CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,141
Total CVEs
506
Critical
1,093
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
236
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Solarwinds 17
5 Fedoraproject 17
6 Fortinet 16
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,141)

CVE-2021-41579
7.8

This vulnerability in LCDS LAquis SCADA allows attackers to bypass security controls and write arbitrary files to the operating system through path tr...

Oct 4, 2021
CVE-2021-22762
7.8

This vulnerability allows remote code execution through path traversal in Schneider Electric's IGSS Definition software. Attackers can exploit it by t...

Jun 11, 2021
CVE-2009-3721
7.8

This vulnerability allows attackers to exploit directory traversal and buffer overflow flaws in yTNEF and Evolution's TNEF parser when processing spec...

May 26, 2021
CVE-2021-27030
7.8

CVE-2021-27030 is a directory traversal vulnerability in Autodesk FBX Review that allows remote code execution when a user opens a malicious FBX file....

Apr 19, 2021
CVE-2021-22651
7.8

This directory traversal vulnerability in Luxion KeyShot products allows attackers to place malicious scripts in system startup folders by tricking us...

Feb 23, 2021
CVE-2021-21037
7.8

This CVE describes a path traversal vulnerability in Adobe Acrobat Reader DC that allows arbitrary code execution. An unauthenticated attacker can exp...

Feb 11, 2021
CVE-2021-26575
7.8

This CVE describes a path traversal vulnerability in HPE Apollo 70 System BMC firmware that allows attackers to delete arbitrary files on the system. ...

Feb 8, 2021
CVE-2021-25124
7.8

This CVE describes a local path traversal vulnerability in the Baseboard Management Controller (BMC) firmware of specific HPE Cloudline servers. An at...

Jan 29, 2021
CVE-2021-25128
7.8

This CVE describes a path traversal vulnerability in the Baseboard Management Controller (BMC) firmware of specific HPE Cloudline servers. It allows l...

Jan 29, 2021
CVE-2020-10010
7.8

This CVE describes a path handling vulnerability in Apple operating systems that allows local attackers to elevate privileges through improper validat...

Dec 8, 2020
CVE-2020-1082
7.8

This vulnerability allows attackers to elevate privileges on Windows systems by exploiting how Windows Error Reporting (WER) handles and executes file...

May 21, 2020
CVE-2025-69377
7.7

This path traversal vulnerability in the WordPress User Extra Fields plugin allows attackers to delete arbitrary files on the server. It affects all W...

Feb 20, 2026
CVE-2025-68862
7.7

This path traversal vulnerability in the Woo File Dropzone WordPress plugin allows attackers to delete arbitrary files on the server. It affects all W...

Feb 20, 2026
CVE-2025-68279
7.7

This vulnerability in Weblate allows attackers to read arbitrary files from the server file system by exploiting crafted symbolic links in repositorie...

Dec 18, 2025
CVE-2025-59002
7.7

This path traversal vulnerability in SeaTheme BM Content Builder WordPress plugin allows attackers to delete arbitrary files on the server. It affects...

Sep 26, 2025
CVE-2025-58355
7.7

Soft Serve versions 0.9.1 and below contain a path traversal vulnerability (CWE-22) in the SSH API that allows attackers to create or overwrite arbitr...

Sep 4, 2025
CVE-2025-53588
7.7

This path traversal vulnerability in the UPC/EAN/GTIN Code Generator WordPress plugin allows attackers to delete arbitrary files on the server. It aff...

Aug 28, 2025
CVE-2024-39399
7.7

CVE-2024-39399 is a path traversal vulnerability in Adobe Commerce that allows low-privileged attackers to read arbitrary files from the server's file...

Aug 14, 2024
CVE-2024-22232
7.7

This vulnerability allows attackers to read arbitrary files from a Salt master's filesystem by exploiting a directory traversal flaw in the Salt file ...

Jun 27, 2024
CVE-2024-4498
7.7

This CVE describes a Path Traversal and Remote File Inclusion vulnerability in the parisneo/lollms-webui application that allows attackers to manipula...

Jun 25, 2024
CVE-2024-38449
7.7

This CVE describes a directory traversal vulnerability in KasmVNC that allows authenticated remote attackers to access files and directories outside t...

Jun 17, 2024
CVE-2022-45368
7.7

This path traversal vulnerability in the Lenderd 1003 Mortgage Application WordPress plugin allows attackers to access files outside the intended dire...

May 17, 2024
CVE-2024-1630
7.7

A path traversal vulnerability in the 'getAllFolderContents' function of GE HealthCare's Common Service Desktop component allows attackers to access f...

May 14, 2024
CVE-2024-3783
7.7

CVE-2024-3783 is a path traversal vulnerability in WBSAirback 21.02.04 that allows low-privileged users to download arbitrary files from the system. T...

Apr 15, 2024
CVE-2024-31240
7.7

This path traversal vulnerability in the WordPress WP Poll Maker plugin allows authenticated users with subscriber-level access to delete arbitrary fi...

