Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3355

3355 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-3445 archiver 路径遍历漏洞 — github.com/mholt/archiver/v3 8.1 High2025-04-13
CVE-2025-32671 WordPress Print Science Designer plugin <= 1.3.155 - Arbitrary File Download vulnerability — Print Science Designer 7.5 High2025-04-11
CVE-2025-32633 WordPress Database Toolset Plugin <= 1.8.4 - Arbitrary File Deletion vulnerability — Database Toolset 8.6 High2025-04-11
CVE-2025-32631 WordPress Oxygen MyData for WooCommerce plugin <= 1.0.64 - Arbitrary File Deletion vulnerability — Oxygen MyData for WooCommerce 8.6 High2025-04-11
CVE-2025-32629 WordPress WP-BusinessDirectory Plugin <= 3.1.2 - Arbitrary File Deletion vulnerability — WP-BusinessDirectory 8.6 High2025-04-11
CVE-2025-32587 WordPress WooCommerce Pickupp plugin <= 2.4.3 - Local File Inclusion vulnerability — WooCommerce Pickupp 8.1 High2025-04-11
CVE-2025-32509 WordPress Simple WP Events plugin <= 1.8.17 - Arbitrary File Deletion vulnerability — Simple WP Events 7.5 High2025-04-11
CVE-2025-2636 InstaWP Connect <= 0.1.0.85 - Unauthenticated Local PHP File Inclusion — InstaWP Connect – 1-click WP Staging & Migration 8.1 High2025-04-11
CVE-2025-31411 WordPress Linet ERP-Woocommerce Integration plugin <= 3.5.12 - Arbitrary File Read/Deletion vulnerability — Linet ERP-Woocommerce Integration 5.9 Medium2025-04-10
CVE-2025-32209 WordPress Total processing card payments for WooCommerce Plugin <= 7.1.5 - Arbitrary File Download vulnerability — Nomupay Payment Processing Gateway 6.5 Medium2025-04-10
CVE-2025-32205 WordPress Piotnet Forms plugin <= 1.0.30 - Path Traversal vulnerability — Piotnet Forms 2.7 Low2025-04-10
CVE-2025-30582 WordPress DyaPress ERP/CRM plugin <= 18.0.2.0 - Local File Inclusion Vulnerability — DyaPress ERP/CRM 8.1 High2025-04-10
CVE-2025-30290 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 8.7 High2025-04-08
CVE-2025-32018 Arbitrary file write from Cursor Agent through a prompt injection from malicious @Docs — cursor 8.1 High2025-04-08
CVE-2025-25254 Fortinet FortiWeb 路径遍历漏洞 — FortiWeb 6.8 High2025-04-08
CVE-2024-41792 Siemens SENTRON 7KT PAC1260 Data Manager 路径遍历漏洞 — SENTRON 7KT PAC1260 Data Manager 8.6 High2025-04-08
CVE-2025-2519 Streamit <= 4.0.1 - Authenticated (Subscriber+) Arbitrary File Download — Streamit 6.5 Medium2025-04-08
CVE-2025-3381 zhangyanbo2007 youkefu File Upload WebIMController.java path traversal — youkefu 6.3 Medium2025-04-07
CVE-2025-3424 3.2.1 Arbitrary File Read in insecure .NET Remoting TCP Channel — IntelliSpace Portal 7.5AIHighAI2025-04-07
CVE-2025-31174 Huawei HarmonyOS 安全漏洞 — HarmonyOS 6.8 Medium2025-04-07
CVE-2025-3317 fumiao opencms dataPage.jsp path traversal — opencms 4.3 Medium2025-04-06
CVE-2025-2941 Drag and Drop Multiple File Upload for WooCommerce <= 1.1.4 - Unauthenticated Arbitrary File Move — Drag and Drop Multiple File Upload for WooCommerce 9.8 Critical2025-04-05
CVE-2025-3214 JFinal CMS readTemplate engine.getTemplate path traversal — CMS 4.3 Medium2025-04-04
CVE-2025-2270 Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.8.9.1 - Unauthenticated Limited Local File Inclusion — Countdown, Coming Soon, Maintenance – Countdown & Clock 8.1 High2025-04-04
CVE-2025-31827 WordPress Fonto plugin <= 1.2.2 - Arbitrary File Download vulnerability — Fonto 4.9 Medium2025-04-03
CVE-2025-31825 WordPress Category Icon plugin <= 1.0.1 - Arbitrary File Download vulnerability — Category Icon 4.9 Medium2025-04-03
CVE-2025-31800 WordPress Publitio plugin <= 2.2.0 - Arbitrary File Read vulnerability — Publitio 6.5 Medium2025-04-03
CVE-2025-31554 WordPress Docxpresso plugin <= 2.6 - Arbitrary File Download vulnerability — Docxpresso 5.9 Medium2025-04-03
CVE-2025-30596 WordPress include-file plugin <= 1 - Arbitrary File Download Vulnerability — include-file 6.5 Medium2025-04-03
CVE-2025-30841 WordPress Countdown & Clock plugin <=2.8.8 - Remote Code Execution (RCE) vulnerability — Countdown & Clock 9.9 Critical2025-04-01

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3355 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.