CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

1,952
Total CVEs
439
Critical
974
High
7.6
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
230
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 26
2 Qnap 21
3 Ivanti 18
4 Fortinet 16
5 Samsung 16
6 Solarwinds 15
7 Siemens 14
8 Adobe 14
9 Fedoraproject 14
10 Synology 12

All Path Traversal CVEs (1,952)

CVE-2025-14344
9.8

This vulnerability allows unauthenticated attackers to delete arbitrary files on WordPress servers running the vulnerable Multi Uploader for Gravity F...

Dec 12, 2025
CVE-2025-67506
9.8

CVE-2025-67506 is a path traversal vulnerability in PipesHub that allows unauthenticated attackers to write arbitrary files anywhere the service accou...

Dec 10, 2025
CVE-2025-66262
9.8

This vulnerability allows attackers to overwrite arbitrary system files via path traversal in tar archive extraction. Attackers can craft malicious .t...

Nov 26, 2025
CVE-2025-11366
9.8

N-central versions before 2025.4 contain a path traversal vulnerability that allows attackers to bypass authentication mechanisms. This affects all or...

Nov 12, 2025
CVE-2025-12493
9.8

This vulnerability allows unauthenticated attackers to include and execute arbitrary PHP files on WordPress servers running the ShopLentor plugin. Att...

Nov 4, 2025
CVE-2025-12422
9.8

This vulnerability allows attackers to write arbitrary files through a vulnerable upgrade feature in BLU-IC2 and BLU-IC4 devices. Successful exploitat...

Oct 28, 2025
CVE-2025-62353
9.8

A path traversal vulnerability in Windsurf IDE allows attackers to read and write arbitrary files on a user's system, both within and outside of curre...

Oct 17, 2025
CVE-2025-6439
9.8

This vulnerability allows unauthenticated attackers to delete arbitrary files on WordPress servers running the vulnerable WooCommerce Designer Pro plu...

Oct 11, 2025
CVE-2025-7526
9.8

This vulnerability allows unauthenticated attackers to delete arbitrary files on WordPress servers running the vulnerable WP Travel Engine plugin. Att...

Oct 9, 2025
CVE-2025-59352
9.8

This vulnerability in Dragonfly allows peers to create or read arbitrary files on other peers' systems via gRPC and HTTP APIs, enabling data theft and...

Sep 17, 2025
CVE-2025-59304
9.8

A directory traversal vulnerability in Swetrix Web Analytics API allows attackers to bypass path restrictions and upload malicious files, leading to r...

Sep 17, 2025
CVE-2025-8895
9.8

The WP Webhooks WordPress plugin allows unauthenticated attackers to copy arbitrary files on the server due to improper input validation. This can lea...

Aug 21, 2025
CVE-2024-44373
9.8

CVE-2024-44373 is a critical path traversal vulnerability in AllSky software that allows unauthenticated attackers to write arbitrary files to the ser...

Aug 19, 2025
CVE-2012-10054
EPSS 75.9% 9.8

This vulnerability allows unauthenticated attackers to upload and execute arbitrary ASPX scripts on Umbraco CMS servers. Attackers can achieve remote ...

Aug 13, 2025
CVE-2025-52913
9.8

An unauthenticated path traversal vulnerability in Mitel MiCollab's NuPoint Unified Messaging component allows attackers to access, modify, or delete ...

Aug 8, 2025
CVE-2025-8356
9.8

CVE-2025-8356 is a critical path traversal vulnerability in Xerox FreeFlow Core version 8.0.4 that allows attackers to access unauthorized files on th...

Aug 8, 2025
CVE-2025-54802
9.8

This vulnerability in pyLoad allows unauthenticated attackers to perform path traversal via the addcrypted endpoint, leading to arbitrary file write a...

Aug 5, 2025
CVE-2025-54387
9.8

CVE-2025-54387 is a path traversal vulnerability in IPX image optimization software that allows attackers to bypass directory restrictions and potenti...

Aug 5, 2025
CVE-2025-54386
9.8

A path traversal vulnerability in Traefik's WASM plugin installation mechanism allows attackers to overwrite arbitrary system files by uploading malic...

Aug 2, 2025
CVE-2025-54446
9.8

This path traversal vulnerability in Samsung MagicINFO 9 Server allows attackers to upload malicious web shell files to restricted directories. Succes...

Jul 23, 2025
CVE-2025-54438
9.8

This path traversal vulnerability in Samsung MagicINFO 9 Server allows attackers to upload malicious web shell files to the web server directory. Atta...

Jul 23, 2025
CVE-2025-46120
9.8

A path traversal vulnerability in Ruckus Unleashed and ZoneDirector web interfaces allows unauthenticated attackers to execute arbitrary EJS template ...

Jul 21, 2025
CVE-2025-4828
9.8

This vulnerability in the Support Board WordPress plugin allows attackers to delete arbitrary files on the server due to insufficient path validation....

Jul 9, 2025
CVE-2025-45890
9.8

A directory traversal vulnerability in novel plus allows remote attackers to read, write, or execute arbitrary files on the server by manipulating the...

