CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,128
Total CVEs
503
Critical
1,083
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
236
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Fedoraproject 17
5 Solarwinds 17
6 Fortinet 16
7 Samsung 16
8 Debian 16
9 Adobe 15
10 Siemens 15

All Path Traversal CVEs (2,128)

CVE-2025-60915
8.1

This vulnerability allows attackers to perform path traversal attacks via the size query parameter in Openatlas's /views/file.py endpoint. Attackers c...

Nov 24, 2025
CVE-2025-10488
8.1

This vulnerability in the Directorist WordPress plugin allows unauthenticated attackers to move arbitrary files on the server due to insufficient file...

Oct 25, 2025
CVE-2025-62156
8.1

Argo Workflows contains a Zip Slip path traversal vulnerability in artifact extraction that allows attackers to write arbitrary files outside the inte...

Oct 14, 2025
CVE-2025-40889
8.1

An authenticated path traversal vulnerability in Time Machine functionality allows limited-privilege users to manipulate files in the /data folder thr...

Oct 7, 2025
CVE-2025-9566
8.1

A path traversal vulnerability in Podman's kube play command allows attackers to overwrite arbitrary host files when Kubernetes YAML files contain sym...

Sep 5, 2025
CVE-2025-5391
8.1

The WooCommerce Purchase Orders plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access or higher to del...

Aug 12, 2025
CVE-2025-6989
8.1

The Kallyas WordPress theme contains a vulnerability that allows authenticated attackers with Contributor-level access or higher to delete arbitrary f...

Jul 26, 2025
CVE-2025-7640
8.1

This CSRF vulnerability in the hiWeb Export Posts WordPress plugin allows unauthenticated attackers to delete arbitrary server files by tricking admin...

Jul 24, 2025
CVE-2025-7645
8.1

The Extensions For CF7 WordPress plugin has an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any file on the s...

Jul 22, 2025
CVE-2025-4946
8.1

The Vikinger WordPress theme allows authenticated attackers with Subscriber-level access or higher to delete arbitrary files on the server due to insu...

Jul 2, 2025
CVE-2025-6445
8.1

ServiceStack's FindType method contains a directory traversal vulnerability that allows remote attackers to execute arbitrary code by manipulating fil...

Jun 25, 2025
CVE-2025-39473
8.1

This path traversal vulnerability in Seofy Core WordPress plugin allows attackers to include arbitrary local PHP files via improper path validation. A...

Jun 9, 2025
CVE-2025-26692
8.1

CVE-2025-26692 is a path traversal vulnerability in Quick Agent V3 and V2 that allows remote unauthenticated attackers to execute arbitrary code with ...

Apr 28, 2025
CVE-2025-3520
8.1

The Avatar WordPress plugin has an arbitrary file deletion vulnerability that allows authenticated attackers with Subscriber-level access or higher to...

Apr 18, 2025
CVE-2025-3445
8.1

A path traversal vulnerability in mholt/archiver Go library allows attackers to create or overwrite arbitrary files by exploiting symlinks in crafted ...

Apr 13, 2025
CVE-2025-32587
8.1

This CVE describes a path traversal vulnerability in the WooCommerce Pickupp plugin that allows attackers to include arbitrary PHP files from the serv...

Apr 11, 2025
CVE-2025-30582
8.1

This path traversal vulnerability in DyaPress ERP/CRM allows attackers to include arbitrary PHP files from the server's filesystem, potentially leadin...

Apr 10, 2025
CVE-2025-2270
8.1

This vulnerability allows unauthenticated attackers to perform Local File Inclusion (LFI) in the Countdown & Clock WordPress plugin, enabling them to ...

Apr 4, 2025
CVE-2025-27932
8.1

A path traversal vulnerability in the USB storage file-sharing function of HGW-BL1500HM devices allows attackers to delete arbitrary files or cause de...

Mar 28, 2025
CVE-2024-8060
8.1

OpenWebUI 0.3.0 has a critical vulnerability in its audio transcription API that allows authenticated users to upload arbitrary files with path traver...

Mar 20, 2025
CVE-2025-1915
8.1

This vulnerability allows attackers to bypass file access restrictions in Google Chrome on Windows by tricking users into installing a malicious exten...

Mar 5, 2025
CVE-2025-24888
8.1

This vulnerability allows a compromised SecureDrop Server to execute arbitrary code on the SecureDrop Client virtual machine by exploiting improper pa...

Feb 13, 2025
CVE-2024-54909
8.1

This vulnerability in GoldPanKit eva-server v4.1.0 allows attackers to download arbitrary files from the server by manipulating the path parameter in ...

Feb 6, 2025
CVE-2024-53961
8.1

This path traversal vulnerability in Adobe ColdFusion allows attackers to read arbitrary files from the server's filesystem when the admin panel is in...

Dec 23, 2024
CVE-2024-10516
8.1

The Swift Performance Lite WordPress plugin contains a Local File Inclusion vulnerability in its 'ajaxify' function, allowing unauthenticated attacker...

