CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (2,007)
CVE-2023-43662 is an unauthenticated arbitrary file read vulnerability in ShokoServer's /api/Image/WithPath endpoint. Attackers can read any file on t...
Sep 28, 2023This vulnerability in the go-getter library allows attackers to perform path traversal, symlink processing, and command injection attacks, potentially...
May 25, 2022CVE-2021-43775 is a path traversal vulnerability in Aim, an open-source machine learning experiment tracking tool. Attackers can use directory travers...
Nov 23, 2021This vulnerability in elFinder.NetCore allows attackers to extract arbitrary files from the server due to insufficient path validation in the ExtractA...
Sep 1, 2021This vulnerability allows attackers to perform directory traversal attacks via the items[] parameter in move operations in the Media File Organizer Wo...
Jul 7, 2021A low-privilege user with page editing access in Grav can read arbitrary server files, including sensitive user account files containing password hash...
Dec 1, 2025This path traversal vulnerability in Salesforce Tableau Server allows attackers to access files outside the intended directory via the tabdoc API's du...
Jul 25, 2025This path traversal vulnerability in the WordPress Newspack Blocks plugin allows attackers to delete arbitrary directories on the server. It affects W...
Nov 1, 2024This vulnerability allows attackers to read arbitrary files on WordPress servers through path traversal in the Timeline and History slider plugin. It ...
Aug 19, 2024This path traversal vulnerability in the ListingPro WordPress theme allows attackers to include arbitrary local PHP files, potentially leading to remo...
Aug 1, 2024This path traversal vulnerability in the Advanced Classifieds & Directory Pro WordPress plugin allows attackers to access files outside the intended d...
Jul 9, 2024This path traversal vulnerability in the Striking WordPress theme allows attackers to access files outside the intended directory. It affects all Word...
Jul 9, 2024This vulnerability allows attackers to perform path traversal attacks in the Consulting Elementor Widgets WordPress plugin, leading to local file incl...
Jun 24, 2024This vulnerability in SuiteCRM allows authenticated users to execute arbitrary code remotely through connectors. It affects all SuiteCRM installations...
Jun 10, 2024This vulnerability allows attackers to perform path traversal attacks in the Stockholm Core WordPress plugin, enabling PHP local file inclusion. Attac...
Jun 4, 2024This vulnerability in Element Pack Pro WordPress plugin allows attackers to read arbitrary files on the server and execute malicious code through dese...
Jun 4, 2024This CVE describes a path traversal vulnerability in the XStore Core WordPress plugin that allows attackers to include arbitrary local PHP files. This...
Jun 4, 2024This vulnerability allows attackers to perform path traversal attacks in the Easy Social Share Buttons WordPress plugin, leading to local file inclusi...
May 17, 2024This path traversal vulnerability in the Brevo Sendinblue for WooCommerce WordPress plugin allows attackers to read or delete arbitrary files on the s...
May 6, 2024This CVE describes a path traversal vulnerability in GitLab that allows attackers to access restricted files and potentially cause denial of service. ...
Apr 25, 2024This CVE describes a path traversal vulnerability in ASUSTOR ADM printer service that allows remote unauthenticated attackers to delete files outside ...
Aug 17, 2023This vulnerability allows authenticated users with configuration access in Icinga Web 2 to create SSH resource files in unintended directories, leadin...
Mar 8, 2022This path traversal vulnerability in GitLab Workhorse allows attackers to access JWT tokens by manipulating file paths. All GitLab versions are affect...
Apr 12, 2021A path traversal vulnerability (CWE-22) in Huawei's virtualization base module allows attackers to access files outside the intended directory. This a...
Aug 6, 2025This vulnerability allows authenticated local attackers on Cisco SD-WAN devices to create or overwrite arbitrary files through insufficient input vali...
Nov 18, 2024CVE-2024-52291 is a path traversal vulnerability in CraftCMS that allows authenticated administrators to bypass local file system validation using a d...
Nov 13, 2024This vulnerability in tgstation-server allows low-permission users with 'Set .dme Path' privilege to potentially execute malicious .dme files, which c...
Jul 29, 2024This vulnerability in SolarWinds Serv-U allows attackers with highly privileged accounts to perform directory traversal attacks, potentially leading t...
Apr 17, 2024This CVE describes a directory traversal vulnerability in Apache Pulsar Functions Worker where authenticated users can upload malicious JAR/NAR files ...
Mar 12, 2024This path traversal vulnerability in ConnectWise ScreenConnect allows attackers to bypass authentication and potentially execute remote code or access...
Feb 21, 2024This path traversal vulnerability in TACC ePO extension allows authenticated administrators to upload malicious GTI reputation files that can execute ...
Nov 27, 2023This vulnerability allows authenticated remote attackers to perform absolute path traversal in Quagga services on D-Link DIR-2640 routers, enabling th...
Dec 30, 2021A vulnerability in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation allows path traversal attacks. This affects Kubernetes cl...
Dec 17, 2025An unauthenticated directory traversal vulnerability in Fanvil x210 V2 IP phones allows attackers on the local network to write files to arbitrary loc...
Dec 5, 2025This vulnerability in Progress Telerik Document Processing Libraries allows attackers to perform path traversal attacks when processing ZIP archives, ...
Feb 12, 2025This vulnerability allows unauthenticated remote attackers to execute arbitrary code on affected Xerox FreeFlow Core systems via path traversal. Attac...
Oct 7, 2024This vulnerability allows attackers to read arbitrary files on WordPress servers running the EmbedPress plugin through path traversal. Attackers can e...
Aug 19, 2024OpenAPI Generator versions before 7.6.0 contain a path traversal vulnerability that allows attackers to read and delete files from arbitrary writable ...
May 27, 2024This path traversal vulnerability in Premmerce Permalink Manager for WooCommerce allows attackers to include arbitrary PHP files from the server's fil...
May 17, 2024This path traversal vulnerability in Fortinet FortiWAN allows authenticated attackers to read and delete arbitrary files on the system via crafted HTT...
Dec 13, 2023A directory traversal vulnerability in EverShop NPM allows remote attackers to access sensitive files outside the intended directory via crafted DELET...
Dec 8, 2023A directory traversal vulnerability in MCL-Net versions before 4.6 Update Package (P01) allows attackers to read arbitrary files on the system. This a...
Oct 11, 2023CVE-2022-23609 is a path traversal vulnerability in iTunesRPC-Remastered that allows attackers to delete arbitrary files on Windows systems. The vulne...
Feb 4, 2022The wp-publications WordPress plugin contains a local file inclusion vulnerability in the Q_FILE parameter of bibtexbrowser.php. This allows attackers...
Sep 10, 2021A path traversal vulnerability in Zarf's archive extraction allows malicious packages to create symlinks pointing outside the destination directory, e...
Mar 6, 2026A path traversal vulnerability in Calibre's EPUB conversion allows malicious EPUB files to corrupt arbitrary files writable by the Calibre process. At...
Feb 6, 2026CVE-2026-24843 is a path traversal vulnerability in melange that allows attackers to write files outside the intended workspace directory. Attackers w...
Feb 4, 2026An input neutralization vulnerability in Crafty Controller's Backup Configuration component allows authenticated attackers to perform path traversal a...
Jan 30, 2026CVE-2026-24842 is a path traversal vulnerability in node-tar, a Node.js library for handling TAR archives, affecting versions prior to 7.5.7. It allow...
Jan 28, 2026This path traversal vulnerability in Azure Logic Apps allows unauthorized attackers to access restricted directories and elevate privileges over the n...
Jan 22, 2026About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 2,007 CVEs classified as CWE-22, with 454 rated critical and 1,012 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free