Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3330

3330 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-15589 MuYuCMS Template Management Template.php delete_dir_file path traversal — MuYuCMS 3.8 Low2026-02-24
CVE-2026-3067 HummerRisk Archive Extraction CommandUtils.java extractZip path traversal — HummerRisk 6.3 Medium2026-02-24
CVE-2026-25965 ImageMagick's policy bypass through path traversal allows reading restricted content despite secured policy — ImageMagick 8.6 High2026-02-24
CVE-2026-3051 DataLinkDC dinky Project Name GitRepository.java getProjectDir path traversal — dinky 6.3 Medium2026-02-24
CVE-2026-23521 Traccar vulnerable to Path Traversal and External Control of File Name or Path — traccar 6.5 Medium2026-02-23
CVE-2026-2953 Dromara UJCMS Template WebFileTemplateController.delete deleteDirectory path traversal — UJCMS 5.4 Medium2026-02-22
CVE-2026-2864 feng_ha_ha/megagao ssm-erp/production_ssm PictureController.java pictureDelete path traversal — ssm-erp 5.4 Medium2026-02-21
CVE-2026-2863 feng_ha_ha/megagao ssm-erp/production_ssm FileServiceImpl.java deleteFile path traversal — ssm-erp 5.4 Medium2026-02-21
CVE-2026-2033 MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability — MLflow 9.8AICriticalAI2026-02-20
CVE-2026-27115 ADB Explorer is Vulnerable to Arbitrary Directory Deletion via Command-Line Argument — ADB-Explorer 7.1 High2026-02-20
CVE-2026-24953 WordPress Simple File List plugin <= 6.1.15 - Arbitrary File Download vulnerability — Simple File List 6.5AIMediumAI2026-02-20
CVE-2025-69379 WordPress Upload Files Anywhere plugin <= 2.8 - Arbitrary File Deletion vulnerability — Upload Files Anywhere 9.1AICriticalAI2026-02-20
CVE-2025-69377 WordPress User Extra Fields plugin <= 17.0 - Arbitrary File Deletion vulnerability — User Extra Fields 6.5AIMediumAI2026-02-20
CVE-2025-69380 WordPress Upload Files Anywhere plugin <= 2.8 - Arbitrary File Download vulnerability — Upload Files Anywhere 9.1AICriticalAI2026-02-20
CVE-2025-69376 WordPress User Extra Fields plugin <= 17.0 - Arbitrary File Deletion vulnerability — User Extra Fields 6.5AIMediumAI2026-02-20
CVE-2025-68862 WordPress Woo File Dropzone plugin <= 1.1.7 - Arbitrary File Deletion vulnerability — Woo File Dropzone 6.5AIMediumAI2026-02-20
CVE-2025-68002 WordPress Open User Map plugin <= 1.4.16 - Arbitrary File Download vulnerability — Open User Map 7.5AIHighAI2026-02-20
CVE-2026-26065 calibre: Path Traversal can Lead to Arbitrary File Write and Potential Code Execution — calibre 8.8 -2026-02-20
CVE-2026-26064 calibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code Execution — calibre 8.8 -2026-02-20
CVE-2026-26960 node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction — node-tar 7.1 High2026-02-20
CVE-2026-26972 OpenClaw has a Path Traversal in Browser Download Functionality — openclaw 6.7 Medium2026-02-19
CVE-2026-26329 OpenClaw has a path traversal in browser upload allows local file read — openclaw 6.5 -2026-02-19
CVE-2026-26321 OpenClaw has a local file disclosure via sendMediaFeishu in Feishu extension — openclaw 7.5 High2026-02-19
CVE-2025-8054 Path Traversal vulnerability have been discovered in OpenText™ XM Fax. — XM Fax 6.5AIMediumAI2026-02-19
CVE-2026-26202 Penpot has Arbitrary File Read via create-font-variant RPC endpoint — penpot 7.5 High2026-02-19
CVE-2026-25766 Echo has a Windows path traversal via backslash in middleware.Static default filesystem — echo 5.3 Medium2026-02-19
CVE-2026-25527 changedetection.io vulnerable to unauthenticated static path traversal — changedetection.io 5.3 Medium2026-02-19
CVE-2026-2731 Unauthenticated RCE in Dynamicweb 9 and Dynamicweb 8 — DynamicWeb 9 9.1AICriticalAI2026-02-19
CVE-2026-2692 CoCoTeaNet CyreneAdmin Image getAvatar path traversal — CyreneAdmin 4.3 Medium2026-02-19
CVE-2026-2683 Tsinghua Unigroup Electronic Archives System downLoad.html path traversal — Electronic Archives System 4.3 Medium2026-02-18

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3330 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.