CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (1,995)
This CVE describes a path traversal vulnerability in Node.js 20's experimental permission model where improper Buffer handling in file system APIs all...
Aug 15, 2023This path traversal vulnerability in SonicWall GMS and Analytics allows authenticated attackers to extract arbitrary files from the underlying filesys...
Jul 13, 2023This path traversal vulnerability in Xibo CMS allows authenticated users to upload specially crafted ZIP files via the layout import function, enablin...
May 30, 2023This vulnerability allows authenticated remote attackers to perform directory traversal via the /be/erpc.php endpoint in Jedox, potentially leading to...
May 2, 2023SUNNET CTMS has a path traversal vulnerability in its file upload function that allows authenticated users to upload and execute scripts in arbitrary ...
Apr 27, 2023CVE-2023-1109 is a path traversal vulnerability in Phoenix Contacts ENERGY AXC PU Web service that allows authenticated users to read, write, and crea...
Apr 17, 2023A path traversal vulnerability in curl's SFTP implementation allows attackers to bypass path filtering by using specially crafted paths containing til...
Mar 30, 2023This CVE describes a Local File Inclusion vulnerability in OpenEMR's interface/forms/LBF/new.php file that allows authenticated remote attackers to ex...
Feb 22, 2023This vulnerability in Jenkins Deployer Framework Plugin allows attackers with Item/Configure permission to upload arbitrary files from the Jenkins con...
Jul 27, 2022This vulnerability allows attackers to perform directory traversal attacks on Algo Communication Products Ltd. 8373 IP Zone Paging Adapter devices. At...
Jun 23, 2022CVE-2021-42643 is an arbitrary file write vulnerability in cmseasy CMS that allows attackers to write PHP script files to the web server. This can lea...
May 17, 2022CVE-2021-44519 is an authenticated directory traversal vulnerability in Citrix XenMobile Server that allows authenticated attackers to escape director...
Apr 19, 2022This vulnerability allows authenticated remote attackers with NTP GPS configuration privileges to overwrite files on pfSense systems, potentially lead...
Mar 31, 2022This vulnerability in WordPress File Upload plugins allows users with Contributor role or higher to perform path traversal attacks via shortcode argum...
Mar 28, 2022CVE-2022-25267 is a directory traversal vulnerability in Passwork On-Premise Edition that allows attackers to upload arbitrary files to any directory ...
Mar 23, 2022CVE-2022-26500 is a path traversal vulnerability in Veeam Backup & Replication that allows authenticated remote attackers to access internal API funct...
Mar 17, 2022This directory traversal vulnerability in TIBCO JasperReports products allows authenticated web server users to access files outside the intended dire...
Mar 15, 2022This is an authenticated path traversal vulnerability in Tiny File Manager that allows users with valid accounts to upload malicious PHP files to the ...
Mar 15, 2022This vulnerability allows authenticated attackers to upload malicious PHP files disguised as language files to Xerte installations, bypassing upload f...
Feb 24, 2022This path traversal vulnerability in Schneider Electric's C-Bus Toolkit and C-Gate Server allows attackers to write files outside intended directories...
Feb 11, 2022This CVE describes a PJL directory traversal vulnerability in Lexmark printers and multifunction devices that allows attackers to overwrite internal c...
Jan 20, 2022This vulnerability allows authenticated attackers to perform directory traversal attacks through the Web Manager File Upload functionality in Lantroni...
Dec 22, 2021This directory traversal vulnerability in Starcharge Nova 360 Cabinet and Titan 180 Premium products allows attackers to access arbitrary files on the...
Dec 22, 2021CVE-2021-41185 is a path traversal vulnerability in Mycodo environmental monitoring systems that allows attackers to download files outside intended d...
Oct 26, 2021This path traversal vulnerability in Juniper Networks Junos OS J-Web interface allows authenticated low-privileged users to escape directory restricti...
