMS up to 2.3. This affects an unknown part of the file /DataController.class.php of t
The vulnerability allows any authenticated user to leak the contents of arbitrary “.m3u8” files from the PeerTube server
A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, al
An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote
The Permission Model assumes that any path starting with two backslashes \ has a four-character prefix that can be ignor
A directory traversal vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_
A vulnerability classified as problematic was found in ChestnutCMS 1.5.2. This vulnerability affects the function rename
Dell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Res
A vulnerability was found in frdel Agent-Zero up to 0.8.4. It has been rated as problematic. This issue affects the func
A vulnerability was found in xataio Xata Agent up to 0.3.0. It has been classified as problematic. This affects the func
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory tr
A vulnerability was identified in erjinzhi 10OA 1.0. Affected by this vulnerability is an unknown functionality of the f
Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's developm
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started