Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3346

3346 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-28792 Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS — cli 9.7 Critical2026-03-12
CVE-2026-24125 Path Traversal in @tinacms/graphql — graphql 6.3 Medium2026-03-12
CVE-2026-4044 projectsend Delete import-orphans.php realpath path traversal — projectsend 3.8 Low2026-03-12
CVE-2026-3954 OpenBMB XAgent workspace.py workspace path traversal — XAgent 6.5 Medium2026-03-11
CVE-2019-25480 ARMBot Unrestricted File Upload via upload.php — ARMBot 7.5 High2026-03-11
CVE-2019-25471 FileThingie 2.5.7 Arbitrary File Upload via ft2.php — FileThingie 9.8 Critical2026-03-11
CVE-2026-30234 OpenProject BIM BCF XML Import: <Snapshot> Path Traversal Leads to Arbitrary Local File Read (AFR) — openproject 6.5 Medium2026-03-11
CVE-2026-27897 Vociferous Unauthenticated Remote Path Traversal (RCE via CSRF) — Vociferous 10.0 Critical2026-03-11
CVE-2026-3013 Path Traversal in Coppermine Photo Gallery — Coppermine Photo Gallery 7.5AIHighAI2026-03-11
CVE-2026-32061 OpenClaw < 2026.2.17 - Arbitrary File Read via $include Directive Path Traversal — openclaw 4.4 Medium2026-03-11
CVE-2026-32060 OpenClaw < 2026.2.14 - Path Traversal in apply_patch via Crafted Paths — openclaw 8.8 High2026-03-11
CVE-2026-21360 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Adobe Commerce 6.8 Medium2026-03-11
CVE-2026-28807 Path Traversal in wisp.serve_static allows arbitrary file read — wisp 7.5AIHighAI2026-03-10
CVE-2026-31817 OliveTin's unsafe parsing of UniqueTrackingId can be used to write files — OliveTin 8.5 High2026-03-10
CVE-2026-30952 liquidjs has a path traversal fallback vulnerability — liquidjs 8.1AIHighAI2026-03-10
CVE-2026-27825 MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment — mcp-atlassian 9.1 Critical2026-03-10
CVE-2026-30973 Zip Slip arbitrary file write in @appium/support ZIP extraction — support 6.5 Medium2026-03-10
CVE-2026-30958 OneUptime: Path Traversal — Arbitrary File Read (No Auth) — oneuptime 7.2 High2026-03-10
CVE-2025-54659 Fortinet FortiSOAR Agent Communication Bridge 路径遍历漏洞 — FortiSOAR Agent Communication Bridge 5.5 Medium2026-03-10
CVE-2026-30942 Flare has a Path Traversal in /api/avatars/[filename] — Flare 6.5AIMediumAI2026-03-10
CVE-2026-2741 Zip Slip Path Traversal on Node Unpack — vaadin 6.7AIMediumAI2026-03-10
CVE-2026-23907 Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code — Apache PDFBox Examples 7.1 -2026-03-10
CVE-2026-3585 The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import — The Events Calendar 7.5 High2026-03-10
CVE-2026-30869 SiYuan has a Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage — siyuan 9.3 Critical2026-03-09
CVE-2026-31802 node-tar Symlink Path Traversal via Drive-Relative Linkpath — node-tar 7.5AIHighAI2026-03-09
CVE-2026-1776 Camaleon CMS AWS Uploader Authenticated Path Traversal Arbitrary File Read — Camaleon CMS 6.5AIMediumAI2026-03-09
CVE-2026-30240 Budibase PWA ZIP Upload Path Traversal Allows Reading Arbitrary Server Files Including All Environment Secrets — budibase 9.6 Critical2026-03-09
CVE-2026-3089 Actual Sync Server 26.2.1 - Authenticated Path Traversal — Actual Sync Server 6.5AIMediumAI2026-03-09
CVE-2025-41758 Arbitrary Write with wwwupload.cgi — UBR-01 Mk II 8.8 High2026-03-09
CVE-2025-41757 Arbitrary Write with ubr-restore — UBR-01 Mk II 8.8 High2026-03-09

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3346 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.