CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,007
Total CVEs
454
Critical
1,012
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
233
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 21
3 Ivanti 18
4 Fortinet 16
5 Samsung 16
6 Solarwinds 16
7 Fedoraproject 16
8 Siemens 15
9 Adobe 15
10 Debian 13

All Path Traversal CVEs (2,007)

CVE-2023-43662
8.6

CVE-2023-43662 is an unauthenticated arbitrary file read vulnerability in ShokoServer's /api/Image/WithPath endpoint. Attackers can read any file on t...

Sep 28, 2023
CVE-2022-30321
8.6

This vulnerability in the go-getter library allows attackers to perform path traversal, symlink processing, and command injection attacks, potentially...

May 25, 2022
CVE-2021-43775
8.6

CVE-2021-43775 is a path traversal vulnerability in Aim, an open-source machine learning experiment tracking tool. Attackers can use directory travers...

Nov 23, 2021
CVE-2021-23427
8.6

This vulnerability in elFinder.NetCore allows attackers to extract arbitrary files from the server due to insufficient path validation in the ExtractA...

Sep 1, 2021
CVE-2020-24144
8.6

This vulnerability allows attackers to perform directory traversal attacks via the items[] parameter in move operations in the Media File Organizer Wo...

Jul 7, 2021
CVE-2025-66300
8.5

A low-privilege user with page editing access in Grav can read arbitrary server files, including sensitive user account files containing password hash...

Dec 1, 2025
CVE-2025-52452
8.5

This path traversal vulnerability in Salesforce Tableau Server allows attackers to access files outside the intended directory via the tabdoc API's du...

Jul 25, 2025
CVE-2024-37423
8.5

This path traversal vulnerability in the WordPress Newspack Blocks plugin allows attackers to delete arbitrary directories on the server. It affects W...

Nov 1, 2024
CVE-2024-43232
8.5

This vulnerability allows attackers to read arbitrary files on WordPress servers through path traversal in the Timeline and History slider plugin. It ...

Aug 19, 2024
CVE-2024-39624
8.5

This path traversal vulnerability in the ListingPro WordPress theme allows attackers to include arbitrary local PHP files, potentially leading to remo...

Aug 1, 2024
CVE-2024-37501
8.5

This path traversal vulnerability in the Advanced Classifieds & Directory Pro WordPress plugin allows attackers to access files outside the intended d...

Jul 9, 2024
CVE-2024-37268
8.5

This path traversal vulnerability in the Striking WordPress theme allows attackers to access files outside the intended directory. It affects all Word...

Jul 9, 2024
CVE-2024-37092
8.5

This vulnerability allows attackers to perform path traversal attacks in the Consulting Elementor Widgets WordPress plugin, leading to local file incl...

Jun 24, 2024
CVE-2024-36418
8.5

This vulnerability in SuiteCRM allows authenticated users to execute arbitrary code remotely through connectors. It affects all SuiteCRM installations...

Jun 10, 2024
CVE-2024-34554
8.5

This vulnerability allows attackers to perform path traversal attacks in the Stockholm Core WordPress plugin, enabling PHP local file inclusion. Attac...

Jun 4, 2024
CVE-2024-33568
8.5

This vulnerability in Element Pack Pro WordPress plugin allows attackers to read arbitrary files on the server and execute malicious code through dese...

Jun 4, 2024
CVE-2024-33557
8.5

This CVE describes a path traversal vulnerability in the XStore Core WordPress plugin that allows attackers to include arbitrary local PHP files. This...

Jun 4, 2024
CVE-2024-31300
8.5

This vulnerability allows attackers to perform path traversal attacks in the Easy Social Share Buttons WordPress plugin, leading to local file inclusi...

May 17, 2024
CVE-2024-32807
8.5

This path traversal vulnerability in the Brevo Sendinblue for WooCommerce WordPress plugin allows attackers to read or delete arbitrary files on the s...

May 6, 2024
CVE-2024-2434
8.5

This CVE describes a path traversal vulnerability in GitLab that allows attackers to access restricted files and potentially cause denial of service. ...

Apr 25, 2024
CVE-2023-3698
8.5

This CVE describes a path traversal vulnerability in ASUSTOR ADM printer service that allows remote unauthenticated attackers to delete files outside ...

Aug 17, 2023
CVE-2022-24715
8.5

This vulnerability allows authenticated users with configuration access in Icinga Web 2 to create SSH resource files in unintended directories, leadin...

Mar 8, 2022
CVE-2021-22190
8.5

This path traversal vulnerability in GitLab Workhorse allows attackers to access JWT tokens by manipulating file paths. All GitLab versions are affect...

Apr 12, 2021
CVE-2025-54652
8.4

A path traversal vulnerability (CWE-22) in Huawei's virtualization base module allows attackers to access files outside the intended directory. This a...

Aug 6, 2025
CVE-2020-26071
8.4

This vulnerability allows authenticated local attackers on Cisco SD-WAN devices to create or overwrite arbitrary files through insufficient input vali...

