CVE-2022-0855
Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.60%
- CWE
- CWE-41
- Published
- 2022-03-04
- Last modified
- 2026-03-13
Affected products
- microweber-dev microweber-dev/whmcs_plugin
Weakness type
Related vulnerabilities
- CVE-2026-85978 — Unauthenticated Remote Code Execution in Akana API Platform
- CVE-2025-24470 — An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.
- CVE-2024-8765 — Improper Path Equivalence Resolution in lunary-ai/lunary
- CVE-2026-57441 — MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
- CVE-2026-5816 — Improper Resolution of Path Equivalence in GitLab
- CVE-2023-46169 — IBM DS8900F file manipulation
- CVE-2026-72835 — filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization
- CVE-2026-34451 — Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories