Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-4347 WP Fastest Cache <= 1.2.6 - Authenticated (Administrator+) Arbitrary File Deletion — WP Fastest Cache – WordPress Cache Plugin 7.2 High2024-05-23
CVE-2024-5147 WPZOOM Addons for Elementor (Templates, Widgets) <= 1.1.37 - Unauthenticated Local File Inclusion — WPZOOM Addons for Elementor – Starter Templates & Widgets 9.8 Critical2024-05-22
CVE-2024-5040 LCDS LAquis SCADA Path Traversal — LAquis SCADA 7.8 High2024-05-21
CVE-2024-4442 Salon booking system <= 9.9 - Unauthenticated Arbitrary File Deletion — Salon Booking System – Free Version 9.1 Critical2024-05-21
CVE-2024-32830 WordPress buddyforms plugin <= 2.8.8- Arbitrary File Read and SSRF vulnerability — BuddyForms 8.6 High2024-05-17
CVE-2024-32680 WordPress HUSKY plugin <= 1.3.5.2 - Remote Code Execution (RCE) vulnerability — HUSKY – Products Filter for WooCommerce (formerly WOOF) 8.8 High2024-05-17
CVE-2024-31300 WordPress Easy Social Share Buttons plugin <= 9.4 - Local File Inclusion vulnerability — Easy Social Share Buttons 8.5 High2024-05-17
CVE-2024-31232 WordPress Rehub theme <= 19.6.1 - Local File Inclusion vulnerability — Rehub 8.0 High2024-05-17
CVE-2024-31231 WordPress Rehub theme <= 19.6.1 - Unauthenticated Local File Inclusion vulnerability — Rehub 9.0 Critical2024-05-17
CVE-2024-30509 WordPress SellKit plugin <= 1.8.1 - Arbitrary File Download vulnerability — SellKit 6.5 Medium2024-05-17
CVE-2024-27954 WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary File Download and SSRF vulnerability — Automatic 9.3 Critical2024-05-17
CVE-2024-24934 WordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerability — Elementor Website Builder 8.5 High2024-05-17
CVE-2024-24869 WordPress Total Upkeep plugin <= 1.15.8 - Arbitrary File Download vulnerability — Total Upkeep 7.5 High2024-05-17
CVE-2023-51401 WordPress Ultimate Addons for Beaver Builder Premium plugin <= 1.35.13 - Limited Arbitrary File Download vulnerability — Ultimate Addons for Beaver Builder 6.3 Medium2024-05-17
CVE-2023-49753 WordPress Adifier System plugin < 3.1.4 - Local File Inclusion vulnerability — Adifier System 7.5 High2024-05-17
CVE-2023-47679 WordPress Qi Addons For Elementor plugin <= 1.6.3 - Local File Inclusion vulnerability — Qi Addons For Elementor 6.4 Medium2024-05-17
CVE-2023-47178 WordPress The Plus Addons for Elementor Pro plugin <= 5.2.8 - Unauthenticated Local File Inclusion vulnerability — The Plus Addons for Elementor Pro 8.6 High2024-05-17
CVE-2023-46784 WordPress ICS Calendar plugin <= 10.12.0.3 - SSRF and Arbitrary File Read vulnerability — ICS Calendar 8.2 High2024-05-17
CVE-2023-46205 WordPress Ultimate Addons for WPBakery Page Builder plugin <= 3.19.14 - Local File Inclusion vulnerability — Ultimate Addons for WPBakery Page Builder 7.1 High2024-05-17
CVE-2023-46197 WordPress Popup by Supsystic plugin <= 1.10.19 - Unauthenticated Subscriber Email Addresses Disclosure — Popup by Supsystic 5.3 Medium2024-05-17
CVE-2023-45652 WordPress Remote Content Shortcode plugin <= 1.5 - Local File Inclusion vulnerability — Remote Content Shortcode 6.5 Medium2024-05-17
CVE-2023-39163 WordPress Phlox Shop plugin <= 2.0.0 - Unauthenticated Local File Inclusion vulnerability — Phlox Shop 8.6 High2024-05-17
CVE-2023-38399 WordPress Phlox Portfolio plugin <= 2.3.1 - Unauthenticated Local File Inclusion vulnerability — Phlox Portfolio 8.6 High2024-05-17
CVE-2023-37888 WordPress Phlox Core Elements plugin <= 2.14.0 - Unauthenticated Local File Inclusion vulnerability — Shortcodes and extra features for Phlox theme 7.6 High2024-05-17
CVE-2023-37385 WordPress Consulting theme <= 6.5.6 - Local File Inclusion — Consulting 7.3 High2024-05-17
CVE-2023-35881 WordPress WooCommerce One Page Checkout plugin <= 2.3.0 - Local File Inclusion vulnerability — WooCommerce One Page Checkout 7.6 High2024-05-17
CVE-2023-33310 WordPress Unite Gallery Lite plugin <= 1.7.59 - Local File Inclusion vulnerability — Unite Gallery Lite 6.0 Medium2024-05-17
CVE-2023-32297 WordPress LWS Affiliation plugin <= 2.2.6 - Local File Inclusion vulnerability — LWS Affiliation 9.0 Critical2024-05-17
CVE-2023-32110 WordPress JupiterX theme <= 3.0.0 - Auth. Local File Inclusion vulnerability — JupiterX 7.6 High2024-05-17
CVE-2023-26526 WordPress Bookly plugin <= 21.7.1 - Authenticated Arbitrary File Deletion vulnerability — Bookly 7.7 High2024-05-17

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.