CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
In WhatsUp Gold versions released before 2023.1.3, a path traversal vulnerability exists. A specially crafted unauthenti
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Livemesh Livemesh Addons
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AWSM Innovations AWSM Te
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vCita Online Booking & S
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DynamicWebLab WordPress
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExS ExS Widgets allows P
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Blue Plugins Events Cale
StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a c
SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.
Path traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS). If a remote authenticated atta
The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in versions 7.3.0 to 7.5.
Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is concatenated wi
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetWidgets fo
Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately fi
Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remo
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in
Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a s
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs a
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Ma
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rashid87 WPSection allow
Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remo
Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal
Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 2
The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including,
In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sk. Abul Hasan Animated
IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker co
Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowi
OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attack
Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDoc
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.
eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.
eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.
The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling the
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit
The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.
Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnera
Saltcorn is an extensible, open source, no-code database application builder. A logged-in user with any role can delete
Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of di
The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage lib
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerl
Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadB
Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web ser
A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPre
E-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server direct
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any
Allegra getFileContentAsString Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remot
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started