Jun 20, 2025
CVE-2025-32799
9.8

CVE-2025-32799 is a path traversal vulnerability in conda-build that allows attackers to write files outside intended directories by crafting maliciou...

Jun 16, 2025
CVE-2025-3594
9.8

A path traversal vulnerability in Liferay Portal and DXP allows remote attackers to write arbitrary files to server locations and download/execute arb...

Jun 16, 2025
CVE-2025-46783
9.8

A path traversal vulnerability (CWE-22) in RICOH Streamline NX V3 PC Client allows attackers to tamper with specific files, potentially leading to arb...

Jun 13, 2025
CVE-2025-37095
9.8

A directory traversal vulnerability in HPE StoreOnce Software allows attackers to access sensitive files outside the intended directory. This affects ...

Jun 2, 2025
CVE-2025-4524
9.8

This vulnerability allows unauthenticated attackers to include and execute arbitrary files on WordPress servers running the Madara theme. Attackers ca...

May 21, 2025
CVE-2025-32926
9.8

This path traversal vulnerability in the Grand Restaurant WordPress theme allows attackers to access files outside the intended directory. If exploite...

May 19, 2025
CVE-2025-4564
9.8

The TicketBAI Facturas para WooCommerce WordPress plugin has an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete ...

May 15, 2025
CVE-2025-30387
9.8

This path traversal vulnerability in Azure allows unauthorized attackers to access restricted directories and elevate privileges over a network. It af...

May 13, 2025
CVE-2025-4632
KEV EPSS 42.7% 9.8

This vulnerability allows attackers to write arbitrary files with system-level privileges on Samsung MagicINFO 9 Server by exploiting improper pathnam...

May 13, 2025
CVE-2025-29660
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary scripts on Yi IOT XY-3820 devices by sending specially crafted TCP requests t...

Apr 21, 2025
CVE-2025-2636
EPSS 10.2% 9.8

This vulnerability allows unauthenticated attackers to include and execute arbitrary PHP files on WordPress servers running the vulnerable InstaWP Con...

Apr 11, 2025
CVE-2025-2941
9.8

This vulnerability allows unauthenticated attackers to move arbitrary files on WordPress servers running the vulnerable Drag and Drop Multiple File Up...

Apr 5, 2025
CVE-2025-22926
9.8

This vulnerability allows attackers to perform directory traversal attacks by sending a specially crafted POST request to the openSIS messaging module...

Apr 3, 2025
CVE-2025-2294
EPSS 53.7% 9.8

The Kubio AI Page Builder WordPress plugin has a Local File Inclusion vulnerability that allows unauthenticated attackers to include and execute arbit...

Mar 28, 2025
CVE-2024-8898
9.8

A path traversal vulnerability in parisneo/lollms-webui version V12 allows attackers to create or delete arbitrary directories on the system by exploi...

Mar 20, 2025
CVE-2025-2505
9.8

The Age Gate WordPress plugin contains a Local File Inclusion vulnerability that allows unauthenticated attackers to include and execute arbitrary PHP...

Mar 20, 2025
CVE-2025-27782
9.8

Applio voice conversion tool versions 3.2.8-bugfix and prior contain an arbitrary file write vulnerability in inference.py that allows attackers to wr...

Mar 19, 2025
CVE-2025-1661
EPSS 91.4% 9.8

This vulnerability allows unauthenticated attackers to perform Local File Inclusion (LFI) via the 'template' parameter in the HUSKY plugin for WordPre...

Mar 11, 2025
CVE-2024-8262
9.8

This path traversal vulnerability in Proliz Software OBS allows attackers to access files outside the intended directory by manipulating file paths. I...

Mar 3, 2025
CVE-2024-38292
9.8

This vulnerability in Extreme Networks XIQ-SE allows attackers to bypass access controls via path traversal, potentially gaining elevated privileges. ...

Feb 27, 2025
CVE-2024-13725
9.8

The Keap Official Opt-in Forms WordPress plugin has a Local File Inclusion vulnerability that allows unauthenticated attackers to include PHP files on...

Feb 18, 2025
CVE-2024-10763
9.8

The Campress WordPress theme contains a Local File Inclusion vulnerability that allows unauthenticated attackers to include and execute arbitrary PHP ...

Feb 13, 2025
CVE-2025-0493
9.8

This vulnerability allows unauthenticated attackers to perform local file inclusion via the tabname parameter in the MultiVendorX WordPress plugin. At...

Jan 31, 2025
CVE-2024-13545
9.8

The Bootstrap Ultimate WordPress theme contains a Local File Inclusion vulnerability that allows unauthenticated attackers to include arbitrary PHP fi...

Jan 24, 2025
CVE-2024-54148
9.8

This vulnerability in Gogs allows a malicious user to commit a crafted symlink file to a repository, potentially gaining SSH access to the server. All...

Dec 23, 2024
CVE-2024-55515
9.8

This vulnerability allows unauthenticated attackers to upload arbitrary files to Raisecom network devices via the web interface. Attackers can exploit...

Dec 17, 2024

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 1,952 CVEs classified as CWE-22, with 439 rated critical and 974 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.6.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free