CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,002
Total CVEs
452
Critical
1,009
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
233
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 26
2 Qnap 21
3 Ivanti 18
4 Fortinet 16
5 Samsung 16
6 Solarwinds 16
7 Fedoraproject 16
8 Siemens 15
9 Adobe 15
10 Debian 13

All Path Traversal CVEs (2,002)

CVE-2022-22685
8.7

This path traversal vulnerability in Synology WebDAV Server allows authenticated remote attackers to delete arbitrary files on the system. The vulnera...

Jul 28, 2022
CVE-2020-26295
8.7

This vulnerability allows authenticated administrators with specific permissions to inject executable files via layout XML in OpenMage, a community-dr...

Jan 21, 2021
CVE-2020-26252
8.7

This vulnerability allows authenticated administrators with product update permissions to upload executable files and execute them via layout XML in O...

Jan 20, 2021
CVE-2026-28679
8.6

CVE-2026-28679 is a path traversal vulnerability in Home-Gallery.org that allows attackers to download sensitive system files outside the intended med...

Mar 6, 2026
CVE-2026-0847
8.6

This vulnerability in NLTK allows attackers to read arbitrary files on the server through path traversal attacks in multiple CorpusReader classes. It ...

Mar 4, 2026
CVE-2026-25965
8.6

ImageMagick's path security policy enforcement occurs before filesystem path resolution, allowing path traversal attacks to bypass policy rules like '...

Feb 24, 2026
CVE-2025-69379
8.6

This path traversal vulnerability in the WordPress 'Upload Files Anywhere' plugin allows attackers to delete arbitrary files on the server. It affects...

Feb 20, 2026
CVE-2026-25635
8.6

Calibre e-book manager versions before 9.2.0 contain a path traversal vulnerability in the CHM reader that allows attackers to write arbitrary files a...

Feb 6, 2026
CVE-2026-24486
8.6

Python-Multipart versions before 0.0.22 contain a path traversal vulnerability when configured with UPLOAD_DIR and UPLOAD_KEEP_FILENAME=True. Attacker...

Jan 27, 2026
CVE-2025-68912
8.6

This CVE describes a path traversal vulnerability in the Harmonic Design HDForms WordPress plugin, allowing attackers to delete arbitrary files on the...

Jan 22, 2026
CVE-2025-68901
8.6

This path traversal vulnerability in the Anona WordPress theme allows attackers to delete arbitrary files on affected systems. It affects all WordPres...

Jan 22, 2026
CVE-2025-67963
8.6

This path traversal vulnerability in the ovatheme Movie Booking WordPress plugin allows attackers to delete arbitrary files on the server. It affects ...

Jan 22, 2026
CVE-2026-23949
8.6

CVE-2026-23949 is a Zip Slip path traversal vulnerability in jaraco.context's tarball() function that allows attackers to extract files outside the in...

Jan 20, 2026
CVE-2025-63680
8.6

This vulnerability in Nero BackItUp allows arbitrary code execution when a user clicks on a crafted entry in the software's interface. Attackers can e...

Nov 14, 2025
CVE-2025-27222
8.6

CVE-2025-27222 is a path traversal vulnerability in TRUfusion Enterprise's /trufusionPortal/getCobrandingData endpoint that allows attackers to read a...

Oct 27, 2025
CVE-2025-10449
8.6

This path traversal vulnerability in Saysis Web Portal allows attackers to access files outside the intended directory by manipulating file paths. It ...

Sep 25, 2025
CVE-2025-48158
8.6

This path traversal vulnerability in the BuddyPress XProfile Custom Image Field WordPress plugin allows attackers to delete arbitrary files on the ser...

Aug 20, 2025
CVE-2025-49415
8.6

This path traversal vulnerability in FW Gallery WordPress plugin allows attackers to delete arbitrary files on the server by manipulating file paths. ...

Jun 17, 2025
CVE-2025-47535
8.6

This path traversal vulnerability in the Opal Woo Custom Product Variation WordPress plugin allows attackers to delete arbitrary files on the server. ...

May 23, 2025
CVE-2025-47492
8.6

This path traversal vulnerability in the Drag and Drop File Upload for Elementor Forms WordPress plugin allows attackers to delete arbitrary files on ...

May 23, 2025
CVE-2025-32633
8.6

This path traversal vulnerability in the neoslab Database Toolset WordPress plugin allows attackers to delete arbitrary files on the server. It affect...

Apr 11, 2025
CVE-2025-32631
8.6

This path traversal vulnerability in Oxygen MyData for WooCommerce allows attackers to delete arbitrary files on the server by manipulating file paths...

Apr 11, 2025
CVE-2024-41792
8.6

The SENTRON 7KT PAC1260 Data Manager contains a path traversal vulnerability in its web interface that allows unauthenticated attackers to read arbitr...

Apr 8, 2025
CVE-2025-31131
EPSS 10.8% 8.6

YesWiki versions before 4.5.2 contain a path traversal vulnerability in the squelette parameter that allows attackers to read arbitrary files on the s...

Apr 1, 2025
CVE-2024-54291
8.6

This path traversal vulnerability in the PluginPass WordPress plugin allows attackers to manipulate web input to access or delete arbitrary files on t...

