CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (2,146)
The MIPL WC Multisite Sync WordPress plugin contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files...
Jan 7, 2025The Error Log Viewer By WP Guru WordPress plugin contains an unauthenticated arbitrary file read vulnerability. Attackers can exploit this to read any...
Jan 7, 2025A path traversal vulnerability in Kurmi Provisioning Suite's DocServlet servlet allows remote attackers to read any file from the web application inst...
Dec 27, 2024Spring applications using WebMvc.fn or WebFlux.fn functional web frameworks to serve static resources are vulnerable to path traversal attacks. Attack...
Dec 19, 2024This path traversal vulnerability in the WP Cookies Enabler WordPress plugin allows attackers to include local PHP files via directory traversal seque...
Dec 16, 2024This CVE describes a path traversal vulnerability in the Sogrid WordPress plugin that allows attackers to include local PHP files via improper pathnam...
Dec 16, 2024This vulnerability allows attackers to perform directory traversal attacks in Syncfusion Essential Studio for ASP.NET MVC's File Manager component. By...
Dec 15, 2024CVE-2024-55657 is an arbitrary file read vulnerability in SiYuan personal knowledge management systems. Attackers can exploit the unvalidated path par...
Dec 12, 2024This path traversal vulnerability in Lenxel Core for Lenxel(LNX) LMS allows attackers to read arbitrary files on the server by manipulating file paths...
Dec 9, 2024The WP Hide & Security Enhancer WordPress plugin has a vulnerability that allows unauthenticated attackers to delete arbitrary files on the server due...
Dec 6, 2024Favorites-web 1.3.0 has a directory traversal vulnerability in SecurityFilter.java that allows attackers to access files outside the intended director...
Dec 5, 2024This vulnerability allows authenticated WordPress users with Contributor-level access or higher to include and execute arbitrary PHP files on Windows ...
Dec 4, 2024This path traversal vulnerability in the Jobify WordPress theme allows unauthenticated attackers to read arbitrary files on the server by manipulating...
Nov 28, 2024This path traversal vulnerability in Sharp and Toshiba multifunction printers allows attackers to access arbitrary files on the affected devices by ma...
Nov 26, 2024The MP3 Sticky Player plugin for WordPress has a directory traversal vulnerability in the content/downloader.php file, allowing unauthenticated attack...
Nov 23, 2024This directory traversal vulnerability in Allegra's serveMathJaxLibraries method allows unauthenticated remote attackers to read arbitrary files on th...
Nov 22, 2024This CVE describes a path traversal vulnerability in the WordPress Bootscraper plugin, allowing attackers to include local PHP files via improper path...
Nov 20, 2024This vulnerability allows unauthenticated attackers to read arbitrary files on WordPress servers running the vulnerable PDF Generator Addon for Elemen...
Nov 16, 2024This path traversal vulnerability in the DigiPass WordPress plugin allows attackers to download arbitrary files from the server by manipulating file p...
Nov 14, 2024The LUNA RADIO PLAYER WordPress plugin contains a directory traversal vulnerability in its js/fallback.php file that allows unauthenticated attackers ...
Nov 13, 2024This vulnerability in Ollama allows attackers to discover which files exist on the server via path traversal in the api/push route. It affects all dep...
Oct 31, 2024This vulnerability allows authenticated users of ZimaOS to read arbitrary files on the system by manipulating the 'files' parameter in the API endpoin...
Oct 24, 2024Nginx UI v2.0.0-beta.35 and earlier contains a path traversal vulnerability that allows attackers to write arbitrary files to the server by manipulati...
Oct 21, 2024A path traversal vulnerability in binary-husky/gpt_academic version 3.83 allows attackers to read arbitrary files on the host system by manipulating t...
Oct 17, 2024This path traversal vulnerability in the SSV MailChimp WordPress plugin allows attackers to include local PHP files through improper path validation. ...
