Use the CWE-21 category to scope related security reviews
MITRE defines CWE-21 as a category for organizing related weaknesses in the CWE catalog. Use the grouping as a scope and navigation aid, and rely on its linked weakness entries for implementation and verification guidance rather than treating the grouping as a directly testable defect.
CWE-21: CWE CATEGORY: DEPRECATED: Pathname Traversal and Equivalence Errors — MITRE CWE