Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3325

3325 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-32846 OpenClaw Media Parsing Path Traversal to Arbitrary File Read — OpenClaw 8.6 -2026-03-26
CVE-2026-3112 Arbitrary File Read via Advanced Logging Support Packet — Mattermost 6.8 Medium2026-03-26
CVE-2025-41368 Multiple vulnerabilities in Small HTTP server by Smallsrv — Small HTTP 7.8 -2026-03-26
CVE-2026-33183 Saloon has a Fixture Name Path Traversal Vulnerability — saloon 8.1 -2026-03-26
CVE-2026-4758 WP Job Portal <= 2.4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field — WP Job Portal – AI-Powered Recruitment System for Company or Job Board website 8.8 High2026-03-25
CVE-2026-30976 Sonarr Path Traversal vulnerability — Sonarr 8.6 High2026-03-25
CVE-2026-32567 WordPress YML for Yandex Market plugin < 5.3.0 - Arbitrary File Deletion vulnerability — YML for Yandex Market 7.5 -2026-03-25
CVE-2026-32522 WordPress WooCommerce Support Ticket System plugin < 18.5 - Arbitrary File Deletion vulnerability — WooCommerce Support Ticket System 7.5 -2026-03-25
CVE-2026-32496 WordPress Spam Protect for Contact Form 7 plugin <= 1.2.9 - Arbitrary File Deletion vulnerability — Spam Protect for Contact Form 7 7.5 -2026-03-25
CVE-2026-31913 WordPress Scape theme < 1.5.16 - Arbitrary File Deletion vulnerability — Scape 7.5 -2026-03-25
CVE-2026-27040 WordPress WZone plugin <= 14.0.31 - Arbitrary File Deletion vulnerability — WZone 8.8 High2026-03-25
CVE-2026-25328 WordPress Product File Upload for WooCommerce plugin <= 2.2.4 - Arbitrary File Deletion vulnerability — Product File Upload for WooCommerce 6.8 Medium2026-03-25
CVE-2026-24970 WordPress Energox theme <= 1.2 - Arbitrary File Deletion vulnerability — Energox 7.7 High2026-03-25
CVE-2026-24969 WordPress Instant VA theme <= 1.0.1 - Arbitrary File Deletion vulnerability — Instant VA 7.7 High2026-03-25
CVE-2026-22448 WordPress PitchPrint plugin <= 11.1.2 - Arbitrary File Deletion vulnerability — PitchPrint 7.5 High2026-03-25
CVE-2026-33344 Dagu has an incomplete fix for CVE-2026-27598: path traversal via %2F-encoded slashes in locateDAG — dagu 8.1 High2026-03-24
CVE-2026-33329 FileRise: Path Traversal in `resumableIdentifier` Leading to Arbitrary File Write, Recursive Directory Deletion, and Limited Existence Oracle — FileRise 8.1 High2026-03-24
CVE-2026-33497 Langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading — langflow 6.5 -2026-03-24
CVE-2026-33309 Langflow has an Arbitrary File Write (RCE) via v2 API — langflow 10.0 Critical2026-03-24
CVE-2026-4741 Path Traversal Vulnerability in TeamJCD/JoyConDroid — JoyConDroid 8.1 -2026-03-24
CVE-2026-33211 Tekton Pipelines git resolver has path traversal that allows reading arbitrary files from the resolver pod — pipeline 9.6 Critical2026-03-23
CVE-2026-33242 Salvo has a Path Traversal in salvo-proxy::encode_url_path allows API Gateway Bypass — salvo 7.5 High2026-03-23
CVE-2026-33195 Rails Active Storage has possible Path Traversal in DiskService — activestorage 8.8 -2026-03-23
CVE-2025-60946 Census CSWeb path traversal — CSWeb 8.8 High2026-03-23
CVE-2026-23485 Blinko: Unauthorized Path Traversal File Enumeration - music-metadata — blinko 5.3 -2026-03-23
CVE-2026-23481 Blinko: Authenticated Arbitrary File Write - saveAdditionalDevFile — blinko 8.1 -2026-03-23
CVE-2026-23484 Blinko: Authenticated Arbitrary File Write - saveDevPlugin — blinko 6.5 -2026-03-23
CVE-2026-23483 Blinko: Unauthorized Arbitrary File Read - /plugins — blinko--2026-03-23
CVE-2026-23482 Blinko: Unauthorized Arbitrary File Read - /api/file/temp — blinko 5.3 -2026-03-23
CVE-2026-33681 AVideo has Path Traversal in pluginRunDatabaseScript.json.php Enables Arbitrary SQL File Execution via Unsanitized Plugin Name — AVideo 7.2 High2026-03-23

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3325 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.