Oct 17, 2024This vulnerability allows attackers to perform path traversal attacks in the WordPress WPOptin plugin, enabling local file inclusion of PHP files. Att...
Oct 16, 2024This path traversal vulnerability in the MaxSlider WordPress plugin allows attackers to read arbitrary files on the server by manipulating file paths....
Oct 16, 2024SolarWinds Serv-U contains a directory traversal vulnerability that allows authenticated users to access files outside intended directories. When comb...
Oct 16, 2024SHIRASAGI CMS versions before 1.19.1 have a path traversal vulnerability that allows attackers to read arbitrary files on the server by sending specia...
Oct 15, 2024CVE-2024-47877 is a path traversal vulnerability in the Extract Go library that allows attackers to create symbolic links outside the intended extract...
Oct 11, 2024This path traversal vulnerability in the WP Timeline plugin allows attackers to include arbitrary PHP files from the server, potentially leading to re...
Oct 5, 2024This CVE describes a path traversal vulnerability in the Podiant WordPress plugin that allows attackers to include local PHP files through improper pa...
Oct 5, 2024This vulnerability allows attackers to read arbitrary files on the server through path traversal in the WP Ticket Ultra WordPress plugin. It affects a...
Oct 5, 2024This CVE describes a path traversal vulnerability in the VR Calendar WordPress plugin that allows attackers to include local PHP files via improper pa...
Oct 5, 2024An unauthenticated directory traversal vulnerability in Veertu Anka Build's archive functionality allows attackers to access sensitive files outside i...
Oct 3, 2024A path traversal vulnerability in E2Nest allows attackers to read arbitrary files on the server by manipulating file paths. This affects all E2Nest de...
Sep 27, 2024eNMS versions 4.4.0 through 4.7.1 contain a directory traversal vulnerability in the scan_folder function that allows attackers to read arbitrary file...
Sep 20, 2024CVE-2024-46645 is a directory traversal vulnerability in eNMS 4.0.0 that allows attackers to read arbitrary files on the server via the get_tree_files...
Sep 20, 2024CVE-2024-8752 is a directory traversal vulnerability in WebIQ 2.15.9 for Windows that allows remote attackers to read arbitrary files on the system. T...
Sep 16, 2024Spring applications using RouterFunctions to serve static resources with FileSystemResource locations are vulnerable to path traversal attacks. This a...
Sep 13, 2024This path traversal vulnerability in Vidco Software VOC TESTER allows attackers to access files outside the intended directory by manipulating file pa...
Sep 11, 2024CVE-2024-44867 is an arbitrary file read vulnerability in phpok v3.0 that allows attackers to read sensitive files on the server through the /autoload...
Sep 10, 2024SeaCMS v13.1 contains an arbitrary file read vulnerability in admin_safe.php that allows attackers to read sensitive files on the server. This affects...
Sep 9, 2024This path traversal vulnerability in DataFlowX Technology's DataDiodeX allows attackers to access files outside the intended directory by manipulating...
Sep 6, 2024A path traversal vulnerability in stripe-cli allows attackers to overwrite arbitrary files on the system when installing plugins with malformed shortn...
Sep 5, 2024This CVE describes a path traversal vulnerability in CentralSquare CryWolf's GeneralDocs.aspx file that allows unauthenticated attackers to read files...
Aug 26, 2024A path traversal vulnerability in OpenText CX-E Voice allows attackers to access arbitrary files on the system by manipulating file paths. This affect...
Aug 22, 2024This vulnerability allows attackers to perform directory traversal attacks through the downloader.php component in TOSEI online store management syste...
Aug 21, 2024This path traversal vulnerability in the Ultimate Bootstrap Elements for Elementor WordPress plugin allows attackers to include local PHP files throug...
Aug 13, 2024CVE-2024-42485 is a path traversal vulnerability in Filament Excel that allows unauthenticated attackers to download arbitrary files from the server v...
Aug 12, 2024About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 2,146 CVEs classified as CWE-22, with 506 rated critical and 1,098 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free