CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

1,995
Total CVEs
447
Critical
1,009
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
231
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 26
2 Qnap 21
3 Ivanti 18
4 Fortinet 16
5 Samsung 16
6 Solarwinds 16
7 Fedoraproject 16
8 Siemens 15
9 Adobe 15
10 Debian 13

All Path Traversal CVEs (1,995)

CVE-2026-26984
8.8

LORIS versions before 26.0.5, 27.0.2, and 28.0.0 contain a path traversal vulnerability in the media module that allows authenticated users with suffi...

Feb 25, 2026
CVE-2026-26065
8.8

CVE-2026-26065 is a path traversal vulnerability in calibre's PDB readers that allows attackers to write arbitrary files anywhere the user has write p...

Feb 20, 2026
CVE-2026-26975
8.8

CVE-2026-26975 is a critical path traversal vulnerability in Music Assistant that allows unauthenticated attackers on the same network to write arbitr...

Feb 20, 2026
CVE-2025-12062
8.8

This vulnerability allows authenticated attackers with Subscriber-level access or higher to include and execute arbitrary .html files on WordPress ser...

Feb 17, 2026
CVE-2026-25161
8.8

This path traversal vulnerability in Alist allows authenticated attackers to bypass directory-level authorization by injecting traversal sequences int...

Feb 4, 2026
CVE-2026-25059
8.8

OpenList Frontend versions before 4.1.10 contain a path traversal vulnerability in file operation handlers that allows authenticated attackers to bypa...

Feb 2, 2026
CVE-2025-66428
8.8

A path traversal vulnerability in WebPros WordPress Toolkit before version 6.9.1 allows attackers to escalate privileges by manipulating WordPress dir...

Jan 22, 2026
CVE-2026-22685
8.8

A path traversal vulnerability in DevToys allows malicious extension packages to write files outside the intended directory, potentially overwriting s...

Jan 10, 2026
CVE-2025-69194
8.8

CVE-2025-69194 is a path traversal vulnerability in GNU Wget2's Metalink document handling that allows attackers to write files to arbitrary locations...

Jan 9, 2026
CVE-2023-53979
8.8

This vulnerability allows authenticated administrators in MyBB 1.8.32 to bypass avatar upload restrictions and execute arbitrary code through a chaine...

Dec 22, 2025
CVE-2025-66449
8.8

CVE-2025-66449 is an arbitrary file write vulnerability in ConvertX, a self-hosted online file converter. Authenticated users can upload files with ma...

Dec 16, 2025
CVE-2025-60786
8.8

A Zip Slip vulnerability in iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code by uploading a specially crafted Zip file. This affe...

Dec 15, 2025
CVE-2025-12824
8.8

The Player Leaderboard WordPress plugin contains a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level acces...

Dec 12, 2025
CVE-2025-66429
8.8

A directory traversal vulnerability in cPanel's Team Manager API allows attackers to overwrite arbitrary files, potentially leading to privilege escal...

Dec 11, 2025
CVE-2025-8110
KEV EPSS 22% 8.8

CVE-2025-8110 is a path traversal vulnerability in Gogs' PutContents API that allows improper symbolic link handling, enabling authenticated attackers...

Dec 10, 2025
CVE-2025-11531
8.8

This vulnerability allows attackers to execute files outside of restricted paths in HP System Event Utility and Omen Gaming Hub software. It affects u...

Dec 9, 2025
CVE-2025-65897
8.8

This vulnerability in zdh_web allows authenticated users to upload arbitrary files to any location on the server due to insufficient path validation. ...

Dec 5, 2025
CVE-2025-54307
8.8

This vulnerability allows authenticated low-privilege users to upload ZIP files containing path traversal payloads, enabling arbitrary file writes to ...

Dec 4, 2025
CVE-2025-66295
8.8

This vulnerability allows authenticated users with account creation privileges to perform path traversal attacks when creating new users in Grav CMS. ...

Dec 1, 2025
CVE-2025-12382
8.8

This path traversal vulnerability in Algosec Firewall Analyzer allows authenticated users to upload files to restricted directories, potentially leadi...

Nov 12, 2025
CVE-2025-64184
8.8

This vulnerability in Dosage comic downloader allows remote attackers to write arbitrary files outside the target directory by manipulating HTTP Conte...

Nov 7, 2025
CVE-2025-58423
8.8

This vulnerability allows attackers to upload malicious configuration files to vulnerable systems, potentially causing denial-of-service, directory tr...

Nov 6, 2025
CVE-2025-62630
8.8

This vulnerability allows attackers to upload malicious configuration files that bypass directory traversal protections, leading to remote code execut...

Nov 6, 2025
CVE-2025-12490
EPSS 19.7% 8.8

This vulnerability allows authenticated remote attackers to create arbitrary files on Netgate pfSense CE systems via a path traversal flaw in the Suri...

Nov 6, 2025
CVE-2025-64107
8.8

This vulnerability in Cursor AI code editor allows attackers to bypass path manipulation detection by using backslashes instead of forward slashes, en...

