Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3357

3357 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-2707 zhijiantianya ruoyi-vue-pro Front-End Store Interface upload path traversal — ruoyi-vue-pro 5.4 Medium2025-03-24
CVE-2025-2749 Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE — Xperience 7.2 High2025-03-24
CVE-2025-1973 Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function — Export and Import Users and Customers 4.9 Medium2025-03-22
CVE-2024-13920 Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function — Order Export & Order Import for WooCommerce 4.9 Medium2025-03-20
CVE-2024-12866 Local File Inclusion in netease-youdao/qanything — netease-youdao/qanything 9.8 -2025-03-20
CVE-2024-8769 Arbitrary File Deletion via Relative Path Traversal in aimhubio/aim — aimhubio/aim 9.1 -2025-03-20
CVE-2024-10830 Path Traversal in eosphoros-ai/db-gpt — eosphoros-ai/db-gpt 9.1 -2025-03-20
CVE-2024-5752 Path Traversal in stitionai/devika — stitionai/devika 8.8 -2025-03-20
CVE-2024-8524 Directory Traversal in modelscope/agentscope — modelscope/agentscope 7.5 -2025-03-20
CVE-2024-12217 Path Traversal in gradio-app/gradio — gradio-app/gradio 3.3 -2025-03-20
CVE-2024-10948 Arbitrary File Read via Upload Function in binary-husky/gpt_academic — binary-husky/gpt_academic 6.5 -2025-03-20
CVE-2024-7776 Arbitrary File Overwrite in onnx/onnx — onnx/onnx 9.8 -2025-03-20
CVE-2024-8898 Path Traversal in parisneo/lollms-webui — parisneo/lollms-webui 9.1 -2025-03-20
CVE-2024-7034 Remote Code Execution due to Arbitrary File Write in open-webui/open-webui — open-webui/open-webui 9.1 -2025-03-20
CVE-2024-10707 Local File Inclusion in gaizhenbiao/chuanhuchatgpt — gaizhenbiao/chuanhuchatgpt 7.5 -2025-03-20
CVE-2024-6851 Arbitrary File Deletion in aimhubio/aim — aimhubio/aim 9.1 -2025-03-20
CVE-2024-8438 Path Traversal in modelscope/agentscope — modelscope/agentscope 7.5 -2025-03-20
CVE-2024-12065 Local File Inclusion in haotian-liu/llava — haotian-liu/llava 7.5 -2025-03-20
CVE-2024-8060 Remote Code Execution in OpenWebUI via Arbitrary File Upload — open-webui/open-webui 8.8 -2025-03-20
CVE-2024-9362 Directory Traversal in polyaxon/polyaxon — polyaxon/polyaxon 7.5 -2025-03-20
CVE-2024-9597 Path Traversal in parisneo/lollms — parisneo/lollms 9.1 -2025-03-20
CVE-2024-8581 Path Traversal in parisneo/lollms-webui — parisneo/lollms-webui 7.5 -2025-03-20
CVE-2024-10902 Arbitrary File Upload with Path Traversal in eosphoros-ai/db-gpt — eosphoros-ai/db-gpt 9.8 -2025-03-20
CVE-2024-10361 Arbitrary File Deletion via Path Traversal in danny-avila/librechat — danny-avila/librechat 9.1 -2025-03-20
CVE-2024-9415 Path Traversal in transformeroptimus/superagi — transformeroptimus/superagi 9.8 -2025-03-20
CVE-2024-11037 Path Traversal in binary-husky/gpt_academic — binary-husky/gpt_academic 7.5 -2025-03-20
CVE-2025-2505 Age Gate <= 3.5.3 - Unauthenticated Local PHP File Inclusion via 'lang' — Age Gate 9.8 Critical2025-03-20
CVE-2025-1770 Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Authenticated (Contributor+) Local File Inclusion — Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) 8.8 High2025-03-20
CVE-2025-27782 Applio allows arbitrary file write in inference.py — Applio 9.8 -2025-03-19
CVE-2025-27783 Applio allows arbitrary file write in train.py — Applio 9.8 -2025-03-19

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3357 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.