CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (2,002)
This path traversal vulnerability in Synology WebDAV Server allows authenticated remote attackers to delete arbitrary files on the system. The vulnera...
Jul 28, 2022This vulnerability allows authenticated administrators with specific permissions to inject executable files via layout XML in OpenMage, a community-dr...
Jan 21, 2021This vulnerability allows authenticated administrators with product update permissions to upload executable files and execute them via layout XML in O...
Jan 20, 2021CVE-2026-28679 is a path traversal vulnerability in Home-Gallery.org that allows attackers to download sensitive system files outside the intended med...
Mar 6, 2026This vulnerability in NLTK allows attackers to read arbitrary files on the server through path traversal attacks in multiple CorpusReader classes. It ...
Mar 4, 2026ImageMagick's path security policy enforcement occurs before filesystem path resolution, allowing path traversal attacks to bypass policy rules like '...
Feb 24, 2026This path traversal vulnerability in the WordPress 'Upload Files Anywhere' plugin allows attackers to delete arbitrary files on the server. It affects...
Feb 20, 2026Calibre e-book manager versions before 9.2.0 contain a path traversal vulnerability in the CHM reader that allows attackers to write arbitrary files a...
Feb 6, 2026Python-Multipart versions before 0.0.22 contain a path traversal vulnerability when configured with UPLOAD_DIR and UPLOAD_KEEP_FILENAME=True. Attacker...
Jan 27, 2026This CVE describes a path traversal vulnerability in the Harmonic Design HDForms WordPress plugin, allowing attackers to delete arbitrary files on the...
Jan 22, 2026This path traversal vulnerability in the Anona WordPress theme allows attackers to delete arbitrary files on affected systems. It affects all WordPres...
Jan 22, 2026This path traversal vulnerability in the ovatheme Movie Booking WordPress plugin allows attackers to delete arbitrary files on the server. It affects ...
Jan 22, 2026CVE-2026-23949 is a Zip Slip path traversal vulnerability in jaraco.context's tarball() function that allows attackers to extract files outside the in...
Jan 20, 2026This vulnerability in Nero BackItUp allows arbitrary code execution when a user clicks on a crafted entry in the software's interface. Attackers can e...
Nov 14, 2025CVE-2025-27222 is a path traversal vulnerability in TRUfusion Enterprise's /trufusionPortal/getCobrandingData endpoint that allows attackers to read a...
Oct 27, 2025This path traversal vulnerability in Saysis Web Portal allows attackers to access files outside the intended directory by manipulating file paths. It ...
Sep 25, 2025This path traversal vulnerability in the BuddyPress XProfile Custom Image Field WordPress plugin allows attackers to delete arbitrary files on the ser...
Aug 20, 2025This path traversal vulnerability in FW Gallery WordPress plugin allows attackers to delete arbitrary files on the server by manipulating file paths. ...
Jun 17, 2025This path traversal vulnerability in the Opal Woo Custom Product Variation WordPress plugin allows attackers to delete arbitrary files on the server. ...
May 23, 2025This path traversal vulnerability in the Drag and Drop File Upload for Elementor Forms WordPress plugin allows attackers to delete arbitrary files on ...
May 23, 2025This path traversal vulnerability in the neoslab Database Toolset WordPress plugin allows attackers to delete arbitrary files on the server. It affect...
Apr 11, 2025This path traversal vulnerability in Oxygen MyData for WooCommerce allows attackers to delete arbitrary files on the server by manipulating file paths...
Apr 11, 2025The SENTRON 7KT PAC1260 Data Manager contains a path traversal vulnerability in its web interface that allows unauthenticated attackers to read arbitr...
Apr 8, 2025YesWiki versions before 4.5.2 contain a path traversal vulnerability in the squelette parameter that allows attackers to read arbitrary files on the s...
Apr 1, 2025This path traversal vulnerability in the PluginPass WordPress plugin allows attackers to manipulate web input to access or delete arbitrary files on t...
Mar 28, 2025This path traversal vulnerability in the Helloprint WordPress plugin allows attackers to delete arbitrary files on the server. It affects all WordPres...
