Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3341

3341 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-47513 WordPress Infocob CRM Forms plugin <= 2.4.0 - Arbitrary File Download vulnerability — Infocob CRM Forms 4.9 Medium2025-05-23
CVE-2025-47535 WordPress Opal Woo Custom Product Variation plugin <= 1.2.0 - Arbitrary File Deletion Vulnerability — Opal Woo Custom Product Variation 8.6 High2025-05-23
CVE-2025-47603 WordPress belingoGeo plugin <= 1.12.0 - Arbitrary File Download Vulnerability — belingoGeo 7.5 High2025-05-23
CVE-2025-48273 WordPress WP Job Portal plugin <= 2.3.2 - Arbitrary File Download Vulnerability — WP Job Portal 7.5 High2025-05-23
CVE-2025-4419 Hot Random Image <= 1.9.2 - Path Traversal to Authenticated (Contributor+) Limited Arbitrary Image Access via path Parameter — Hot Random Image 4.3 Medium2025-05-22
CVE-2025-3486 Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability — Allegra 8.8AIHighAI2025-05-22
CVE-2025-3884 Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability — Hue 7.5AIHighAI2025-05-22
CVE-2025-5029 Kingdee Cloud Galaxy Private Cloud BBC System File deleteFileAction.jhtml path traversal — Cloud Galaxy Private Cloud BBC System 5.4 Medium2025-05-21
CVE-2025-4524 Madara – Responsive and modern WordPress theme for manga sites <= 2.2.2 - Unauthenticated Local File Inclusion — Madara – Responsive and modern WordPress theme for manga sites 9.8 Critical2025-05-21
CVE-2025-48017 Improper Limitation of a Pathname to a Restricted Directory — SEL-5056 Software-Defined Network Flow Controller 9.0 Critical2025-05-20
CVE-2025-41229 VMware Cloud Foundation Directory Traversal Vulnerability — Cloud Foundation 8.2 High2025-05-20
CVE-2025-3223 WorkstationST EGD Configuration Server Path Traversal Vulnerability — WorkstationST 5.9 Medium2025-05-19
CVE-2025-32926 WordPress Grand Restaurant WordPress theme <= 7.0 - Path Traversal to PHP Object Injection vulnerability — Grand Restaurant 9.8 Critical2025-05-19
CVE-2025-27566 appleple a-blog cms 路径遍历漏洞 — a-blog cms 3.8 Low2025-05-19
CVE-2025-4912 SourceCodester Student Result Management System Image File update_student.php path traversal — Student Result Management System 5.4 Medium2025-05-19
CVE-2025-4898 SourceCodester Student Result Management System Logo File update_system.php unlink path traversal — Student Result Management System 5.4 Medium2025-05-18
CVE-2025-4893 jammy928 CoinExchange_CryptoExchange_Java File Upload Endpoint UploadFileUtil.java uploadLocalImage path traversal — CoinExchange_CryptoExchange_Java 6.3 Medium2025-05-18
CVE-2025-4868 merikbest ecommerce-spring-reactjs File Upload Endpoint admin path traversal — ecommerce-spring-reactjs 6.3 Medium2025-05-18
CVE-2025-47273 setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write — setuptools 9.8AICriticalAI2025-05-17
CVE-2025-40629 Path Traversal vulnerability in PNETLab — PNETLab 7.5AIHighAI2025-05-16
CVE-2025-4720 SourceCodester Student Result Management System drop_student.php path traversal — Student Result Management System 5.4 Medium2025-05-15
CVE-2025-47788 Missing Path Validation Enables Path Traversal in Controller.php — Atheos 9.8AICriticalAI2025-05-15
CVE-2025-4564 TicketBAI Facturas para WooCommerce <= 3.18 - Unauthenticated Arbitrary File Deletion — TicketBAI Facturas para WooCommerce 9.8 Critical2025-05-15
CVE-2024-13914 File Manager Advanced Shortcode <= Multiple Versions - Authenticated (Administrator+) Local JavaScript File Inclusion via Shortcode — File Manager Advanced Shortcode 7.2 High2025-05-15
CVE-2025-43566 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 6.8 Medium2025-05-13
CVE-2025-30387 Document Intelligence Studio On-Prem Elevation of Privilege Vulnerability — Azure AI Document Intelligence Studio 9.8 Critical2025-05-13
CVE-2025-31493 Path traversal of collection names during file system lookup — kirby 8.3AIHighAI2025-05-13
CVE-2025-30207 Kirby vulnerable to path traversal in the router for PHP's built-in server — kirby 8.1AIHighAI2025-05-13
CVE-2025-30159 Kirby vulnerable to path traversal of snippet names in the `snippet()` helper — kirby 7.1AIHighAI2025-05-13
CVE-2025-4632 SAMSUNG MagicINFO 9 Server 安全漏洞 — MagicINFO 9 Server 9.8 Critical2025-05-13

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3341 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.