Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3327

3327 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2019-25687 Pegasus CMS 1.0 Remote Code Execution via extra_fields.php — Pegasus CMS 9.8 Critical2026-04-05
CVE-2019-25671 VA MAX 8.3.4 Remote Code Execution via changeip.php — VA MAX 8.8 High2026-04-05
CVE-2026-5595 griptape-ai griptape FileManagerTool save_memory_artifacts_to_disk path traversal — griptape 6.3 Medium2026-04-05
CVE-2026-5535 FedML-AI FedML MQTT Message FileUtils.java path traversal — FedML 4.3 Medium2026-04-05
CVE-2026-3666 wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post Body — wpForo Forum 8.8 High2026-04-04
CVE-2026-34607 Emlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCE — emlog 7.2 High2026-04-03
CVE-2026-34978 OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) — cups 6.5 Medium2026-04-03
CVE-2026-26058 Zulip: Path Traversal in Import — zulip 6.1 Medium2026-04-03
CVE-2026-22661 prompts.chat Path Traversal via Skill File Handling — prompts.chat 8.1 High2026-04-03
CVE-2026-35214 Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write — budibase 8.7 High2026-04-03
CVE-2026-4350 Perfmatters <= 2.5.9.1 - Authenticated (Subscriber+) Arbitrary File Deletion via 'delete' Parameter — Perfmatters 8.1 High2026-04-03
CVE-2026-34745 Unauthenticated Path Traversal Arbitrary File Write in /api/uploadChunked/public — fireshare 9.1 Critical2026-04-02
CVE-2026-34730 Copier `_external_data` allows path traversal and absolute-path local file read without unsafe mode — copier 5.5 Medium2026-04-02
CVE-2026-34726 Copier `_subdirectory` allows template root escape via parent-directory traversal — copier 4.4 Medium2026-04-02
CVE-2026-34591 Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write — poetry 7.8AIHighAI2026-04-02
CVE-2026-34524 SillyTavern: Path traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root — SillyTavern 8.3 High2026-04-02
CVE-2026-34523 SillyTavern: Path traversal allows file existence oracle — SillyTavern 5.3 Medium2026-04-02
CVE-2026-34522 SillyTavern: Path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory — SillyTavern 8.1 High2026-04-02
CVE-2026-34790 Endian Firewall /cgi-bin/backup.cgi remove ARCHIVE Directory Traversal — Endian Firewall 7.1 High2026-04-02
CVE-2026-5344 Textpattern XML-RPC TXP_RPCServer.php mt_uploadImage path traversal — Textpattern 6.3 Medium2026-04-02
CVE-2026-34728 phpMyFAQ: Path Traversal - Arbitrary File Deletion in MediaBrowserController — phpMyFAQ 8.7 High2026-04-02
CVE-2026-5331 OpenCart Extension Installer installer.php path traversal — OpenCart 4.7 Medium2026-04-02
CVE-2026-4347 MW WP Form <= 5.1.0 - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir — MW WP Form 8.1 High2026-04-02
CVE-2026-3987 WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UI — Fireware OS 7.2AIHighAI2026-04-01
CVE-2026-34750 Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints — payload 6.5 Medium2026-04-01
CVE-2026-34446 ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load — onnx 4.7 Medium2026-04-01
CVE-2026-20174 Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability — Cisco Nexus Dashboard 4.9 Medium2026-04-01
CVE-2026-34603 @tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions — tinacms 7.1 High2026-04-01
CVE-2026-34604 @tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions — tinacms 7.1 High2026-04-01
CVE-2026-33949 @tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files — tinacms 8.1 High2026-04-01

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3327 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.