Nov 4, 2025
CVE-2025-64108
8.8

This CVE describes a path traversal vulnerability in Cursor AI code editor that allows attackers to bypass sensitive file protections via NTFS path qu...

Nov 4, 2025
CVE-2025-11746
8.8

The XStore WordPress theme contains a Local File Inclusion vulnerability that allows authenticated attackers with Subscriber-level access or higher to...

Oct 15, 2025
CVE-2025-9713
8.8

CVE-2025-9713 is a path traversal vulnerability in Ivanti Endpoint Manager (EPM) that allows remote unauthenticated attackers to achieve remote code e...

Oct 13, 2025
CVE-2025-35055
8.8

This vulnerability allows authenticated attackers to upload arbitrary files to any writable location in Newforma Info Exchange (NIX), potentially enab...

Oct 9, 2025
CVE-2025-11221
8.8

This vulnerability in GTONE ChangeFlow allows attackers to upload malicious files and traverse directory paths to access restricted areas. It affects ...

Oct 2, 2025
CVE-2025-11020
8.8

A path traversal vulnerability in MarkAny SafePC Enterprise allows attackers to access server information, potentially enabling SQL injection and unre...

Oct 2, 2025
CVE-2025-41714
8.8

This vulnerability allows authenticated attackers to perform path traversal attacks via the 'Upload-Key' header, enabling arbitrary file writes outsid...

Sep 10, 2025
CVE-2025-58755
8.8

This vulnerability in MONAI allows path traversal attacks through malicious ZIP files. When MONAI processes compressed files using extractall(), attac...

Sep 9, 2025
CVE-2025-58158
8.8

Harness Gitness git LFS server prior to version 3.3.0 has an arbitrary file write vulnerability due to improper path sanitization in the upload API. A...

Aug 29, 2025
CVE-2025-8141
8.8

The Redirection for Contact Form 7 WordPress plugin has an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any f...

Aug 20, 2025
CVE-2025-3671
8.8

The WPGYM WordPress plugin has a Local File Inclusion vulnerability that allows authenticated attackers with Subscriber-level access to include and ex...

Aug 16, 2025
CVE-2025-54453
8.8

This path traversal vulnerability in Samsung MagicINFO 9 Server allows attackers to access files outside the intended directory, potentially leading t...

Jul 23, 2025
CVE-2025-3740
8.8

This Local File Inclusion vulnerability in the School Management System for WordPress plugin allows authenticated attackers with Subscriber-level acce...

Jul 18, 2025
CVE-2025-40738
8.8

A path traversal vulnerability in SINEC NMS allows attackers to write arbitrary files to restricted locations by uploading malicious ZIP archives. Thi...

Jul 8, 2025
CVE-2025-2932
8.8

The JKDEVKIT WordPress plugin allows authenticated attackers with Subscriber-level access (or Contributor-level if WooCommerce is enabled) to delete a...

Jul 3, 2025
CVE-2025-5014
8.8

This vulnerability allows authenticated attackers with Subscriber-level access or higher to delete arbitrary files on WordPress servers running the Ho...

Jul 2, 2025
CVE-2025-6379
8.8

The BeeTeam368 Extensions Pro WordPress plugin contains a directory traversal vulnerability that allows authenticated attackers with Subscriber-level ...

Jun 28, 2025
CVE-2025-2158
8.8

This vulnerability allows authenticated attackers with Contributor-level access or higher to perform Local File Inclusion attacks in the WordPress Rev...

May 10, 2025
CVE-2025-2817
8.8

This vulnerability allows a medium-integrity user process to interfere with Thunderbird's SYSTEM-level updater by manipulating file-locking behavior. ...

Apr 29, 2025
CVE-2025-27718
8.8

A path traversal vulnerability in the USB storage file-sharing function of HGW-BL1500HM devices allows attackers to access, modify, or delete files an...

Mar 28, 2025
CVE-2025-2328
8.8

This vulnerability allows unauthenticated attackers to delete arbitrary files on WordPress servers using the Drag and Drop Multiple File Upload for Co...

Mar 28, 2025
CVE-2024-9415
8.8

A path traversal vulnerability in transformeroptimus/superagi version 0.0.14 allows attackers to upload arbitrary files to any location on the server....

Mar 20, 2025
CVE-2025-2449
8.8

This vulnerability in NI FlexLogger's usiReg component allows remote attackers to create arbitrary files via directory traversal in URI file parsing. ...

Mar 18, 2025
CVE-2024-12035
8.8

The CS Framework WordPress plugin has an arbitrary file deletion vulnerability that allows authenticated attackers with Subscriber-level access or hig...

Mar 7, 2025
CVE-2025-1282
8.8

This vulnerability in the Car Dealer Automotive WordPress theme allows authenticated attackers with Subscriber-level access or higher to delete arbitr...

Feb 27, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 1,995 CVEs classified as CWE-22, with 447 rated critical and 1,009 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free