Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3325

3325 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-33513 AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP) — AVideo 8.6 High2026-03-23
CVE-2026-33493 AVideo has a Path Traversal in import.json.php that Allows Private Video Theft and Arbitrary File Read/Deletion via fileURI Parameter — AVideo 7.1 High2026-03-23
CVE-2026-33293 AVideo Affected by Arbitrary File Deletion via Path Traversal in CloneSite deleteDump Parameter — AVideo 8.1 High2026-03-22
CVE-2026-33292 AVideo has Authorization Bypass via Path Traversal in HLS Endpoint Allows Streaming Private/Paid Videos — AVideo 7.5 High2026-03-22
CVE-2019-25610 NetNumber Titan Master 7.9.1 Path Traversal via drp — NetNumber Titan ENUM/DNS/NP 6.5 Medium2026-03-22
CVE-2026-4542 SSCMS layerImage Endpoint LayerImageController.Submit.cs path traversal — SSCMS 5.4 Medium2026-03-22
CVE-2019-25579 phpTransformer 2016.9 Directory Traversal via jQueryFileUpload — phpTransformer 7.5 High2026-03-21
CVE-2019-25577 SeoToaster Ecommerce 3.0.0 Local File Inclusion via backend_theme — SeoToaster Ecommerce 5.5 Medium2026-03-21
CVE-2019-25574 Green CMS 2.x Path Traversal Arbitrary File Download — Green CMS 6.5 Medium2026-03-21
CVE-2026-32055 OpenClaw < 2026.2.26 - Workspace Path Boundary Bypass via Non-existent Symlink — OpenClaw 7.6 High2026-03-21
CVE-2026-33238 AVideo has a Path Traversal in listFiles.json.php that Enables Server Filesystem Enumeration — AVideo 4.3 Medium2026-03-20
CVE-2026-3474 EmailKit <= 1.6.3 - Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API Parameter — EmailKit – Email Customizer for WooCommerce & WP 4.9 Medium2026-03-20
CVE-2026-3339 Keep Backup Daily <= 2.1.1 - Authenticated (Admin+) Limited Path Traversal via 'kbd_path' Parameter — Keep Backup Daily 2.7 Low2026-03-20
CVE-2026-33236 NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite — nltk 8.1 High2026-03-20
CVE-2026-32733 Halloy has a file transfer path traveral vulnerability — halloy 9.1 -2026-03-20
CVE-2026-33476 SiYuan has an Unauthenticated Arbitrary File Read via Path Traversal — siyuan 7.5 High2026-03-20
CVE-2026-33194 SiYuan has an Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr, /home — siyuan 6.8 Medium2026-03-20
CVE-2026-3864 CSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS server — CSI Driver for NFS 6.5 Medium2026-03-20
CVE-2026-23536 Feast: unauthenticated arbitrary file read — Red Hat OpenShift AI (RHOAI) 7.5 High2026-03-20
CVE-2026-33171 Statamic has a path traversal in file dictionary fieldtype — cms 4.3 Medium2026-03-20
CVE-2026-33166 Allure Report has an Arbitrary File Read via Path Traversal in Attachment Processing (Allure 1, Allure 2, and XCTest Readers) — allure2 8.6 High2026-03-20
CVE-2026-32310 Cryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC paths — cryptomator 4.1 Medium2026-03-20
CVE-2026-27625 Stirling-PDF Zip Slip: Arbitrary File Write via Path Traversal in Markdown-to-PDF ZIP Extraction — Stirling-PDF 8.1 High2026-03-20
CVE-2026-2421 ilGhera Carta Docente for WooCommerce <= 1.5.0 - Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'cert' Parameter — ilGhera Carta Docente for WooCommerce 6.5 Medium2026-03-20
CVE-2026-33054 Mesop: Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion — mesop 10.0 Critical2026-03-20
CVE-2026-32938 SiYuan has an Arbitrary File Read in its Desktop Publish Service — siyuan 9.9 Critical2026-03-20
CVE-2026-32808 pyLoad: Arbitrary File Deletion via Path Traversal during Encrypted 7z Password Verification — pyload 8.1 High2026-03-20
CVE-2026-32711 pydicom: Path traversal in FileSet/DICOMDIR ReferencedFileID allows file access outside the File-set root — pydicom 7.8 High2026-03-20
CVE-2026-32771 Monitoring is vulnerable to Archive Slip due to missing checks in sanitization — monitoring 9.1 -2026-03-20
CVE-2026-32033 OpenClaw < 2026.2.24 - Path Traversal via @-prefixed Absolute Paths in Workspace Boundary Validation — OpenClaw 6.5 Medium2026-03-19

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3325 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.