CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,146
Total CVEs
506
Critical
1,098
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
236
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Solarwinds 17
5 Fedoraproject 17
6 Fortinet 16
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,146)

CVE-2025-3046
7.5

This vulnerability allows attackers to read arbitrary files on systems using the affected llama_index library by exploiting symbolic link handling in ...

Jul 7, 2025
CVE-2025-27022
7.5

A path traversal vulnerability in Infinera G42's WebGUI HTTP endpoint allows authenticated remote users to download any readable files from the operat...

Jul 2, 2025
CVE-2025-37098
7.5

A path traversal vulnerability in HPE Insight Remote Support (IRS) allows attackers to access files outside the intended directory by manipulating fil...

Jul 1, 2025
CVE-2025-34045
EPSS 18.6% 7.5

A path traversal vulnerability in WeiPHP 5.0 allows unauthenticated remote attackers to read arbitrary files on the server by sending crafted POST req...

Jun 26, 2025
CVE-2025-34031
EPSS 14.5% 7.5

A path traversal vulnerability in Moodle LMS Jmol plugin versions 6.1 and earlier allows unauthenticated attackers to read arbitrary files from the se...

Jun 24, 2025
CVE-2025-48026
7.5

An unauthenticated path traversal vulnerability in Mitel OpenScape Xpressions WebApl component allows attackers to read arbitrary files from the under...

Jun 23, 2025
CVE-2025-50349
7.5

PHPGurukul Pre-School Enrollment System V1.0 contains a directory traversal vulnerability in update-teacher-pic.php that allows attackers to read arbi...

Jun 23, 2025
CVE-2025-48124
7.5

This path traversal vulnerability in the Spreadsheet Price Changer WordPress plugin allows attackers to download arbitrary files from the server by ma...

Jun 9, 2025
CVE-2025-4138
7.5

This vulnerability in Python's tarfile module allows attackers to bypass extraction filters, enabling symlink attacks that can write files outside the...

Jun 3, 2025
CVE-2025-27956
7.5

A directory traversal vulnerability in WebLaudos 24.2 (04) allows remote attackers to access sensitive files outside the intended directory structure ...

Jun 2, 2025
CVE-2024-6648
7.5

An unauthenticated remote attacker can exploit this absolute path traversal vulnerability in AP Page Builder to modify configuration files and read ar...

May 8, 2025
CVE-2025-1565
7.5

The Mayosis Core WordPress plugin contains an arbitrary file read vulnerability in all versions up to 5.4.1. Unauthenticated attackers can exploit thi...

Apr 25, 2025
CVE-2025-28072
7.5

PHPGurukul Pre-School Enrollment System contains a directory traversal vulnerability in manage-teachers.php that allows attackers to access files outs...

Apr 16, 2025
CVE-2024-12905
7.5

This vulnerability in tar-fs allows attackers to write files outside the intended extraction directory when processing malicious tar archives. It affe...

Mar 27, 2025
CVE-2025-30895
7.5

This path traversal vulnerability in the WpEvently WordPress plugin allows attackers to include arbitrary PHP files from the server, potentially leadi...

Mar 27, 2025
CVE-2024-9362
7.5

An unauthenticated directory traversal vulnerability in Polyaxon allows attackers to access sensitive files and directory information without authenti...

Mar 20, 2025
CVE-2024-8438
7.5

A path traversal vulnerability in modelscope/agentscope v0.0.4 allows attackers to read arbitrary files on the server by manipulating the 'path' param...

Mar 20, 2025
CVE-2024-6851
7.5

This vulnerability allows arbitrary file deletion on systems running the aim tracking server. An attacker can craft a glob-pattern to delete files out...

Mar 20, 2025
CVE-2024-12866
7.5

A local file inclusion vulnerability in netease-youdao/qanything v2.0.0 allows attackers to read arbitrary files on the file system. This can lead to ...

Mar 20, 2025
CVE-2024-12065
7.5

A local file inclusion vulnerability in haotian-liu/llava's Gradio web UI allows attackers to read arbitrary files on the server by sending specially ...

Mar 20, 2025
CVE-2025-2493
7.5

This path traversal vulnerability in Softdial Contact Center allows attackers to manipulate the 'id' parameter in the '/softdial/scheduler/load.php' e...

Mar 18, 2025
CVE-2025-25684
7.5

This path traversal vulnerability in GL-INet Beryl AX GL-MT3000 routers allows attackers to download arbitrary files from the device's file system by ...

Mar 17, 2025
CVE-2025-25685
7.5

This vulnerability allows attackers to download arbitrary files from GL-INet Beryl AX GL-MT3000 routers by exploiting symbolic link manipulation on ex...

Mar 17, 2025
CVE-2024-13471
7.5

The DesignThemes Core Features WordPress plugin contains a file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files ...

Mar 5, 2025
CVE-2025-25759
7.5

This vulnerability in SUCMS v1.0 allows attackers to perform directory traversal and delete arbitrary files via crafted GET requests to admin_template...