Mar 28, 2025
CVE-2025-26534
8.6

This path traversal vulnerability in the Helloprint WordPress plugin allows attackers to delete arbitrary files on the server. It affects all WordPres...

Mar 3, 2025
CVE-2025-26752
8.6

This path traversal vulnerability in VideoWhisper Live Streaming Integration allows attackers to delete arbitrary files on affected WordPress sites. A...

Feb 25, 2025
CVE-2025-22663
8.6

This path traversal vulnerability in the Paid Videochat Turnkey Site WordPress plugin allows attackers to delete arbitrary files on affected systems. ...

Feb 18, 2025
CVE-2025-25243
8.6

CVE-2025-25243 is an unauthenticated arbitrary file download vulnerability in SAP Supplier Relationship Management's Master Data Management Catalog. A...

Feb 11, 2025
CVE-2024-52371
8.6

This path traversal vulnerability in the Global Gateway e4 | Payeezy Gateway WordPress plugin allows attackers to delete arbitrary files on the server...

Nov 14, 2024
CVE-2024-51998
8.6

This vulnerability in changedetection.io allows attackers to read arbitrary files on the system when webdriver is enabled and ALLOW_FILE_URI is false ...

Nov 8, 2024
CVE-2024-50509
8.6

This path traversal vulnerability in the Woocommerce Product Design WordPress plugin allows attackers to delete arbitrary files on the server. It affe...

Oct 30, 2024
CVE-2024-49315
8.6

This path traversal vulnerability in CodeFlock's FREE DOWNLOAD MANAGER WordPress plugin allows attackers to delete arbitrary files on the server. It a...

Oct 17, 2024
CVE-2024-43248
8.6

CVE-2024-43248 is an unauthenticated path traversal vulnerability in Bit Form Pro WordPress plugin that allows attackers to delete arbitrary files on ...

Aug 19, 2024
CVE-2024-39651
8.6

This vulnerability allows unauthenticated attackers to delete arbitrary files on WordPress sites running the vulnerable WooCommerce PDF Vouchers plugi...

Aug 13, 2024
CVE-2024-39903
8.6

This Local File Inclusion vulnerability in Solara allows attackers to read arbitrary files on the server by manipulating URI fragments with directory ...

Jul 12, 2024
CVE-2024-37932
8.6

This vulnerability allows unauthenticated attackers to perform path traversal attacks on WooCommerce OpenPos, enabling arbitrary file deletion on affe...

Jul 12, 2024
CVE-2024-39937
8.6

This vulnerability in supOS 5.0 allows attackers to perform directory traversal via the api/image/download endpoint, enabling unauthorized reading of ...

Jul 4, 2024
CVE-2024-6085
8.6

An unauthenticated path traversal vulnerability in lollms v9.6's XTTS server allows attackers to read arbitrary files and write audio files anywhere o...

Jun 27, 2024
CVE-2024-36117
8.6

CVE-2024-36117 is an arbitrary file read vulnerability in Reposilite v3.5.10 that allows attackers to read sensitive files on the server via path trav...

Jun 19, 2024
CVE-2024-35743
8.6

This path traversal vulnerability in the Siteclean SC filechecker WordPress plugin allows attackers to manipulate files outside intended directories. ...

Jun 10, 2024
CVE-2024-35658
8.6

This is an unauthenticated path traversal vulnerability in ThemeHigh's Checkout Field Editor for WooCommerce Pro plugin that allows attackers to delet...

Jun 10, 2024
CVE-2024-28995
8.6

SolarWinds Serv-U contains a directory traversal vulnerability that allows attackers to read sensitive files on the host system. This affects organiza...

Jun 6, 2024
CVE-2024-32830
8.6

This path traversal vulnerability in the BuddyForms WordPress plugin allows attackers to read arbitrary files and perform server-side request forgery ...

May 17, 2024
CVE-2023-47178
8.6

This vulnerability allows unauthenticated attackers to perform path traversal attacks, enabling local file inclusion in WordPress sites using The Plus...

May 17, 2024
CVE-2023-39163
8.6

This vulnerability allows unauthenticated attackers to perform path traversal attacks in the Phlox Shop WordPress plugin, leading to local file inclus...

May 17, 2024
CVE-2024-31850
8.6

An unauthenticated path traversal vulnerability in CData Arc Java versions before 23.4.8839 allows remote attackers to access sensitive files and perf...

Apr 5, 2024
CVE-2023-42947
8.6

This CVE describes a path handling vulnerability in Apple operating systems that allows malicious applications to escape their sandbox restrictions. I...

Mar 28, 2024
CVE-2023-43662
8.6

CVE-2023-43662 is an unauthenticated arbitrary file read vulnerability in ShokoServer's /api/Image/WithPath endpoint. Attackers can read any file on t...

Sep 28, 2023
CVE-2022-30321
8.6

This vulnerability in the go-getter library allows attackers to perform path traversal, symlink processing, and command injection attacks, potentially...

May 25, 2022

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,002 CVEs classified as CWE-22, with 452 rated critical and 1,009 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free