CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

1,995
Total CVEs
447
Critical
1,009
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
231
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 26
2 Qnap 21
3 Ivanti 18
4 Fortinet 16
5 Samsung 16
6 Solarwinds 16
7 Fedoraproject 16
8 Siemens 15
9 Adobe 15
10 Debian 13

All Path Traversal CVEs (1,995)

CVE-2023-32004
8.8

This CVE describes a path traversal vulnerability in Node.js 20's experimental permission model where improper Buffer handling in file system APIs all...

Aug 15, 2023
CVE-2023-34129
8.8

This path traversal vulnerability in SonicWall GMS and Analytics allows authenticated attackers to extract arbitrary files from the underlying filesys...

Jul 13, 2023
CVE-2023-33177
8.8

This path traversal vulnerability in Xibo CMS allows authenticated users to upload specially crafted ZIP files via the layout import function, enablin...

May 30, 2023
CVE-2022-47875
8.8

This vulnerability allows authenticated remote attackers to perform directory traversal via the /be/erpc.php endpoint in Jedox, potentially leading to...

May 2, 2023
CVE-2023-24836
8.8

SUNNET CTMS has a path traversal vulnerability in its file upload function that allows authenticated users to upload and execute scripts in arbitrary ...

Apr 27, 2023
CVE-2023-1109
8.8

CVE-2023-1109 is a path traversal vulnerability in Phoenix Contacts ENERGY AXC PU Web service that allows authenticated users to read, write, and crea...

Apr 17, 2023
CVE-2023-27534
8.8

A path traversal vulnerability in curl's SFTP implementation allows attackers to bypass path filtering by using specially crafted paths containing til...

Mar 30, 2023
CVE-2023-22973
8.8

This CVE describes a Local File Inclusion vulnerability in OpenEMR's interface/forms/LBF/new.php file that allows authenticated remote attackers to ex...

Feb 22, 2023
CVE-2022-36889
8.8

This vulnerability in Jenkins Deployer Framework Plugin allows attackers with Item/Configure permission to upload arbitrary files from the Jenkins con...

Jul 27, 2022
CVE-2022-31395
8.8

This vulnerability allows attackers to perform directory traversal attacks on Algo Communication Products Ltd. 8373 IP Zone Paging Adapter devices. At...

Jun 23, 2022
CVE-2021-42643
8.8

CVE-2021-42643 is an arbitrary file write vulnerability in cmseasy CMS that allows attackers to write PHP script files to the web server. This can lea...

May 17, 2022
CVE-2021-44519
8.8

CVE-2021-44519 is an authenticated directory traversal vulnerability in Citrix XenMobile Server that allows authenticated attackers to escape director...

Apr 19, 2022
CVE-2022-26019
8.8

This vulnerability allows authenticated remote attackers with NTP GPS configuration privileges to overwrite files on pfSense systems, potentially lead...

Mar 31, 2022
CVE-2021-24962
8.8

This vulnerability in WordPress File Upload plugins allows users with Contributor role or higher to perform path traversal attacks via shortcode argum...

Mar 28, 2022
CVE-2022-25267
8.8

CVE-2022-25267 is a directory traversal vulnerability in Passwork On-Premise Edition that allows attackers to upload arbitrary files to any directory ...

Mar 23, 2022
CVE-2022-26500
8.8

CVE-2022-26500 is a path traversal vulnerability in Veeam Backup & Replication that allows authenticated remote attackers to access internal API funct...

Mar 17, 2022
CVE-2022-22771
8.8

This directory traversal vulnerability in TIBCO JasperReports products allows authenticated web server users to access files outside the intended dire...

Mar 15, 2022
CVE-2021-45010
8.8

This is an authenticated path traversal vulnerability in Tiny File Manager that allows users with valid accounts to upload malicious PHP files to the ...

Mar 15, 2022
CVE-2021-44664
8.8

This vulnerability allows authenticated attackers to upload malicious PHP files disguised as language files to Xerte installations, bypassing upload f...

Feb 24, 2022
CVE-2021-22748
8.8

This path traversal vulnerability in Schneider Electric's C-Bus Toolkit and C-Gate Server allows attackers to write files outside intended directories...

Feb 11, 2022
CVE-2021-44737
8.8

This CVE describes a PJL directory traversal vulnerability in Lexmark printers and multifunction devices that allows attackers to overwrite internal c...

Jan 20, 2022
CVE-2021-21879
8.8

This vulnerability allows authenticated attackers to perform directory traversal attacks through the Web Manager File Upload functionality in Lantroni...

Dec 22, 2021
CVE-2021-45418
8.8

This directory traversal vulnerability in Starcharge Nova 360 Cabinet and Titan 180 Premium products allows attackers to access arbitrary files on the...

Dec 22, 2021
CVE-2021-41185
8.8

CVE-2021-41185 is a path traversal vulnerability in Mycodo environmental monitoring systems that allows attackers to download files outside intended d...

