Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3331

3331 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-12493 ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template' — ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin 9.8 Critical2025-11-04
CVE-2025-12626 jeecgboot jeewx-boot WxActGoldeneggsPrizesController.java getImgUrl path traversal — jeewx-boot 4.3 Medium2025-11-03
CVE-2025-8385 Zombify <= 1.7.5 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read — Zombify 6.8 Medium2025-10-31
CVE-2025-10897 WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read — WooCommerce Designer Pro 8.6 High2025-10-31
CVE-2025-3356 IBM Tivoli Monitoring is vulnerable to unauthenticated file read and write operations — Tivoli Monitoring 8.6 High2025-10-30
CVE-2025-3355 IBM Tivoli Monitoring is vulnerable to unauthenticated file read and write operations — Tivoli Monitoring 7.5 High2025-10-30
CVE-2025-12060 Keras keras.utils.get_file Utility Path Traversal Vulnerability — Keras 5.3AIMediumAI2025-10-30
CVE-2025-11466 Allegra DatabaseBackupBL Directory Traversal Information Disclosure Vulnerability — Allegra 6.5AIMediumAI2025-10-29
CVE-2025-11201 MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability — MLflow 9.8AICriticalAI2025-10-29
CVE-2025-12422 Vulnerable Upgrade Feature (Arbitrary File Write) — BLU-IC2 8.8AIHighAI2025-10-28
CVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations — compose 9.8AICriticalAI2025-10-27
CVE-2025-12250 OpenWGA TMLScript API WGA.File path traversal — OpenWGA 4.7 Medium2025-10-27
CVE-2025-12055 Unauthenticated Local File Disclosure in MPDV Mikrolab MIP 2 / FEDRA 2 / HYDRA X Manufacturing Execution System — MIP 2 7.5AIHighAI2025-10-27
CVE-2025-12203 givanz Vvveb Code Editor functions.php sanitizeFileName path traversal — Vvveb 6.3 Medium2025-10-27
CVE-2025-10488 Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.4.8 - Authenticated (Subscriber+) Arbitrary File Move — Directorist: AI-Powered Business Directory, Listings & Classified Ads 8.1 High2025-10-25
CVE-2025-62254 Liferay Portal和Liferay DXP 路径遍历漏洞 — Portal 7.5AIHighAI2025-10-23
CVE-2025-41073 Path Traversal in Gandia Integra Total by TESI — Gandia Integra Total 6.5AIMediumAI2025-10-23
CVE-2025-60227 WordPress WP Pipes plugin <= 1.4.3 - Arbitrary File Deletion vulnerability — WP Pipes 8.6 High2025-10-22
CVE-2025-60217 WordPress PT Luxa Addons Plugin <= 1.2.2 - Arbitrary File Deletion Vulnerability — PT Luxa Addons 7.7 High2025-10-22
CVE-2025-59566 WordPress Workreap (theme's plugin) plugin <= 3.3.5 - Arbitrary File Deletion vulnerability — Workreap (theme's plugin) 7.7 High2025-10-22
CVE-2025-58959 WordPress Taskbot plugin <= 6.4 - Arbitrary File Deletion vulnerability — Taskbot 7.7 High2025-10-22
CVE-2025-62522 vite allows server.fs.deny bypass via backslash on Windows — vite 7.5AIHighAI2025-10-20
CVE-2025-3465 Path Traversal Vulnerability — CoreSense™ HM 7.1 High2025-10-20
CVE-2025-11941 e107 CMS Avatar image.php path traversal — CMS 5.4 Medium2025-10-19
CVE-2025-11939 ChurchCRM Backup Restore RestoreJob.php path traversal — ChurchCRM 4.7 Medium2025-10-19
CVE-2025-11914 Shenzhen Ruiming Technology Streamax Crocus DeviceFileReport.do download path traversal — Streamax Crocus 4.3 Medium2025-10-17
CVE-2025-11913 Shenzhen Ruiming Technology Streamax Crocus Service.do download path traversal — Streamax Crocus 4.3 Medium2025-10-17
CVE-2025-62424 ClipBucket path traversal vulnerability in template editor allows arbitrary file read and write — clipbucket-v5 6.7 Medium2025-10-17
CVE-2025-62356 Qodo Gen 安全漏洞 — Qodo Gen 7.5 High2025-10-17
CVE-2025-62353 Windsurf 安全漏洞 — Windsurf 9.8 Critical2025-10-17

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3331 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.