Nov 18, 2024
CVE-2024-52291
8.4

CVE-2024-52291 is a path traversal vulnerability in CraftCMS that allows authenticated administrators to bypass local file system validation using a d...

Nov 13, 2024
CVE-2024-41799
8.4

This vulnerability in tgstation-server allows low-permission users with 'Set .dme Path' privilege to potentially execute malicious .dme files, which c...

Jul 29, 2024
CVE-2024-28073
8.4

This vulnerability in SolarWinds Serv-U allows attackers with highly privileged accounts to perform directory traversal attacks, potentially leading t...

Apr 17, 2024
CVE-2024-27317
8.4

This CVE describes a directory traversal vulnerability in Apache Pulsar Functions Worker where authenticated users can upload malicious JAR/NAR files ...

Mar 12, 2024
CVE-2024-1708
8.4

This path traversal vulnerability in ConnectWise ScreenConnect allows attackers to bypass authentication and potentially execute remote code or access...

Feb 21, 2024
CVE-2023-5607
8.4

This path traversal vulnerability in TACC ePO extension allows authenticated administrators to upload malicious GTI reputation files that can execute ...

Nov 27, 2023
CVE-2021-20134
8.4

This vulnerability allows authenticated remote attackers to perform absolute path traversal in Quagga services on D-Link DIR-2640 routers, enabling th...

Dec 30, 2021
CVE-2025-14727
8.3

A vulnerability in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation allows path traversal attacks. This affects Kubernetes cl...

Dec 17, 2025
CVE-2025-64057
8.3

An unauthenticated directory traversal vulnerability in Fanvil x210 V2 IP phones allows attackers on the local network to write files to arbitrary loc...

Dec 5, 2025
CVE-2024-11343
8.3

This vulnerability in Progress Telerik Document Processing Libraries allows attackers to perform path traversal attacks when processing ZIP archives, ...

Feb 12, 2025
CVE-2024-47556
8.3

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on affected Xerox FreeFlow Core systems via path traversal. Attac...

Oct 7, 2024
CVE-2024-43328
8.3

This vulnerability allows attackers to read arbitrary files on WordPress servers running the EmbedPress plugin through path traversal. Attackers can e...

Aug 19, 2024
CVE-2024-35219
8.3

OpenAPI Generator versions before 7.6.0 contain a path traversal vulnerability that allows attackers to read and delete files from arbitrary writable ...

May 27, 2024
CVE-2024-27971
8.3

This path traversal vulnerability in Premmerce Permalink Manager for WooCommerce allows attackers to include arbitrary PHP files from the server's fil...

May 17, 2024
CVE-2023-44251
8.3

This path traversal vulnerability in Fortinet FortiWAN allows authenticated attackers to read and delete arbitrary files on the system via crafted HTT...

Dec 13, 2023
CVE-2023-46496
8.3

A directory traversal vulnerability in EverShop NPM allows remote attackers to access sensitive files outside the intended directory via crafted DELET...

Dec 8, 2023
CVE-2023-4990
8.3

A directory traversal vulnerability in MCL-Net versions before 4.6 Update Package (P01) allows attackers to read arbitrary files on the system. This a...

Oct 11, 2023
CVE-2022-23609
8.3

CVE-2022-23609 is a path traversal vulnerability in iTunesRPC-Remastered that allows attackers to delete arbitrary files on Windows systems. The vulne...

Feb 4, 2022
CVE-2021-38360
8.3

The wp-publications WordPress plugin contains a local file inclusion vulnerability in the Q_FILE parameter of bibtexbrowser.php. This allows attackers...

Sep 10, 2021
CVE-2026-29064
8.2

A path traversal vulnerability in Zarf's archive extraction allows malicious packages to create symlinks pointing outside the destination directory, e...

Mar 6, 2026
CVE-2026-25636
8.2

A path traversal vulnerability in Calibre's EPUB conversion allows malicious EPUB files to corrupt arbitrary files writable by the Calibre process. At...

Feb 6, 2026
CVE-2026-24843
8.2

CVE-2026-24843 is a path traversal vulnerability in melange that allows attackers to write files outside the intended workspace directory. Attackers w...

Feb 4, 2026
CVE-2026-0805
8.2

An input neutralization vulnerability in Crafty Controller's Backup Configuration component allows authenticated attackers to perform path traversal a...

Jan 30, 2026
CVE-2026-24842
8.2

CVE-2026-24842 is a path traversal vulnerability in node-tar, a Node.js library for handling TAR archives, affecting versions prior to 7.5.7. It allow...

Jan 28, 2026
CVE-2026-21227
8.2

This path traversal vulnerability in Azure Logic Apps allows unauthorized attackers to access restricted directories and elevate privileges over the n...

Jan 22, 2026

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,007 CVEs classified as CWE-22, with 454 rated critical and 1,012 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free