Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3346

3346 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-41755 Arbitrary Read with ubr-logread — UBR-01 Mk II 6.5 Medium2026-03-09
CVE-2026-3795 doramart DoraCMS v1.js createFileBypath path traversal — DoraCMS 6.3 Medium2026-03-09
CVE-2026-3719 Tsinghua Unigroup Electronic Archives System downLoad path traversal — Electronic Archives System 5.3 Medium2026-03-08
CVE-2026-3695 SourceCodester Modern Image Gallery App delete.php path traversal — Modern Image Gallery App 6.5 Medium2026-03-08
CVE-2026-30848 Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory — parse-server 7.5 -2026-03-07
CVE-2026-29786 node-tar: Hardlink Path Traversal via Drive-Relative Linkpath — node-tar 7.5 -2026-03-07
CVE-2026-29780 eml_parser: Path Traversal in Official Example Script Leading to Arbitrary File Write — eml_parser 5.5 Medium2026-03-07
CVE-2026-29190 Karapace: Path Traversal in Backup Reader — karapace 4.1 Medium2026-03-07
CVE-2026-29185 @backstage/integration: Potential reading of SCM URLs using built in token — backstage 2.7 Low2026-03-07
CVE-2025-14675 Meta Box <= 5.11.1 - Authenticated (Contributor+) Arbitrary File Deletion — Meta Box 7.2 High2026-03-07
CVE-2026-29790 dbt-common: commonprefix() doesn't protect against path traversal — dbt-common 7.5 -2026-03-06
CVE-2026-29064 Zarf: Symlink targets in archives are not validated against destination directory — zarf 8.2 High2026-03-06
CVE-2018-25194 Nominas 0.27 SQL Injection via username Parameter — Nominas 8.2 High2026-03-06
CVE-2018-25184 Surreal ToDo 0.6.1.2 Local File Inclusion via index.php — Surreal ToDo 6.2 Medium2026-03-06
CVE-2018-25181 Musicco 2.0.0 Arbitrary Directory Download via Path Traversal — Musicco 7.5 High2026-03-06
CVE-2018-25178 Easyndexer 1.0 Arbitrary File Download via showtif.php — Easyndexer 7.5 High2026-03-06
CVE-2026-29059 Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly — windmill 7.5 -2026-03-06
CVE-2026-29065 changedetection.io: Zip Slip vulnerability in the backup restore functionality — changedetection.io 6.5 -2026-03-06
CVE-2026-28800 Natro Macro: Malicious actions allowed through Discord RC Commands by any user — NatroMacro 6.4 Medium2026-03-06
CVE-2026-28795 OpenChatBI: Critical Path Traversal Vulnerability in save_report Tool of OpenChatBI — openchatbi 6.5 -2026-03-06
CVE-2026-28429 Talishar: Critical Path Traversal in gameName Parameter — Talishar 7.5 High2026-03-06
CVE-2026-28679 HomeGallery: Path Traversal (Arbitrary File Read) — home-gallery 8.6 High2026-03-06
CVE-2026-28676 OpenSift: Insufficient path containment checks in storage helpers could allow path traversal-style file operations — OpenSift 8.8 High2026-03-06
CVE-2026-28486 OpenClaw 2026.1.16-2 < 2026.2.14 - Path Traversal (Zip Slip) in Archive Extraction via Installation Commands — OpenClaw 6.1 Medium2026-03-05
CVE-2026-28482 OpenClaw < 2026.2.12 - Path Traversal via Unsanitized sessionId and sessionFile Parameters — OpenClaw 7.1 High2026-03-05
CVE-2026-28462 OpenClaw < 2026.2.13 - Path Traversal in Trace and Download Output Paths — OpenClaw 7.5 High2026-03-05
CVE-2026-28457 OpenClaw < 2026.2.14 - Path Traversal in Sandbox Skill Mirroring via Name Parameter — OpenClaw 6.1 Medium2026-03-05
CVE-2026-28453 OpenClaw < 2026.2.14 - Zip Slip Path Traversal in TAR Archive Extraction — OpenClaw 7.5 High2026-03-05
CVE-2026-28447 OpenClaw 2026.1.29-beta.1 < 2026.2.1 - Path Traversal in Plugin Installation via Package Name — OpenClaw 8.1 High2026-03-05
CVE-2026-28393 OpenClaw 2.0.0-beta3 < 2026.2.14 - Arbitrary JavaScript Module Loading via Hook Transform Path Traversal — OpenClaw 7.7 High2026-03-05

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3346 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.