CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
SonicJS up to v0.7.0 allows attackers to execute an authenticated path traversal when an attacker injects special charac
The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and inc
Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends.
AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can access arbitrar
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through
_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVol
Directory traversal vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions
Knowage is the professional open source suite for modern business analytics over traditional sources and big data system
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of t
Uptime Kuma, a self-hosted monitoring tool, has a path traversal vulnerability in versions prior to 1.22.1. Uptime Kuma
A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5. A
SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remot
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyze
Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an attacker to perform unauthorized fi
Jenkins MathWorks Polyspace Plugin 1.0.5 and earlier allows attackers with Item/Configure permission to send emails with
Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the unde
Path Traversal vulnerability in SonicWall GMS and Analytics allows a remote authenticated attacker to read arbitrary fil
An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal in the Task Ex
IBM Security Verify Governance, Identity Manager 10.0 could allow a remote attacker to traverse directories on the syste
SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative
Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticate
cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possib
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, in the back office, files can be compro
Sensitive information disclosure due to unauthenticated path traversal. The following products are affected: Acronis Clo
i-doit Pro v25 and below was discovered to be vulnerable to path traversal.
M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerabilit
A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del.cgi is vulnerable to pa
Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux al
Path Traversal in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated us
A Path Traversal vulnerability exists in PaperCut NG before 22.1.1 and PaperCut MF before 22.1.1. Under specific conditi
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2
views.py in Wagtail CRX CodeRed Extensions (formerly CodeRed CMS or coderedcms) before 0.22.3 allows upward protected/..
A directory traversal vulnerability exists in the AgeVolt Portal prior to version 0.1 that leads to Information Disclosu
ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the S
The McFeeder server (distributed as part of SSW package), is susceptible to an arbitrary file write vulnerability on th
NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthentic
Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrati
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be
In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, a Directory Traversal in the print function of the
Directory Traversal vulnerability in jeecg-boot v.3.6.0 allows a remote privileged attacker to obtain sensitive informat
** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the ma
Path traversal vulnerability whose exploitation could allow an authenticated remote user to bypass SecurityManager's int
The discontinued FFS Colibri product allows a remote user to access files on the system including files containing login
Dell DM5500 contains a path traversal vulnerability in the appliance. A remote attacker with high privileges could po
The Frontend File Manager Plugin WordPress plugin before 22.6 has a vulnerability that allows an Editor+ user to bypass
Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be inc
Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated at
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started