Feb 27, 2025
CVE-2025-26905
7.5

This path traversal vulnerability in the Estatik WordPress plugin allows attackers to include arbitrary local PHP files, potentially leading to remote...

Feb 25, 2025
CVE-2025-26753
7.5

This path traversal vulnerability in VideoWhisper Live Streaming Integration allows attackers to download arbitrary files from the server by manipulat...

Feb 25, 2025
CVE-2025-27092
7.5

A path traversal vulnerability in GHOSTS version 8.0.0.0 allows attackers to read arbitrary files from the server's filesystem by exploiting the photo...

Feb 19, 2025
CVE-2025-25997
7.5

CVE-2025-25997 is a directory traversal vulnerability in FeMiner wms v1.0 that allows remote attackers to access sensitive files outside the intended ...

Feb 14, 2025
CVE-2024-51376
7.5

A directory traversal vulnerability in yeqifu carRental v1.0 allows remote attackers to access sensitive files outside the intended directory via the ...

Feb 12, 2025
CVE-2025-24406
7.5

This CVE describes a path traversal vulnerability in Adobe Commerce that allows unauthenticated attackers to modify files outside restricted directori...

Feb 11, 2025
CVE-2024-52883
7.5

A path traversal vulnerability in AudioCodes One Voice Operations Center (OVOC) allows unauthenticated attackers to read sensitive data. This affects ...

Feb 7, 2025
CVE-2025-25155
7.5

This path traversal vulnerability in the efreja Music Sheet Viewer WordPress plugin allows attackers to read arbitrary files on the server by manipula...

Feb 7, 2025
CVE-2025-25163
EPSS 17.5% 7.5

This path traversal vulnerability in the WordPress Plugin A/B Image Optimizer allows attackers to download arbitrary files from the server by manipula...

Feb 7, 2025
CVE-2024-57451
7.5

ChestnutCMS versions 1.5.0 and earlier contain a directory traversal vulnerability in the FileController component that allows attackers to access arb...

Feb 3, 2025
CVE-2024-57669
7.5

A directory traversal vulnerability in Zrlog backup-sql-file.jar v3.0.31 allows remote attackers to read arbitrary files on the server by manipulating...

Feb 3, 2025
CVE-2025-24569
7.5

This path traversal vulnerability in the PDF Generator Addon for Elementor Page Builder WordPress plugin allows attackers to read arbitrary files on t...

Feb 3, 2025
CVE-2025-23819
7.5

This path traversal vulnerability in the WP Cloud WordPress plugin allows attackers to delete arbitrary files on the server by manipulating file paths...

Feb 3, 2025
CVE-2024-53582
7.5

This vulnerability in OpenPanel v0.3.4 allows attackers to perform directory traversal attacks through the File Manager's Copy and View functions. Att...

Jan 31, 2025
CVE-2024-13671
7.5

The Music Sheet Viewer WordPress plugin contains an arbitrary file read vulnerability that allows unauthenticated attackers to read any file on the se...

Jan 30, 2025
CVE-2024-13409
7.5

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to perform Local File Inclusion attacks via the 'theme...

Jan 24, 2025
CVE-2025-23422
7.5

This path traversal vulnerability in the WordPress Store Locator plugin allows attackers to include arbitrary local PHP files through improper path va...

Jan 24, 2025
CVE-2024-13180
7.5

CVE-2024-13180 is a path traversal vulnerability in Ivanti Avalanche that allows remote unauthenticated attackers to access sensitive files and inform...

Jan 14, 2025
CVE-2023-42232
7.5

This directory traversal vulnerability in Pat Infinite Solutions HelpdeskAdvanced allows attackers to access files outside the intended directory via ...

Jan 13, 2025
CVE-2023-42225
7.5

This directory traversal vulnerability in Pat Infinite Solutions HelpdeskAdvanced allows attackers to access arbitrary files on the server by manipula...

Jan 13, 2025
CVE-2023-42226
7.5

This vulnerability allows attackers to perform directory traversal attacks through the Email/SaveAttachment function in Pat Infinite Solutions Helpdes...

Jan 13, 2025
CVE-2023-42227
7.5

This vulnerability allows attackers to perform directory traversal attacks through the WSCView/Save function in Pat Infinite Solutions HelpdeskAdvance...

Jan 13, 2025
CVE-2025-21622
7.5

This CVE describes a path traversal vulnerability in ClipBucket V5's avatar upload feature. Attackers can delete arbitrary files on the server by mani...

Jan 7, 2025
CVE-2025-21623
7.5

This vulnerability in ClipBucket V5 allows unauthenticated attackers to perform directory traversal attacks to change the template directory, leading ...

Jan 7, 2025
CVE-2024-56286
7.5

This path traversal vulnerability in Classic Addons for WPBakery Page Builder allows attackers to include arbitrary PHP files from the server's filesy...

Jan 7, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,146 CVEs classified as CWE-22, with 506 rated critical and 1,098 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free