CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,141
Total CVEs
506
Critical
1,093
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
236
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Solarwinds 17
5 Fedoraproject 17
6 Fortinet 16
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,141)

CVE-2025-23343
7.6

The NVIDIA NVDebug tool contains a improper path validation vulnerability (CWE-22) that allows attackers to write files to restricted system component...

Sep 9, 2025
CVE-2025-42977
7.6

SAP NetWeaver Visual Composer has a directory traversal vulnerability where high-privileged users can manipulate input paths to access arbitrary files...

Jun 10, 2025
CVE-2024-55926
7.6

A vulnerability in Xerox Workplace Suite allows attackers to read, upload, and delete arbitrary files on the server by manipulating HTTP headers. This...

Jan 23, 2025
CVE-2024-55602
7.6

This vulnerability in PwnDoc allows authenticated users with template update/download permissions to perform path traversal attacks by injecting '../'...

Dec 10, 2024
CVE-2024-47558
7.6

This vulnerability allows authenticated attackers to execute arbitrary code on affected Xerox FreeFlow Core systems via path traversal. Attackers can ...

Oct 7, 2024
CVE-2020-24102
7.6

CVE-2020-24102 is a directory traversal vulnerability in Punkbuster's pbsv.d64 component that allows remote attackers to read arbitrary files and pote...

Jul 22, 2024
CVE-2024-23474
7.6

CVE-2024-23474 is a vulnerability in SolarWinds Access Rights Manager that allows attackers to delete arbitrary files and disclose sensitive informati...

Jul 17, 2024
CVE-2024-23468
7.6

CVE-2024-23468 is a directory traversal vulnerability in SolarWinds Access Rights Manager that allows unauthenticated attackers to delete arbitrary fi...

Jul 17, 2024
CVE-2023-37888
7.6

This vulnerability allows unauthenticated attackers to perform path traversal attacks, leading to local file inclusion in WordPress sites using the Ph...

May 17, 2024
CVE-2023-35881
7.6

This vulnerability allows attackers to read arbitrary files on the server through path traversal in the WooCommerce One Page Checkout plugin. It affec...

May 17, 2024
CVE-2023-23888
7.6

This path traversal vulnerability in Rank Math SEO WordPress plugin allows attackers to read arbitrary files on the server by manipulating file paths....

May 17, 2024
CVE-2024-31978
7.6

This vulnerability in SINEC NMS allows authenticated users to exploit a path traversal flaw in the monitoring data export API endpoint. Attackers can ...

Apr 9, 2024
CVE-2023-4760
7.6

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running vulnerable Eclipse RAP versions. Attackers can exploit...

Sep 21, 2023
CVE-2022-24718
7.6

CVE-2022-24718 is a path traversal vulnerability in ssr-pages, an HTML page builder for server-side rendering. When untrusted input is passed to the '...

Mar 1, 2022
CVE-2018-25178
7.5

Easyndexer 1.0 contains an unauthenticated arbitrary file download vulnerability that allows attackers to retrieve sensitive system files by manipulat...

Mar 6, 2026
CVE-2026-28429
7.5

This CVE describes a path traversal vulnerability in Talishar, a fan-made Flesh and Blood project, where the ParseGamestate.php component can be acces...

Mar 6, 2026
CVE-2026-28462
7.5

OpenClaw versions before 2026.2.13 contain a path traversal vulnerability in browser control API endpoints that handle trace and download files. Attac...

Mar 5, 2026
CVE-2026-1557
7.5

The WP Responsive Images WordPress plugin contains a path traversal vulnerability in the 'src' parameter that allows unauthenticated attackers to read...

Feb 26, 2026
CVE-2026-25891
7.5

A path traversal vulnerability in Fiber's static middleware on Windows allows remote attackers to bypass sanitization and read arbitrary files from th...

Feb 24, 2026
CVE-2026-27202
7.5

GetSimple CMS has a path traversal vulnerability in its Uploaded Files feature that allows attackers to read arbitrary files on the server. This affec...

Feb 21, 2026
CVE-2026-26321
7.5

OpenClaw's Feishu extension had a path traversal vulnerability that allowed reading arbitrary local files by supplying attacker-controlled paths. This...

Feb 19, 2026
CVE-2026-26202
7.5

An authenticated user with team edit permissions in Penpot can read arbitrary files from the server filesystem by exploiting a path traversal vulnerab...

Feb 19, 2026
CVE-2019-25355
7.5

CVE-2019-25355 is a directory traversal vulnerability in gSOAP 2.8 that allows unauthenticated attackers to access sensitive system files by manipulat...

Feb 18, 2026
CVE-2026-23491
7.5

CVE-2026-23491 is a path traversal vulnerability in InvoicePlane that allows unauthenticated attackers to read arbitrary files on the server by manipu...

Feb 18, 2026
CVE-2026-22860
7.5

This vulnerability in Rack's Rack::Directory component allows attackers to bypass directory restrictions using path traversal techniques. By crafting ...