Oct 26, 2021
CVE-2021-31385
8.8

This path traversal vulnerability in Juniper Networks Junos OS J-Web interface allows authenticated low-privileged users to escape directory restricti...

Oct 19, 2021
CVE-2021-40097
8.8

This vulnerability allows authenticated attackers in Concrete CMS to perform path traversal attacks, leading to remote code execution by uploading PHP...

Sep 27, 2021
CVE-2021-32814
8.8

CVE-2021-32814 is a directory traversal vulnerability in Skytable NoSQL database that allows remote attackers to delete or modify critical files on th...

Aug 3, 2021
CVE-2021-37441
8.8

CVE-2021-37441 is a path traversal vulnerability in NCH Axon PBX that allows attackers to delete arbitrary files on the system by manipulating the log...

Jul 25, 2021
CVE-2021-24453
8.8

The Include Me WordPress plugin through version 1.2.1 contains a path traversal vulnerability that allows attackers to read arbitrary files on the ser...

Jul 19, 2021
CVE-2021-24013
8.8

This path traversal vulnerability in FortiMail webmail allows authenticated users to access unauthorized files and data through specially crafted web ...

Jul 12, 2021
CVE-2021-28588
8.8

This vulnerability allows authenticated attackers to perform path traversal attacks via crafted HTTP POST requests in Adobe RoboHelp Server. Successfu...

Jun 28, 2021
CVE-2021-21090
8.8

CVE-2021-21090 is a path traversal vulnerability in Adobe InCopy that allows remote code execution when a user opens a malicious file. Attackers can e...

Jun 28, 2021
CVE-2021-21102
8.8

CVE-2021-21102 is a path traversal vulnerability in Adobe Illustrator that allows arbitrary code execution when a malicious file is opened. Attackers ...

Jun 28, 2021
CVE-2021-20517
8.8

This vulnerability in IBM WebSphere Application Server Network Deployment allows authenticated remote attackers to perform directory traversal attacks...

Jun 7, 2021
CVE-2021-22717
8.8

This path traversal vulnerability in Schneider Electric C-Bus Toolkit allows attackers to execute arbitrary code remotely by manipulating config file ...

Apr 13, 2021
CVE-2021-22719
8.8

This path traversal vulnerability in Schneider Electric's C-Bus Toolkit allows attackers to upload malicious files to arbitrary locations on the syste...

Apr 13, 2021
CVE-2026-23954
8.7

This vulnerability in Incus allows users with container launch privileges to exploit directory traversal or symbolic links in template functionality, ...

Jan 22, 2026
CVE-2025-24960
8.7

CVE-2025-24960 is a path traversal vulnerability in Jellystat (a statistics app for Jellyfin) that allows authenticated admin users to delete arbitrar...

Feb 3, 2025
CVE-2023-51366
8.7

This path traversal vulnerability in QNAP operating systems allows authenticated users to access files outside intended directories via network reques...

Sep 6, 2024
CVE-2024-7782
8.7

This vulnerability allows authenticated attackers with Administrator-level WordPress access to delete arbitrary files on the server due to insufficien...

Aug 20, 2024
CVE-2023-51364
8.7

This CVE-2023-51364 is a path traversal vulnerability in multiple QNAP operating system versions that allows authenticated users to read arbitrary fil...

Apr 26, 2024
CVE-2023-5504
8.7

The BackWPup WordPress plugin up to version 4.0.1 contains a directory traversal vulnerability in the Log File Folder setting. Authenticated attackers...

Jan 11, 2024
CVE-2023-4274
8.7

The WPvivid WordPress plugin up to version 0.9.89 contains a directory traversal vulnerability that allows authenticated administrators to delete arbi...

Oct 20, 2023
CVE-2023-33989
8.7

This vulnerability allows authenticated non-administrative users in SAP NetWeaver BI Content Add-On to exploit a directory traversal flaw to overwrite...

Jul 11, 2023
CVE-2023-29186
8.7

This vulnerability allows attackers with administrative privileges to exploit a directory traversal flaw in SAP NetWeaver BI CONT ADDON reports to upl...

Apr 11, 2023
CVE-2022-22685
8.7

This path traversal vulnerability in Synology WebDAV Server allows authenticated remote attackers to delete arbitrary files on the system. The vulnera...

Jul 28, 2022
CVE-2020-26295
8.7

This vulnerability allows authenticated administrators with specific permissions to inject executable files via layout XML in OpenMage, a community-dr...

Jan 21, 2021
CVE-2020-26252
8.7

This vulnerability allows authenticated administrators with product update permissions to upload executable files and execute them via layout XML in O...

Jan 20, 2021
CVE-2026-28679
8.6

CVE-2026-28679 is a path traversal vulnerability in Home-Gallery.org that allows attackers to download sensitive system files outside the intended med...

Mar 6, 2026
CVE-2026-0847
8.6

This vulnerability in NLTK allows attackers to read arbitrary files on the server through path traversal attacks in multiple CorpusReader classes. It ...

Mar 4, 2026

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 1,995 CVEs classified as CWE-22, with 447 rated critical and 1,009 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free