CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (2,131)
This vulnerability allows authenticated low-privileged attackers to perform directory traversal attacks through the web-services interface of Loadbala...
May 12, 2023MuYuCMS v2.2 contains an arbitrary file deletion vulnerability in the /accessory/picdel.html component that allows attackers to delete any file on the...
Mar 28, 2023OrangeScrum version 2.0.11 contains a path traversal vulnerability that allows authenticated attackers to delete arbitrary files on the server. This o...
Feb 1, 2023This CVE combines path traversal and command injection vulnerabilities in ABB flow computer and remote controller products. Attackers can exploit thes...
Jul 21, 2022CVE-2022-1993 is a path traversal vulnerability in Gogs (Go Git Service) that allows attackers to read arbitrary files on the server by manipulating f...
Jun 9, 2022This path traversal vulnerability in Android HTTP File Server 1.4.1 allows attackers to access, list, and modify files outside the intended directory....
Jun 9, 2022CVE-2022-1850 is a path traversal vulnerability in FileGator that allows attackers to access files outside the intended directory. This affects all Fi...
May 24, 2022Verydows v2.0 contains an arbitrary file deletion vulnerability in the backend file controller that allows attackers to delete files on the server. Th...
Apr 26, 2022HongCMS 3.0.0 contains an arbitrary file deletion vulnerability in the template management component. Attackers can delete any file on the server by e...
Apr 26, 2022CVE-2022-28527 is an arbitrary folder deletion vulnerability in dhcms v20170919 that allows attackers to delete arbitrary folders via the /admin.php?r...
Apr 26, 2022This vulnerability allows attackers to perform directory traversal attacks on Artica Proxy by manipulating the filename parameter in the /cgi-bin/main...
Apr 25, 2022CVE-2022-24851 is a stored cross-site scripting (XSS) vulnerability in LDAP Account Manager (LAM) that allows authenticated attackers to inject malici...
Apr 15, 2022This vulnerability allows unauthenticated attackers on the local network to perform path traversal attacks on ASUS RT-AX56U routers. By exploiting ins...
Apr 7, 2022CVE-2021-26601 is a path traversal vulnerability in ImpressCMS that allows attackers to read arbitrary files on the server by manipulating the image_t...
Mar 28, 2022The Jenkins Warnings Next Generation Plugin vulnerability allows attackers with Item/Configure permission to read and write files with specific hard-c...
Jan 12, 2022CVE-2021-21909 is a path traversal vulnerability in a file deletion command that allows arbitrary file deletion via specially crafted arguments. Attac...
Dec 22, 2021This vulnerability in Squashfs-Tools allows directory traversal attacks during archive extraction. Attackers can craft malicious squashfs archives tha...
Aug 27, 2021This CVE describes a path traversal vulnerability in FortiSandbox that allows authenticated users to access restricted files and directories via speci...
Aug 4, 2021CVE-2021-37443 is a path traversal vulnerability in NCH IVM Attendant that allows attackers to delete arbitrary files on the server via the logdeletes...
Jul 25, 2021This vulnerability allows authenticated users in NCH Quorum conference software to delete arbitrary files via directory traversal in the documentdelet...
Jul 25, 2021This vulnerability allows authorized WordPress users to perform directory traversal attacks via the CM Download Manager plugin, enabling them to delet...
Jul 7, 2021Envoy proxy versions 1.18.2 and earlier fail to decode escaped slash sequences (%2F and %5C) in HTTP URL paths, allowing attackers to bypass access co...
May 28, 2021This CVE describes a directory traversal vulnerability in FusionPBX 4.5.7 that allows authenticated remote attackers to delete arbitrary folders on th...
May 20, 2021This directory traversal vulnerability in SolarView Compact SV-CPT-MC310 allows authenticated attackers to delete arbitrary files and directories on t...
Feb 24, 2021This vulnerability allows remote attackers with access to an iSCSI LUN to perform directory traversal attacks via XCOPY requests in the Linux kernel's...
Jan 13, 2021This path traversal vulnerability in Marvell QConvergeConsole GUI allows authenticated remote attackers to delete arbitrary files with SYSTEM/root pri...
Jan 8, 2021This vulnerability allows authenticated attackers to read and write files outside the web root directory using directory traversal techniques in FlexD...
Nov 12, 2020This vulnerability allows authenticated remote attackers to perform directory traversal attacks on Cisco Firepower Management Center (FMC) and Firepow...
Oct 21, 2020This vulnerability in the Weblate command-line client (wlc) allows a malicious Weblate server to write files to arbitrary locations on a client's syst...
Jan 16, 2026This CVE describes a path traversal vulnerability in Keras 3.11.3's keras.utils.get_file() function when extracting tar archives. The vulnerability al...
Nov 28, 2025This vulnerability allows admin users in Mattermost to execute arbitrary code by uploading malicious plugins to the prepackaged plugins directory. The...
Sep 19, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete arbitrary files on the server due to insuffic...
Sep 11, 2025This vulnerability allows attackers to perform path traversal attacks in the Rehub WordPress theme, enabling local file inclusion of PHP files. It aff...
May 17, 2024This vulnerability allows attackers to perform path traversal attacks via malicious ZIP archives ('zip slip'), enabling arbitrary file overwrites on t...
May 15, 2024The JSON datasource plugin for Grafana has a path traversal vulnerability that allows authenticated users to query arbitrary endpoints on the configur...
Feb 14, 2024This vulnerability allows low-privileged users to exploit directory traversal in SolarWinds Network Configuration Manager to execute arbitrary code wi...
Nov 9, 2023This vulnerability in SolarWinds Network Configuration Manager allows low-privileged users to exploit directory traversal flaws to execute arbitrary c...
Nov 1, 2023This directory traversal vulnerability allows attackers to access files outside the intended backup folder structure by manipulating path sequences. I...
Oct 22, 2021CVE-2020-14352 is a directory traversal vulnerability in librepo versions before 1.12.1 that allows attackers controlling remote repositories to write...
Aug 30, 2020A partial-path traversal vulnerability in AWS SDK for Java v1 allows attackers to write S3 bucket contents outside the intended destination directory ...
Jul 15, 2022This path traversal vulnerability in Synology Docker's container volume management allows local users to bypass directory restrictions and access arbi...
Jun 1, 2021OpenViking versions 0.2.1 and earlier contain a path traversal vulnerability in .ovpack import handling that allows attackers to write arbitrary files...
Mar 3, 2026A path validation vulnerability in Apple operating systems allows malicious applications to gain root privileges through improper path handling. This ...
Feb 11, 2026This CVE describes a path handling vulnerability in macOS that allows an application to gain root privileges through improper validation. It affects m...
Feb 11, 2026This vulnerability allows attackers on the same local network to probe the TP-Link Tapo C260 v1 camera's filesystem to determine if specific files exi...
Feb 10, 2026A directory traversal vulnerability in 7-Zip's ZIP file parsing allows remote attackers to execute arbitrary code by crafting malicious ZIP archives c...
Jan 23, 2026This vulnerability allows arbitrary file write through path traversal in archive extraction functions. Attackers can place malicious archives that ext...
Jan 23, 2026CVE-2025-68921 is a directory traversal vulnerability in SteelSeries Nahimic 3 audio software that allows attackers to read arbitrary files on the sys...
Jan 16, 2026This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of pdfforge PDF Architect by tricking user...
Dec 23, 2025This vulnerability allows remote attackers to execute arbitrary code on Soda PDF Desktop by tricking users into opening malicious CBZ files. Attackers...
Dec 23, 2025About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 2,131 CVEs classified as CWE-22, with 503 rated critical and 1,086 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free