Feb 18, 2026
CVE-2026-21878
7.5

This vulnerability in BACnet Stack allows attackers to write files to arbitrary directories due to lack of path validation in file writing functionali...

Feb 13, 2026
CVE-2025-15577
7.5

An unauthenticated attacker can exploit this vulnerability by manipulating URLs to read arbitrary files from the Valmet DNA Web Tools server. This aff...

Feb 12, 2026
CVE-2026-20660
7.5

This CVE describes a path handling vulnerability (CWE-22) in multiple Apple operating systems and Safari that allows a remote attacker to write arbitr...

Feb 11, 2026
CVE-2020-37214
7.5

CVE-2020-37214 is a directory traversal vulnerability in Voyager 1.3.0 that allows attackers to read sensitive system files by manipulating the asset ...

Feb 11, 2026
CVE-2025-70084
7.5

A directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to access sensitive files or delete arbitrary files by manipulating input to ...

Feb 11, 2026
CVE-2026-22905
7.5

This vulnerability allows unauthenticated remote attackers to bypass authentication by exploiting insufficient URI validation. Attackers can use path ...

Feb 9, 2026
CVE-2026-25732
7.5

This vulnerability in NiceGUI allows attackers to perform path traversal attacks by uploading files with malicious filenames containing '../' sequence...

Feb 6, 2026
CVE-2026-25499
7.5

This vulnerability in the Terraform/OpenTofu Proxmox provider allows attackers to escape restricted directories via path traversal (../) in SSH config...

Feb 4, 2026
CVE-2020-37041
7.5

CVE-2020-37041 is a directory traversal vulnerability in OpenCTI 3.3.1 that allows unauthenticated attackers to read arbitrary files from the server f...

Jan 30, 2026
CVE-2026-24469
7.5

CVE-2026-24469 is a path traversal vulnerability in C++ HTTP Server versions 1.0 and below that allows unauthenticated remote attackers to read arbitr...

Jan 24, 2026
CVE-2025-68907
7.5

This path traversal vulnerability in the Hostme v2 WordPress theme allows attackers to delete arbitrary files on the server by manipulating file paths...

Jan 22, 2026
CVE-2021-47850
7.5

Mini Mouse 9.2.0 contains a path traversal vulnerability that allows remote attackers to access arbitrary system files and directories through crafted...

Jan 21, 2026
CVE-2026-23850
7.5

SiYuan personal knowledge management system versions before 3.5.4 contain a path traversal vulnerability in the markdown feature's HTML rendering. Thi...

Jan 19, 2026
CVE-2026-23644
7.5

A path traversal vulnerability in esm.sh CDN allows attackers to write arbitrary files outside intended directories by exploiting absolute paths in ma...

Jan 18, 2026
CVE-2025-67076
7.5

This directory traversal vulnerability in Omnispace Agora Project allows unauthenticated attackers to read arbitrary files with extensions from the se...

Jan 15, 2026
CVE-2021-47755
7.5

CVE-2021-47755 is a path traversal vulnerability in Oliver Library Server v5 that allows unauthenticated attackers to download arbitrary files from th...

Jan 15, 2026
CVE-2025-9142
7.5

This vulnerability allows a local user on a Windows system to manipulate the Harmony SASE client to write or delete files outside its intended certifi...

Jan 14, 2026
CVE-2022-50932
7.5

Kyocera Command Center RX ECOSYS M2035dn has a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system files ...

Jan 13, 2026
CVE-2025-25652
7.5

This directory traversal vulnerability in Eptura Archibus allows attackers to access files outside the intended directory through the 'Run script' and...

Jan 13, 2026
CVE-2025-66744
EPSS 10.5% 7.5

This vulnerability in Yonyou YonBIP allows attackers to bypass normal directory restrictions via path traversal in the LoginWithV8 interface, potentia...

Jan 9, 2026
CVE-2026-0669
7.5

This path traversal vulnerability in MediaWiki's CSS extension allows attackers to read arbitrary files on the server by manipulating file paths. It a...

Jan 7, 2026
CVE-2025-13801
7.5

The Yoco Payments WordPress plugin contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files on the server...

Jan 7, 2026
CVE-2025-68953
7.5

This CVE describes a path traversal vulnerability in Frappe web framework that allows attackers to read arbitrary files from the server due to insuffi...

Jan 5, 2026
CVE-2025-67160
7.5

This directory traversal vulnerability in Vatilon v1.12.37-20240124 allows attackers to access sensitive files and directories outside the intended we...

Jan 2, 2026
CVE-2025-59384
7.5

A path traversal vulnerability in Qfiling allows remote attackers to read arbitrary files on the system by manipulating file paths. This affects all Q...

Jan 2, 2026

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,141 CVEs classified as CWE-22, with 506 rated critical and 1,093 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free