Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3355

3355 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-4893 jammy928 CoinExchange_CryptoExchange_Java File Upload Endpoint UploadFileUtil.java uploadLocalImage path traversal — CoinExchange_CryptoExchange_Java 6.3 Medium2025-05-18
CVE-2025-4868 merikbest ecommerce-spring-reactjs File Upload Endpoint admin path traversal — ecommerce-spring-reactjs 6.3 Medium2025-05-18
CVE-2025-47273 setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write — setuptools 9.8AICriticalAI2025-05-17
CVE-2025-40629 Path Traversal vulnerability in PNETLab — PNETLab 7.5AIHighAI2025-05-16
CVE-2025-4720 SourceCodester Student Result Management System drop_student.php path traversal — Student Result Management System 5.4 Medium2025-05-15
CVE-2025-47788 Missing Path Validation Enables Path Traversal in Controller.php — Atheos 9.8AICriticalAI2025-05-15
CVE-2025-4564 TicketBAI Facturas para WooCommerce <= 3.18 - Unauthenticated Arbitrary File Deletion — TicketBAI Facturas para WooCommerce 9.8 Critical2025-05-15
CVE-2024-13914 File Manager Advanced Shortcode <= Multiple Versions - Authenticated (Administrator+) Local JavaScript File Inclusion via Shortcode — File Manager Advanced Shortcode 7.2 High2025-05-15
CVE-2025-43566 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 6.8 Medium2025-05-13
CVE-2025-30387 Document Intelligence Studio On-Prem Elevation of Privilege Vulnerability — Azure AI Document Intelligence Studio 9.8 Critical2025-05-13
CVE-2025-31493 Path traversal of collection names during file system lookup — kirby 8.3AIHighAI2025-05-13
CVE-2025-30207 Kirby vulnerable to path traversal in the router for PHP's built-in server — kirby 8.1AIHighAI2025-05-13
CVE-2025-30159 Kirby vulnerable to path traversal of snippet names in the `snippet()` helper — kirby 7.1AIHighAI2025-05-13
CVE-2025-4632 SAMSUNG MagicINFO 9 Server 安全漏洞 — MagicINFO 9 Server 9.8 Critical2025-05-13
CVE-2024-4982 Pagure: path traversal in view_issue_raw_file() 7.6 High2025-05-12
CVE-2025-4545 CTCMS Content Management System File Tpl.php del path traversal — Content Management System 5.4 Medium2025-05-11
CVE-2025-4530 feng_ha_ha/megagao ssm-erp/production_ssm File FileController.java handleFileDownload path traversal — ssm-erp 4.3 Medium2025-05-11
CVE-2025-4529 Seeyon Zhiyuan OA Web Application System ZIP File M3CoreController.class download path traversal — Zhiyuan OA Web Application System 4.3 Medium2025-05-11
CVE-2025-4511 vector4wang spring-boot-quick quick-img2txt Img2TxtController.java ResponseEntity path traversal — spring-boot-quick 6.3 Medium2025-05-10
CVE-2025-2158 WordPress Review Plugin: The Ultimate Solution for Building a Review Website <= 5.3.5 - Authenticated (Contributor+) Local File Inclusion via Post Custom Fields — WordPress Review Plugin: The Ultimate Solution for Building a Review Website 8.8 High2025-05-10
CVE-2025-3897 EUCookieLaw <= 2.7.2 - Unauthenticated Arbitrary File Read — EUCookieLaw 5.9 Medium2025-05-09
CVE-2025-4206 WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg <= 4.1.1.2 - Authenticated (Administrator+) Arbitrary File Deletion — Groundhogg — CRM, Newsletters, and Marketing Automation 7.2 High2025-05-09
CVE-2025-4377 Path traversal vulnerability in Sparx Pro Cloud Server WebEA webconfig in logview.php — Pro Cloud Server 7.5AIHighAI2025-05-09
CVE-2024-6648 Path Traversal in AP Page Builder — AP Page Builder 7.5AIHighAI2025-05-08
CVE-2025-44021 OpenStack Ironic 安全漏洞 — Ironic 2.8 Low2025-05-08
CVE-2025-32820 SonicWALL SMA100 安全漏洞 — SMA100 8.1AIHighAI2025-05-07
CVE-2025-20187 Cisco SD-WAN Manager Software Arbitrary File Creation Vulnerability — Cisco Catalyst SD-WAN Manager 6.5 Medium2025-05-07
CVE-2025-22479 Dell Storage Manager 路径遍历漏洞 — Dell Storage Center - Dell Storage Manager 3.5 Low2025-05-06
CVE-2025-4329 74CMS index path traversal — 74CMS 4.3 Medium2025-05-06
CVE-2025-46559 Misskey Directory Traversal Vulnerability in AiScript via `Mk:api` — misskey 5.4 Medium2025-05-05

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3355 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.