Mar 3, 2025This path traversal vulnerability in VideoWhisper Live Streaming Integration allows attackers to delete arbitrary files on affected WordPress sites. A...
Feb 25, 2025This path traversal vulnerability in the Paid Videochat Turnkey Site WordPress plugin allows attackers to delete arbitrary files on affected systems. ...
Feb 18, 2025CVE-2025-25243 is an unauthenticated arbitrary file download vulnerability in SAP Supplier Relationship Management's Master Data Management Catalog. A...
Feb 11, 2025This path traversal vulnerability in the Global Gateway e4 | Payeezy Gateway WordPress plugin allows attackers to delete arbitrary files on the server...
Nov 14, 2024This vulnerability in changedetection.io allows attackers to read arbitrary files on the system when webdriver is enabled and ALLOW_FILE_URI is false ...
Nov 8, 2024This path traversal vulnerability in the Woocommerce Product Design WordPress plugin allows attackers to delete arbitrary files on the server. It affe...
Oct 30, 2024This path traversal vulnerability in CodeFlock's FREE DOWNLOAD MANAGER WordPress plugin allows attackers to delete arbitrary files on the server. It a...
Oct 17, 2024CVE-2024-43248 is an unauthenticated path traversal vulnerability in Bit Form Pro WordPress plugin that allows attackers to delete arbitrary files on ...
Aug 19, 2024This vulnerability allows unauthenticated attackers to delete arbitrary files on WordPress sites running the vulnerable WooCommerce PDF Vouchers plugi...
Aug 13, 2024This Local File Inclusion vulnerability in Solara allows attackers to read arbitrary files on the server by manipulating URI fragments with directory ...
Jul 12, 2024This vulnerability allows unauthenticated attackers to perform path traversal attacks on WooCommerce OpenPos, enabling arbitrary file deletion on affe...
Jul 12, 2024This vulnerability in supOS 5.0 allows attackers to perform directory traversal via the api/image/download endpoint, enabling unauthorized reading of ...
Jul 4, 2024An unauthenticated path traversal vulnerability in lollms v9.6's XTTS server allows attackers to read arbitrary files and write audio files anywhere o...
Jun 27, 2024CVE-2024-36117 is an arbitrary file read vulnerability in Reposilite v3.5.10 that allows attackers to read sensitive files on the server via path trav...
Jun 19, 2024This path traversal vulnerability in the Siteclean SC filechecker WordPress plugin allows attackers to manipulate files outside intended directories. ...
Jun 10, 2024This is an unauthenticated path traversal vulnerability in ThemeHigh's Checkout Field Editor for WooCommerce Pro plugin that allows attackers to delet...
Jun 10, 2024SolarWinds Serv-U contains a directory traversal vulnerability that allows attackers to read sensitive files on the host system. This affects organiza...
Jun 6, 2024This path traversal vulnerability in the BuddyForms WordPress plugin allows attackers to read arbitrary files and perform server-side request forgery ...
May 17, 2024This vulnerability allows unauthenticated attackers to perform path traversal attacks, enabling local file inclusion in WordPress sites using The Plus...
May 17, 2024This vulnerability allows unauthenticated attackers to perform path traversal attacks in the Phlox Shop WordPress plugin, leading to local file inclus...
May 17, 2024An unauthenticated path traversal vulnerability in CData Arc Java versions before 23.4.8839 allows remote attackers to access sensitive files and perf...
Apr 5, 2024This CVE describes a path handling vulnerability in Apple operating systems that allows malicious applications to escape their sandbox restrictions. I...
Mar 28, 2024CVE-2023-43662 is an unauthenticated arbitrary file read vulnerability in ShokoServer's /api/Image/WithPath endpoint. Attackers can read any file on t...
Sep 28, 2023This vulnerability in the go-getter library allows attackers to perform path traversal, symlink processing, and command injection attacks, potentially...
May 25, 2022About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 2,002 CVEs classified as CWE-22, with 452 rated critical and 1,009 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free