Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3344

3344 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-3474 EmailKit <= 1.6.3 - Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API Parameter — EmailKit – Email Customizer for WooCommerce & WP 4.9 Medium2026-03-20
CVE-2026-3339 Keep Backup Daily <= 2.1.1 - Authenticated (Admin+) Limited Path Traversal via 'kbd_path' Parameter — Keep Backup Daily 2.7 Low2026-03-20
CVE-2026-33236 NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite — nltk 8.1 High2026-03-20
CVE-2026-32733 Halloy has a file transfer path traveral vulnerability — halloy 9.1 -2026-03-20
CVE-2026-33476 SiYuan has an Unauthenticated Arbitrary File Read via Path Traversal — siyuan 7.5 High2026-03-20
CVE-2026-33194 SiYuan has an Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr, /home — siyuan 6.8 Medium2026-03-20
CVE-2026-3864 CSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS server — CSI Driver for NFS 6.5 Medium2026-03-20
CVE-2026-23536 Feast: unauthenticated arbitrary file read — Red Hat OpenShift AI (RHOAI) 7.5 High2026-03-20
CVE-2026-33171 Statamic has a path traversal in file dictionary fieldtype — cms 4.3 Medium2026-03-20
CVE-2026-33166 Allure Report has an Arbitrary File Read via Path Traversal in Attachment Processing (Allure 1, Allure 2, and XCTest Readers) — allure2 8.6 High2026-03-20
CVE-2026-32310 Cryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC paths — cryptomator 4.1 Medium2026-03-20
CVE-2026-27625 Stirling-PDF Zip Slip: Arbitrary File Write via Path Traversal in Markdown-to-PDF ZIP Extraction — Stirling-PDF 8.1 High2026-03-20
CVE-2026-2421 ilGhera Carta Docente for WooCommerce <= 1.5.0 - Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'cert' Parameter — ilGhera Carta Docente for WooCommerce 6.5 Medium2026-03-20
CVE-2026-33054 Mesop: Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion — mesop 10.0 Critical2026-03-20
CVE-2026-32938 SiYuan has an Arbitrary File Read in its Desktop Publish Service — siyuan 9.9 Critical2026-03-20
CVE-2026-32808 pyLoad: Arbitrary File Deletion via Path Traversal during Encrypted 7z Password Verification — pyload 8.1 High2026-03-20
CVE-2026-32711 pydicom: Path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root — pydicom 7.8 High2026-03-20
CVE-2026-32771 Monitoring is vulnerable to Archive Slip due to missing checks in sanitization — monitoring 9.1 -2026-03-20
CVE-2026-32033 OpenClaw < 2026.2.24 - Path Traversal via @-prefixed Absolute Paths in Workspace Boundary Validation — OpenClaw 6.5 Medium2026-03-19
CVE-2026-32030 OpenClaw < 2026.2.19 - Sensitive File Disclosure via stageSandboxMedia Path Traversal — OpenClaw 7.5 High2026-03-19
CVE-2026-32026 OpenClaw < 2026.2.24 - Arbitrary File Read via Improper Temporary Path Validation in Sandbox — OpenClaw 6.5 Medium2026-03-19
CVE-2026-32007 OpenClaw < 2026.2.23 - Sandbox Bypass in apply_patch Tool via Workspace-Only Check Bypass — OpenClaw 6.8 Medium2026-03-19
CVE-2026-32750 SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes — siyuan 6.8 Medium2026-03-19
CVE-2026-32747 SiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrets — siyuan 6.8 Medium2026-03-19
CVE-2026-25928 OpenEMR Vulnerable to Path Traversal When Zipping DICOM Folders — openemr 6.5 Medium2026-03-19
CVE-2026-32805 Romeo is vulnerable to Archive Slip due to missing checks in sanitization — romeo 8.8 -2026-03-18
CVE-2025-15031 Path Traversal Vulnerability in mlflow/mlflow — mlflow/mlflow 7.8 -2026-03-18
CVE-2026-32731 ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction — import-export 10.0 Critical2026-03-18
CVE-2026-27523 OpenClaw < 2026.2.24 - Sandbox Bind Validation Bypass via Symlink-Parent Missing-Leaf Paths — OpenClaw 6.1 Medium2026-03-18
CVE-2026-27522 OpenClaw < 2026.2.24 - Arbitrary File Read via sendAttachment and setGroupIcon Message Actions — OpenClaw 6.5 Medium2026-03-18

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3344 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.