Apr 10, 2024
CVE-2024-31457
7.7

This CVE describes a code injection vulnerability in gin-vue-admin's plugin template feature where attackers can perform directory traversal via the p...

Apr 9, 2024
CVE-2023-49089
7.7

This vulnerability allows authenticated Umbraco backoffice users with package creation permissions to perform path traversal attacks, enabling them to...

Dec 12, 2023
CVE-2023-23365
7.7

This path traversal vulnerability in QNAP Music Station allows authenticated users to access files outside the intended directory by manipulating file...

Oct 6, 2023
CVE-2023-42462
7.7

CVE-2023-42462 is a path traversal vulnerability in GLPI's document upload functionality that allows attackers to delete arbitrary files on the server...

Sep 27, 2023
CVE-2023-3406
7.7

This path traversal vulnerability in M-Files Classic Web allows authenticated users to access restricted files on the web server by manipulating file ...

Aug 25, 2023
CVE-2023-26215
7.7

This vulnerability in TIBCO EBX Add-ons allows authenticated low-privileged users to read system files accessible to the web server. It affects organi...

May 25, 2023
CVE-2022-27615
7.7

This path traversal vulnerability in Synology DNS Server allows authenticated remote attackers to delete arbitrary files on the system. It affects Syn...

Jul 28, 2022
CVE-2022-24730
7.7

Argo CD versions 1.3.0 through 2.3.0 contain a path traversal vulnerability combined with improper access control. This allows authenticated users wit...

Mar 23, 2022
CVE-2021-27471
7.7

This vulnerability allows attackers to craft malicious files that exploit path traversal when opened in Rockwell Automation Connected Components Workb...

Mar 23, 2022
CVE-2022-24348
7.7

This vulnerability in Argo CD allows attackers to perform directory traversal attacks through malicious Helm charts, potentially accessing sensitive f...

Feb 4, 2022
CVE-2022-23602
7.7

This vulnerability in Nimforum allows any authenticated user to create posts or threads that include local file references, which the server will rend...

Feb 1, 2022
CVE-2022-21682
7.7

Flatpak versions before 1.12.3 and 1.10.6 contain a path traversal vulnerability in flatpak-builder when using the --mirror-screenshots-url option. Th...

Jan 13, 2022
CVE-2021-41152
7.7

CVE-2021-41152 is a path traversal vulnerability in OpenOlat that allows authenticated users to read arbitrary files on the server by manipulating HTT...

Oct 18, 2021
CVE-2021-37200
7.7

CVE-2021-37200 is a path traversal vulnerability in Siemens SINEC NMS that allows authenticated attackers to download arbitrary files from the underly...

Sep 14, 2021
CVE-2020-26279
7.7

CVE-2020-26279 is a path traversal vulnerability in go-ipfs that allows attackers to overwrite files or write to incorrect directories when retrieving...

Mar 24, 2021
CVE-2020-13550
7.7

A local file inclusion vulnerability in Advantech WebAccess/SCADA 9.0.1 allows authenticated attackers to read arbitrary files on the system. This aff...

Feb 17, 2021
CVE-2021-21251
7.7

CVE-2021-21251 is a path traversal vulnerability in OneDev's TarUtils library that allows authenticated attackers to write arbitrary files anywhere on...

Jan 15, 2021
CVE-2020-35749
7.7

This CVE describes a directory traversal vulnerability in the Simple Job Board WordPress plugin that allows authenticated attackers to read arbitrary ...

Jan 15, 2021
CVE-2021-21234
7.7

This CVE describes a directory traversal vulnerability in spring-boot-actuator-logview library versions before 0.2.13. Attackers can exploit insuffici...

Jan 5, 2021
CVE-2020-16136
7.7

This vulnerability allows authenticated users with log download permissions in tgstation-server to perform directory traversal attacks, enabling them ...

Jul 31, 2020
CVE-2020-12103
7.7

This vulnerability in Tiny File Manager 2.4.1 allows authenticated users to create backup copies of files with .bak extension outside their intended d...

Apr 28, 2020
CVE-2025-14914
7.6

This vulnerability allows a privileged user in IBM WebSphere Application Server Liberty to upload a zip archive containing path traversal sequences, w...

Feb 2, 2026
CVE-2026-25116
7.6

CVE-2026-25116 is an unauthenticated path traversal vulnerability in Runtipi homeserver orchestrator that allows remote attackers to overwrite the doc...

Jan 29, 2026
CVE-2025-59566
7.6

This path traversal vulnerability in the Workreap WordPress theme plugin allows attackers to delete arbitrary files on the server by manipulating file...

Oct 22, 2025
CVE-2025-61784
7.6

This SSRF/LFI vulnerability in LLaMA-Factory allows authenticated users to make arbitrary HTTP requests to internal/external networks and read arbitra...

Oct 7, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,141 CVEs classified as CWE-22, with 506 rated critical and 1,093 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free