CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,014
Total CVEs
455
Critical
1,018
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
233
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 21
3 Ivanti 18
4 Solarwinds 17
5 Fortinet 16
6 Samsung 16
7 Fedoraproject 16
8 Siemens 15
9 Adobe 15
10 Debian 13

All Path Traversal CVEs (2,014)

CVE-2026-24842
8.2

CVE-2026-24842 is a path traversal vulnerability in node-tar, a Node.js library for handling TAR archives, affecting versions prior to 7.5.7. It allow...

Jan 28, 2026
CVE-2026-21227
8.2

This path traversal vulnerability in Azure Logic Apps allows unauthorized attackers to access restricted directories and elevate privileges over the n...

Jan 22, 2026
CVE-2025-65025
8.2

CVE-2025-65025 is a path traversal vulnerability in esm.sh CDN service that allows attackers to write files to arbitrary server locations during NPM p...

Nov 19, 2025
CVE-2025-43813
8.2

This vulnerability in Liferay Portal/DXP allows remote attackers to perform path traversal attacks via the ComboServlet, potentially accessing arbitra...

Sep 29, 2025
CVE-2025-7359
8.2

The Counter live visitors for WooCommerce WordPress plugin has an arbitrary file deletion vulnerability that allows unauthenticated attackers to delet...

Jul 16, 2025
CVE-2025-44177
8.2

An unauthenticated directory traversal vulnerability in White Star Software Protop version 4.4.2-2024-11-27 allows remote attackers to read arbitrary ...

Jul 9, 2025
CVE-2025-41229
8.2

VMware Cloud Foundation contains a directory traversal vulnerability (CWE-22) that allows attackers with network access to port 443 to access internal...

May 20, 2025
CVE-2025-27147
8.2

CVE-2025-27147 is an improper access control vulnerability in the GLPI Inventory Plugin that allows unauthorized users to perform administrative actio...

Mar 25, 2025
CVE-2024-10830
8.2

This path traversal vulnerability in db-gpt version 0.6.0 allows attackers to delete arbitrary files on the server by manipulating the file_key parame...

Mar 20, 2025
CVE-2024-11481
8.2

This vulnerability in ESM 11.6.10 allows unauthenticated attackers to access internal Snowservice API endpoints via path traversal. This can lead to u...

Nov 29, 2024
CVE-2024-43395
8.2

CVE-2024-43395 is a path traversal vulnerability in CraftOS-PC 2 that allows attackers to escape the designated computer folder and access arbitrary f...

Aug 16, 2024
CVE-2024-6255
8.2

This vulnerability allows any user to delete any JSON file on the server through directory traversal attacks due to improper path validation. It affec...

Jul 31, 2024
CVE-2024-40348
8.2

This vulnerability in Bazaar v1.4.3 allows unauthenticated attackers to perform directory traversal attacks via the /api/swaggerui/static component. A...

Jul 20, 2024
CVE-2024-32982
8.2

This CVE describes a Local File Inclusion (LFI) vulnerability in Litestar/Starlite ASGI frameworks that allows attackers to exploit path traversal fla...

May 6, 2024
CVE-2023-27326
8.2

This vulnerability allows local attackers with high-privileged code execution on a Parallels Desktop guest system to escalate privileges on the host s...

May 3, 2024
CVE-2023-2110
8.2

This vulnerability in Obsidian desktop allows malicious webpages or markdown files to access local files through improper path handling. Attackers can...

Aug 19, 2023
CVE-2021-27771
8.2

CVE-2021-27771 is a path traversal vulnerability in HCL Sametime chat application where attackers can modify user session IDs to upload arbitrary file...

May 12, 2022
CVE-2021-41150
8.2

CVE-2021-41150 is a path traversal vulnerability in the Tough TUF library that allows attackers to overwrite arbitrary JSON files on the system when r...

Oct 19, 2021
CVE-2021-41149
8.2

CVE-2021-41149 is a path traversal vulnerability in the Tough TUF library that allows attackers to overwrite arbitrary files on the system when cachin...

Oct 19, 2021
CVE-2021-37712
8.2

This vulnerability in the npm tar package allows attackers to bypass symlink checks by exploiting Unicode normalization and Windows short path behavio...

Aug 31, 2021
CVE-2021-32804
8.2

The npm tar package before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has an arbitrary file creation/overwrite vulnerability due to insufficient sanitiz...

Aug 3, 2021
CVE-2026-28447
8.1

OpenClaw versions 2026.1.29-beta.1 through 2026.2.1 contain a path traversal vulnerability in plugin installation. Attackers can craft malicious plugi...

Mar 5, 2026
CVE-2026-3179
8.1

This path traversal vulnerability in ASUSTOR ADM FTP Backup allows attackers to access files outside the intended directory by manipulating file paths...

Feb 25, 2026
CVE-2026-2033
8.1

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on MLflow Tracking Server installations via directory traversal i...