Oct 19, 2021This vulnerability allows authenticated attackers in Concrete CMS to perform path traversal attacks, leading to remote code execution by uploading PHP...
Sep 27, 2021CVE-2021-32814 is a directory traversal vulnerability in Skytable NoSQL database that allows remote attackers to delete or modify critical files on th...
Aug 3, 2021CVE-2021-37441 is a path traversal vulnerability in NCH Axon PBX that allows attackers to delete arbitrary files on the system by manipulating the log...
Jul 25, 2021The Include Me WordPress plugin through version 1.2.1 contains a path traversal vulnerability that allows attackers to read arbitrary files on the ser...
Jul 19, 2021This path traversal vulnerability in FortiMail webmail allows authenticated users to access unauthorized files and data through specially crafted web ...
Jul 12, 2021This vulnerability allows authenticated attackers to perform path traversal attacks via crafted HTTP POST requests in Adobe RoboHelp Server. Successfu...
Jun 28, 2021CVE-2021-21090 is a path traversal vulnerability in Adobe InCopy that allows remote code execution when a user opens a malicious file. Attackers can e...
Jun 28, 2021CVE-2021-21102 is a path traversal vulnerability in Adobe Illustrator that allows arbitrary code execution when a malicious file is opened. Attackers ...
Jun 28, 2021This vulnerability in IBM WebSphere Application Server Network Deployment allows authenticated remote attackers to perform directory traversal attacks...
Jun 7, 2021This path traversal vulnerability in Schneider Electric C-Bus Toolkit allows attackers to execute arbitrary code remotely by manipulating config file ...
Apr 13, 2021This path traversal vulnerability in Schneider Electric's C-Bus Toolkit allows attackers to upload malicious files to arbitrary locations on the syste...
Apr 13, 2021This vulnerability in Incus allows users with container launch privileges to exploit directory traversal or symbolic links in template functionality, ...
Jan 22, 2026CVE-2025-24960 is a path traversal vulnerability in Jellystat (a statistics app for Jellyfin) that allows authenticated admin users to delete arbitrar...
Feb 3, 2025This path traversal vulnerability in QNAP operating systems allows authenticated users to access files outside intended directories via network reques...
Sep 6, 2024This vulnerability allows authenticated attackers with Administrator-level WordPress access to delete arbitrary files on the server due to insufficien...
Aug 20, 2024This CVE-2023-51364 is a path traversal vulnerability in multiple QNAP operating system versions that allows authenticated users to read arbitrary fil...
Apr 26, 2024The BackWPup WordPress plugin up to version 4.0.1 contains a directory traversal vulnerability in the Log File Folder setting. Authenticated attackers...
Jan 11, 2024The WPvivid WordPress plugin up to version 0.9.89 contains a directory traversal vulnerability that allows authenticated administrators to delete arbi...
Oct 20, 2023This vulnerability allows authenticated non-administrative users in SAP NetWeaver BI Content Add-On to exploit a directory traversal flaw to overwrite...
Jul 11, 2023This vulnerability allows attackers with administrative privileges to exploit a directory traversal flaw in SAP NetWeaver BI CONT ADDON reports to upl...
Apr 11, 2023This path traversal vulnerability in Synology WebDAV Server allows authenticated remote attackers to delete arbitrary files on the system. The vulnera...
Jul 28, 2022This vulnerability allows authenticated administrators with specific permissions to inject executable files via layout XML in OpenMage, a community-dr...
Jan 21, 2021This vulnerability allows authenticated administrators with product update permissions to upload executable files and execute them via layout XML in O...
Jan 20, 2021CVE-2026-28679 is a path traversal vulnerability in Home-Gallery.org that allows attackers to download sensitive system files outside the intended med...
Mar 6, 2026This vulnerability in NLTK allows attackers to read arbitrary files on the server through path traversal attacks in multiple CorpusReader classes. It ...
Mar 4, 2026About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 1,995 CVEs classified as CWE-22, with 447 rated critical and 1,009 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free