Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3346

3346 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-69376 WordPress User Extra Fields plugin <= 17.0 - Arbitrary File Deletion vulnerability — User Extra Fields 8.6 High2026-02-20
CVE-2025-68862 WordPress Woo File Dropzone plugin <= 1.1.7 - Arbitrary File Deletion vulnerability — Woo File Dropzone 7.7 High2026-02-20
CVE-2025-68002 WordPress Open User Map plugin <= 1.4.16 - Arbitrary File Download vulnerability — Open User Map 6.5 Medium2026-02-20
CVE-2026-26065 calibre: Path Traversal can Lead to Arbitrary File Write and Potential Code Execution — calibre 8.8 -2026-02-20
CVE-2026-26064 calibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code Execution — calibre 8.8 -2026-02-20
CVE-2026-26960 node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction — node-tar 7.1 High2026-02-20
CVE-2026-26972 OpenClaw has a Path Traversal in Browser Download Functionality — openclaw 6.7 Medium2026-02-19
CVE-2026-26329 OpenClaw has a path traversal in browser upload allows local file read — openclaw 6.5 -2026-02-19
CVE-2026-26321 OpenClaw has a local file disclosure via sendMediaFeishu in Feishu extension — openclaw 7.5 High2026-02-19
CVE-2025-8054 Path Traversal vulnerability have been discovered in OpenText™ XM Fax. — XM Fax 6.5AIMediumAI2026-02-19
CVE-2026-26202 Penpot has Arbitrary File Read via create-font-variant RPC endpoint — penpot 7.5 High2026-02-19
CVE-2026-25766 Echo has a Windows path traversal via backslash in middleware.Static default filesystem — echo 5.3 Medium2026-02-19
CVE-2026-25527 changedetection.io vulnerable to unauthenticated static path traversal — changedetection.io 5.3 Medium2026-02-19
CVE-2026-2731 Unauthenticated RCE in Dynamicweb 9 and Dynamicweb 8 — DynamicWeb 9 9.1AICriticalAI2026-02-19
CVE-2026-2692 CoCoTeaNet CyreneAdmin Image getAvatar path traversal — CyreneAdmin 4.3 Medium2026-02-19
CVE-2026-2683 Tsinghua Unigroup Electronic Archives System downLoad.html path traversal — Electronic Archives System 4.3 Medium2026-02-18
CVE-2019-25355 Genivia gSOAP 2.8 - 'gSOAP' Path Traversal — gSOAP 7.5 High2026-02-18
CVE-2019-25352 Genivia Crystal Live HTTP Server 6.01 - 'Crystal Live HTTP Server' Path Traversal — Crystal Live HTTP Server 7.5 High2026-02-18
CVE-2026-2672 Tsinghua Unigroup Electronic Archives System downLoad download path traversal — Electronic Archives System 4.3 Medium2026-02-18
CVE-2026-23491 InvoicePlane has Unauthenticated Path Traversal in Guest Controller — InvoicePlane 7.5 -2026-02-18
CVE-2026-22860 Rack has a Directory Traversal via Rack:Directory — rack 7.5 High2026-02-18
CVE-2026-2464 Directory Traversal in AMR Printer Management by AMR — AMR Printer Management Beta web service 7.5AIHighAI2026-02-18
CVE-2026-2426 WP-DownloadManager <= 1.69 - Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'file' Parameter — WP-DownloadManager 6.5 Medium2026-02-18
CVE-2026-2419 WP-DownloadManager <= 1.69 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'download_path' Parameter — WP-DownloadManager 2.7 Low2026-02-18
CVE-2026-2623 Blossom File Upload BLOSManager.java put path traversal — Blossom 6.3 Medium2026-02-17
CVE-2026-22762 Dell Avamar Server和Dell Avamar Virtual Edition 路径遍历漏洞 — Avamar Server 6.5 Medium2026-02-17
CVE-2025-36598 Dell Avamar 路径遍历漏洞 — Avamar Virtual Edition 6.5 Medium2026-02-17
CVE-2025-36597 Dell Avamar 路径遍历漏洞 — Avamar Server 4.7 Medium2026-02-17
CVE-2025-12062 WP Maps <= 4.8.6 - Authenticated (Subscriber+) Limited Local File Inclusion — WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters 8.8 High2026-02-16
CVE-2026-2552 ZenTao Editor control.php delete path traversal — ZenTao 5.5 Medium2026-02-16

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3346 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.