Feb 20, 2026
CVE-2026-24135
8.1

CVE-2026-24135 is a path traversal vulnerability in Gogs self-hosted Git service that allows authenticated users with wiki write access to delete arbi...

Feb 6, 2026
CVE-2026-25055
8.1

This vulnerability in n8n workflow automation platform allows attackers to write files to unintended locations on remote systems via SSH nodes, potent...

Feb 4, 2026
CVE-2026-24741
8.1

ConvertX versions before 0.17.0 have a path traversal vulnerability in the /delete endpoint that allows attackers to delete arbitrary files on the ser...

Jan 27, 2026
CVE-2025-69097
8.1

This path traversal vulnerability in VibeThemes WPLMS plugin allows attackers to delete arbitrary files on WordPress sites. It affects all WordPress i...

Jan 22, 2026
CVE-2025-66292
8.1

CVE-2025-66292 is an arbitrary file deletion vulnerability in DPanel server management panel. Authenticated users can delete any file on the server vi...

Jan 15, 2026
CVE-2025-68472
8.1

CVE-2025-68472 is an unauthenticated path traversal vulnerability in MindsDB's file upload API that allows attackers to read arbitrary files from the ...

Jan 12, 2026
CVE-2025-14850
8.1

Advantech WebAccess/SCADA is vulnerable to directory traversal that allows attackers to delete arbitrary files on the system. This affects industrial ...

Dec 18, 2025
CVE-2025-40898
8.1

This path traversal vulnerability allows authenticated users with limited privileges to upload malicious Arc data archives that can write arbitrary fi...

Dec 18, 2025
CVE-2025-65879
8.1

Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. Remote authenticated attackers can delete arbitrary f...

Dec 5, 2025
CVE-2025-60915
8.1

This vulnerability allows attackers to perform path traversal attacks via the size query parameter in Openatlas's /views/file.py endpoint. Attackers c...

Nov 24, 2025
CVE-2025-10488
8.1

This vulnerability in the Directorist WordPress plugin allows unauthenticated attackers to move arbitrary files on the server due to insufficient file...

Oct 25, 2025
CVE-2025-62156
8.1

Argo Workflows contains a Zip Slip path traversal vulnerability in artifact extraction that allows attackers to write arbitrary files outside the inte...

Oct 14, 2025
CVE-2025-40889
8.1

An authenticated path traversal vulnerability in Time Machine functionality allows limited-privilege users to manipulate files in the /data folder thr...

Oct 7, 2025
CVE-2025-9566
8.1

A path traversal vulnerability in Podman's kube play command allows attackers to overwrite arbitrary host files when Kubernetes YAML files contain sym...

Sep 5, 2025
CVE-2025-5391
8.1

The WooCommerce Purchase Orders plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access or higher to del...

Aug 12, 2025
CVE-2025-6989
8.1

The Kallyas WordPress theme contains a vulnerability that allows authenticated attackers with Contributor-level access or higher to delete arbitrary f...

Jul 26, 2025
CVE-2025-7640
8.1

This CSRF vulnerability in the hiWeb Export Posts WordPress plugin allows unauthenticated attackers to delete arbitrary server files by tricking admin...

Jul 24, 2025
CVE-2025-7645
8.1

The Extensions For CF7 WordPress plugin has an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any file on the s...

Jul 22, 2025
CVE-2025-4946
8.1

The Vikinger WordPress theme allows authenticated attackers with Subscriber-level access or higher to delete arbitrary files on the server due to insu...

Jul 2, 2025
CVE-2025-6445
8.1

ServiceStack's FindType method contains a directory traversal vulnerability that allows remote attackers to execute arbitrary code by manipulating fil...

Jun 25, 2025
CVE-2025-39473
8.1

This path traversal vulnerability in Seofy Core WordPress plugin allows attackers to include arbitrary local PHP files via improper path validation. A...

Jun 9, 2025
CVE-2025-26692
8.1

CVE-2025-26692 is a path traversal vulnerability in Quick Agent V3 and V2 that allows remote unauthenticated attackers to execute arbitrary code with ...

Apr 28, 2025
CVE-2025-3520
8.1

The Avatar WordPress plugin has an arbitrary file deletion vulnerability that allows authenticated attackers with Subscriber-level access or higher to...

Apr 18, 2025
CVE-2025-3445
8.1

A path traversal vulnerability in mholt/archiver Go library allows attackers to create or overwrite arbitrary files by exploiting symlinks in crafted ...

Apr 13, 2025
CVE-2025-32587
8.1

This CVE describes a path traversal vulnerability in the WooCommerce Pickupp plugin that allows attackers to include arbitrary PHP files from the serv...

Apr 11, 2025
CVE-2025-30582
8.1

This path traversal vulnerability in DyaPress ERP/CRM allows attackers to include arbitrary PHP files from the server's filesystem, potentially leadin...

Apr 10, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,014 CVEs classified as CWE-22, with 455 rated critical and 1,018 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free