Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3346

3346 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-2551 ZenTao Backup control.php delete path traversal — ZenTao 5.4 Medium2026-02-16
CVE-2026-1793 Element Pack Addons for Elementor <= 8.3.17 - Authenticated (Contributor+) Arbitrary File Read — Element Pack – Widgets, Templates & Addons for Elementor 6.5 Medium2026-02-15
CVE-2025-13681 BFG Tools – Extension Zipper <= 1.0.7 - Authenticated (Administrator+) Path Traversal via 'first_file' Parameter — BFG Tools – Extension Zipper 4.9 Medium2026-02-14
CVE-2026-26187 lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access — lakeFS 8.1 High2026-02-13
CVE-2026-25964 Tandoor Recipes Affected by Authenticated Local File Disclosure (LFD) via Recipe Import leads to Arbitrary File Read — recipes 4.9 Medium2026-02-13
CVE-2026-21878 BACnet Stack Improperly Limits Pathnames to a Restricted Directory — bacnet-stack 7.5 High2026-02-13
CVE-2019-25333 Bullwark Momentum Series JAWS 1.0 - 'Momentum Series JAWS' Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — Momentum Series JAWS 7.5 High2026-02-12
CVE-2026-26217 Crawl4AI < 0.8.0 Docker API Local File Inclusion via file URL Handling — Crawl4AI 8.6 High2026-02-12
CVE-2025-15577 Valmet DNA Web server arbitrary file read access — Valmet DNA Web Tools 7.5AIHighAI2026-02-12
CVE-2020-37214 Voyager 1.3.0 - Directory Traversal — Voyager 7.5 High2026-02-11
CVE-2026-25062 Outline Affected an Arbitrary File Read via Path Traversal in JSON Import — outline 5.5 Medium2026-02-11
CVE-2026-25869 MiniGal Nano <= 0.3.5 Path Traversal via dir Parameter — MiniGal Nano 5.3AIMediumAI2026-02-11
CVE-2025-54162 File Station 5 — File Station 5 6.5AIMediumAI2026-02-11
CVE-2025-58470 Qsync Central — Qsync Central 7.5AIHighAI2026-02-11
CVE-2025-62853 File Station 5 — File Station 5 6.5AIMediumAI2026-02-11
CVE-2025-62855 File Station 5 — File Station 5 5.5AIMediumAI2026-02-11
CVE-2025-62856 File Station 5 — File Station 5 5.5AIMediumAI2026-02-11
CVE-2025-66278 File Station 5 — File Station 5 6.5AIMediumAI2026-02-11
CVE-2025-68406 Qsync Central — Qsync Central 7.5AIHighAI2026-02-11
CVE-2026-22894 File Station 5 — File Station 5 6.5AIMediumAI2026-02-11
CVE-2026-25872 JUNG Smart Panel 5.1 KNX Unauthenticated Path Traversal — JUNG Smart Panel 5.1 KNX 5.3 Medium2026-02-10
CVE-2026-25992 SiYuan has a File Read Interface Case Bypass Vulnerability — siyuan 7.5 High2026-02-10
CVE-2026-0651 Path Traversal on TP-Link Tapo D235 and C260 via Local https — Tapo C260 v1 6.1AIMediumAI2026-02-10
CVE-2025-12757 Axis Camera Station Pro 安全漏洞 — AXIS Camera Station Pro 4.6 Medium2026-02-10
CVE-2026-25895 FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API — FUXA 7.5AIHighAI2026-02-09
CVE-2026-25951 FUXA has a Path Traversal Sanitization Bypass — FUXA 7.2AIHighAI2026-02-09
CVE-2026-22905 Authentication Bypass via URI Traversal — 0852-1322 7.5 High2026-02-09
CVE-2026-2216 rachelos WeRSS we-mp-rss tools.py download_export_file path traversal — WeRSS we-mp-rss 4.3 Medium2026-02-09
CVE-2026-2111 JeecgBoot Retrieval-Augmented Generation edit path traversal — JeecgBoot 4.3 Medium2026-02-07
CVE-2026-25760 Website Path Traversal / Arbitrary File Read (Authenticated) in Sliver — sliver 6.5 Medium2026-02-06

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3346 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.