Dec 6, 2024
CVE-2024-11398
8.1

This path traversal vulnerability in Synology Router Manager allows authenticated remote attackers to delete arbitrary files on affected systems by ex...

Dec 4, 2024
CVE-2024-10220
8.1

This vulnerability in Kubernetes kubelet allows attackers to execute arbitrary commands on nodes by exploiting specially crafted gitRepo volumes. It a...

Nov 22, 2024
CVE-2024-41971
8.1

CVE-2024-41971 allows low-privileged remote attackers to overwrite arbitrary files on the filesystem, potentially causing denial of service and data l...

Nov 18, 2024
CVE-2024-43434
8.1

This CSRF vulnerability in Moodle's Feedback module allows attackers to trick authenticated users into unknowingly sending bulk messages to non-respon...

Nov 7, 2024
CVE-2024-44023
8.1

This CVE describes a path traversal vulnerability in the ABCApp Creator WordPress plugin that allows attackers to include local PHP files through impr...

Oct 5, 2024
CVE-2021-27916
8.1

CVE-2021-27916 is a path traversal vulnerability in Mautic's GrapesJS builder that allows authenticated users to delete arbitrary files outside intend...

Sep 17, 2024
CVE-2024-7603
8.1

This vulnerability allows authenticated remote attackers to delete arbitrary directories on Logsign Unified SecOps Platform installations. Attackers c...

Aug 21, 2024
CVE-2024-7600
8.1

This vulnerability allows authenticated remote attackers to delete arbitrary files on Logsign Unified SecOps Platform installations. Attackers can exp...

Aug 21, 2024
CVE-2024-36267
8.1

A path traversal vulnerability in Redmine DMSF Plugin allows authenticated users to access or delete arbitrary files on the server within the Redmine ...

May 30, 2024
CVE-2024-32523
8.1

CVE-2024-32523 is an unauthenticated path traversal vulnerability in the WordPress Mailster plugin that allows attackers to include arbitrary local PH...

May 17, 2024
CVE-2024-1132
8.1

This vulnerability in Keycloak allows attackers to bypass URL validation in redirects when clients use wildcards in Valid Redirect URIs. Attackers can...

Apr 17, 2024
CVE-2024-23671
8.1

This path traversal vulnerability in Fortinet FortiSandbox allows attackers to execute arbitrary code or commands via specially crafted HTTP requests....

Apr 9, 2024
CVE-2024-25567
8.1

This CVE describes a path traversal vulnerability that allows attackers to write files outside intended directories and potentially overwrite existing...

Mar 21, 2024
CVE-2024-28171
8.1

CVE-2024-28171 is a path traversal vulnerability that allows attackers to write files outside intended directories and overwrite existing system files...

Mar 21, 2024
CVE-2024-25006
8.1

This vulnerability allows authenticated XenForo administrators with style management permissions to perform directory traversal attacks when importing...

Feb 29, 2024
CVE-2024-0763
8.1

CVE-2024-0763 is a path traversal vulnerability in Anything-LLM that allows authenticated users to delete arbitrary folders recursively on the server....

Feb 27, 2024
CVE-2023-38019
8.1

This directory traversal vulnerability in IBM SOAR QRadar Plugin App allows remote attackers to read arbitrary files on the system by sending speciall...

Feb 2, 2024
CVE-2024-23182
8.1

This CVE describes a relative path traversal vulnerability in a-blog CMS that allows authenticated remote attackers to delete arbitrary files on the s...

Jan 23, 2024
CVE-2023-48243
8.1

This critical vulnerability allows remote attackers to upload arbitrary files anywhere on affected Bosch systems via crafted HTTP requests, leading to...

Jan 10, 2024
CVE-2023-5355
8.1

This vulnerability in the Awesome Support WordPress plugin allows ticket submitters to delete arbitrary files on the server due to improper path sanit...

Nov 6, 2023
CVE-2023-45868
8.1

CVE-2023-45868 is a directory traversal vulnerability in ILIAS Learning Module 7.25 that allows authenticated attackers to relocate directories outsid...

Oct 26, 2023
CVE-2023-34217
8.1

This vulnerability allows authenticated attackers to delete arbitrary files on affected TN-4900 and TN-5900 Series devices through command injection i...

Aug 17, 2023
CVE-2023-35801
8.1

A directory traversal vulnerability in Safe Software FME Server allows authenticated attackers with write privileges to bypass validation when editing...

Jun 23, 2023
CVE-2023-28382
8.1

This directory traversal vulnerability in ESS REC Agent Server Edition allows authenticated attackers to access or modify arbitrary files on affected ...

May 26, 2023
CVE-2020-13377
8.1

This vulnerability allows authenticated low-privileged attackers to perform directory traversal attacks through the web-services interface of Loadbala...

May 12, 2023

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,128 CVEs classified as CWE-22, with 503 rated critical and 1,083 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free