CWE-22


Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.


We have discovered 4,097 live websites that are affected by CWE-22.

Contact us to get more info









CVEs

  • Count - 3



Countries

United States1,030 websites



Germany512 websites
France249 websites
Italy241 websites
GB163 websites
Poland159 websites
Russia147 websites
Netherlands137 websites
Spain118 websites
Japan115 websites

TLDs

.com1,377 websites
.org435 websites
.de326 websites
.it143 websites
.ru124 websites
.pl114 websites
.nl109 websites
.net100 websites
.fr99 websites
.eu75 websites

Newest CVEs

List of the most recent CVEs that are part of CWE-22
DiscoveredCVEDescriptionWebsites
Apr, 2023CVE-2023-1427 Photo Gallery by 10Web < 1.8.15 - Admin+ Path Traversal3,902
Jun, 2022CVE-2022-1657 JupiterX Theme <= 2.0.6 and Jupiter Theme <= 6.10.1 - Authenticated Path Traversal and Local File Inclusion169
Aug, 2021CVE-2021-34638 WordPress Download Manager <= 3.1.24 Authenticated Directory Traversal26
List of the most common CVEs that are part of CWE-22
DiscoveredCVEDescriptionWebsites
Apr, 2023CVE-2023-1427 Photo Gallery by 10Web < 1.8.15 - Admin+ Path Traversal3,902
Jun, 2022CVE-2022-1657 JupiterX Theme <= 2.0.6 and Jupiter Theme <= 6.10.1 - Authenticated Path Traversal and Local File Inclusion169
Aug, 2021CVE-2021-34638 WordPress Download Manager <= 3.1.24 Authenticated Directory Traversal26

Websites affected by CWE-22

Top websites that are affected by CWE-22. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.org Israel**,***
*********.kz Kazakhstan**,***
******.name France**,***
***********.org United States**,***
***.*******.com United States**,***
***.***.info United States**,***
***.**********.**.uk GB**,***
***.***********.com GB**,***
***.***.***.ph Philippines**,***
************.net United States**,***
See full domain list