Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3323

3323 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-40909 WWBN AVideo has a Path Traversal in Locale Save Endpoint that Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE) — AVideo 8.7 High2026-04-21
CVE-2026-40876 SFTP root escape via prefix-based path validation in goshs — goshs 8.8AIHighAI2026-04-21
CVE-2026-40611 Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider — lego 8.8 High2026-04-21
CVE-2026-41193 FreeScout has Zip Slip path traversal in module installation that allows arbitrary file write leading to RCE — freescout 9.1 Critical2026-04-21
CVE-2026-40576 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in excel-mcp-server — excel-mcp-server 9.4 Critical2026-04-21
CVE-2026-32147 SFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT — OTP 6.5AIMediumAI2026-04-21
CVE-2026-39973 Apktool: Path Traversal to Arbitrary File Write — Apktool 7.1 High2026-04-21
CVE-2026-39861 Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace — claude-code 8.8AIHighAI2026-04-21
CVE-2026-39378 nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding — nbconvert 6.5 Medium2026-04-21
CVE-2026-39377 nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames — nbconvert 6.5 Medium2026-04-21
CVE-2026-35570 OpenClaude has Sandbox Bypass via Early-Exit Logic Flaw that Allows Path Traversal — openclaude 8.4 High2026-04-20
CVE-2026-5478 Everest Forms <= 3.4.4 - Unauthenticated Arbitrary File Read and Deletion via Upload Field 'old_files' Parameter — Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder 8.1 High2026-04-20
CVE-2026-6248 wpForo Forum <= 3.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Field File Path — wpForo Forum 8.1 High2026-04-20
CVE-2026-25525 OpenMage LTS has Path Traversal Filter Bypass in Dataflow Module — magento-lts 4.9 Medium2026-04-20
CVE-2026-41245 Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix — junrar 5.9 Medium2026-04-20
CVE-2026-6636 p2r3 convert API buildCache.js Bun.serve path traversal — convert 4.3 Medium2026-04-20
CVE-2026-6620 SonicCloudOrg sonic-server File Upload Endpoint FileTool.java upload path traversal — sonic-server 6.3 Medium2026-04-20
CVE-2026-6615 TransformerOptimus SuperAGI Multipart Upload resources.py upload path traversal — SuperAGI 7.3 High2026-04-20
CVE-2026-6591 ComfyUI LoadImage Node folder_paths.py folder_paths.get_annotated_filepath path traversal — ComfyUI 4.3 Medium2026-04-20
CVE-2026-6590 ComfyUI Model Preview Endpoint model_manager.py get_model_preview path traversal — ComfyUI 4.3 Medium2026-04-20
CVE-2026-6568 kodcloud KodExplorer Public Share share.class.php initShareOld path traversal — KodExplorer 7.3 High2026-04-19
CVE-2026-40491 gdown Affected by Arbitrary File Write via Path Traversal in gdown.extractall — gdown 6.5 Medium2026-04-18
CVE-2026-40258 Gramps Web API has Zip Slip Path Traversal in Media Archive Import — gramps-web-api 9.1 Critical2026-04-17
CVE-2026-40342 Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution — firebird 10.0 Critical2026-04-17
CVE-2026-5710 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Limited Arbitrary File Read via mfile Field — Drag and Drop Multiple File Upload for Contact Form 7 7.5 High2026-04-17
CVE-2026-40518 ByteDance DeerFlow Path Traversal and Arbitrary File Write via Bootstrap Mode — deer-flow 7.1 High2026-04-17
CVE-2026-3464 WP Customer Area <= 8.3.4 - Authenticated (Subscriber+) Arbitrary File Read/Deletion via ajax_attach_file — WP Customer Area 8.8 High2026-04-17
CVE-2026-6496 prasathmani TinyFileManager POST Parameter filemanager.php path traversal — TinyFileManager 5.4 Medium2026-04-17
CVE-2026-6487 Qihui jtbc5 CMS Code Endpoint manage.php path traversal — jtbc5 CMS 4.3 Medium2026-04-17
CVE-2026-4659 Unlimited Elements For Elementor <= 2.0.6 - Authenticated (Contributor+) Arbitrary File Read via Path Traversal in Repeater JSON/CSV URL with Path Traversal — Unlimited Elements For Elementor 7.5 High2026-04-17

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3323 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.