Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3327

3327 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-28795 OpenChatBI: Critical Path Traversal Vulnerability in save_report Tool of OpenChatBI — openchatbi 6.5 -2026-03-06
CVE-2026-28429 Talishar: Critical Path Traversal in gameName Parameter — Talishar 7.5 High2026-03-06
CVE-2026-28679 HomeGallery: Path Traversal (Arbitrary File Read) — home-gallery 8.6 High2026-03-06
CVE-2026-28676 OpenSift: Insufficient path containment checks in storage helpers could allow path traversal-style file operations — OpenSift 8.8 High2026-03-06
CVE-2026-28486 OpenClaw 2026.1.16-2 < 2026.2.14 - Path Traversal (Zip Slip) in Archive Extraction via Installation Commands — OpenClaw 6.1 Medium2026-03-05
CVE-2026-28482 OpenClaw < 2026.2.12 - Path Traversal via Unsanitized sessionId and sessionFile Parameters — OpenClaw 7.1 High2026-03-05
CVE-2026-28462 OpenClaw < 2026.2.13 - Path Traversal in Trace and Download Output Paths — OpenClaw 7.5 High2026-03-05
CVE-2026-28457 OpenClaw < 2026.2.14 - Path Traversal in Sandbox Skill Mirroring via Name Parameter — OpenClaw 6.1 Medium2026-03-05
CVE-2026-28453 OpenClaw < 2026.2.14 - Zip Slip Path Traversal in TAR Archive Extraction — OpenClaw 7.5 High2026-03-05
CVE-2026-28447 OpenClaw 2026.1.29-beta.1 < 2026.2.1 - Path Traversal in Plugin Installation via Package Name — OpenClaw 8.1 High2026-03-05
CVE-2026-28393 OpenClaw 2.0.0-beta3 < 2026.2.14 - Arbitrary JavaScript Module Loading via Hook Transform Path Traversal — OpenClaw 7.7 High2026-03-05
CVE-2026-24457 OpenMQ 安全漏洞 — Eclipse OpenMQ 9.1 Critical2026-03-05
CVE-2026-2743 SEPPmail User Web Interface Arbitrary File Write to RCE — SeppMail 8.8 -2026-03-05
CVE-2026-28078 WordPress uListing plugin <= 2.2.0 - Arbitrary File Download vulnerability — uListing 7.5 -2026-03-05
CVE-2026-22460 WordPress FormGent plugin <= 1.7.0 - Arbitrary File Deletion vulnerability — FormGent 8.6 High2026-03-05
CVE-2025-69411 WordPress ionCube tester plus plugin <= 1.3 - Arbitrary File Download vulnerability — ionCube tester plus 7.5 -2026-03-05
CVE-2026-28427 OpenDeck affected by path traversal allows arbitrary file read — OpenDeck 7.5AIHighAI2026-03-04
CVE-2026-0847 Path Traversal in nltk/nltk — nltk/nltk 7.5AIHighAI2026-03-04
CVE-2026-27442 zip_attachments Path Traversal — Secure Email Gateway 7.5AIHighAI2026-03-04
CVE-2026-28769 LFI in /IDC_Logging/checkifdone.cgi, "file" parameter Allowing for File Existence Enumeration On IDC Satellite Receiver Web Management Interface Version 101 — SFX Series SuperFlex Satellite Receiver Web management interface 6.5AIMediumAI2026-03-04
CVE-2026-24848 OpenEMR Arbitrary File Write leading to Remote Code Execution — openemr 8.8AIHighAI2026-03-03
CVE-2026-2606 IBM webMethods API Management fails to validate user input and enables unauthorized arbitrary file read — webMethods API Gateway (on-prem) 6.5 Medium2026-03-03
CVE-2026-28518 OpenViking .ovpack Import ZIP Slip Path Traversal — OpenViking 7.8 High2026-03-03
CVE-2026-2448 Page Builder by SiteOrigin <= 2.33.5 - Authenticated (Contributor+) Local File Inclusion — Page Builder by SiteOrigin 8.8 High2026-03-03
CVE-2026-0655 Path Traversal on TP-Link Deco BE25 — Deco BE25 v1.0 7.3AIHighAI2026-03-02
CVE-2026-3405 thinkgem JeeSite Connection path traversal — JeeSite 3.1 Low2026-03-02
CVE-2026-28406 kaniko has tar archive path traversal in build context extraction allows writing files outside destination directory — kaniko 8.2 High2026-02-27
CVE-2026-27734 Beszel Vulnerable to Docker API Path Traversal via Unsanitized Container ID — beszel 6.5 Medium2026-02-27
CVE-2026-24488 OpenEMR Vulnerable to Arbitrary File Exfiltration via Fax Endpoint — openemr 6.5 Medium2026-02-27
CVE-2026-3223 Zip Slip leading to Arbitrary File Write and Privilege Escalation in Google Web Designer — Web Designer 9.8 -2026-02-27

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3327 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.