CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,146
Total CVEs
506
Critical
1,098
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
236
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Solarwinds 17
5 Fedoraproject 17
6 Fortinet 16
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,146)

CVE-2024-12152
7.5

The MIPL WC Multisite Sync WordPress plugin contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files...

Jan 7, 2025
CVE-2024-12849
EPSS 92.6% 7.5

The Error Log Viewer By WP Guru WordPress plugin contains an unauthenticated arbitrary file read vulnerability. Attackers can exploit this to read any...

Jan 7, 2025
CVE-2024-54453
7.5

A path traversal vulnerability in Kurmi Provisioning Suite's DocServlet servlet allows remote attackers to read any file from the web application inst...

Dec 27, 2024
CVE-2024-38819
7.5

Spring applications using WebMvc.fn or WebFlux.fn functional web frameworks to serve static resources are vulnerable to path traversal attacks. Attack...

Dec 19, 2024
CVE-2024-54380
7.5

This path traversal vulnerability in the WP Cookies Enabler WordPress plugin allows attackers to include local PHP files via directory traversal seque...

Dec 16, 2024
CVE-2024-54374
7.5

This CVE describes a path traversal vulnerability in the Sogrid WordPress plugin that allows attackers to include local PHP files via improper pathnam...

Dec 16, 2024
CVE-2024-55970
7.5

This vulnerability allows attackers to perform directory traversal attacks in Syncfusion Essential Studio for ASP.NET MVC's File Manager component. By...

Dec 15, 2024
CVE-2024-55657
7.5

CVE-2024-55657 is an arbitrary file read vulnerability in SiYuan personal knowledge management systems. Attackers can exploit the unvalidated path par...

Dec 12, 2024
CVE-2024-53790
7.5

This path traversal vulnerability in Lenxel Core for Lenxel(LNX) LMS allows attackers to read arbitrary files on the server by manipulating file paths...

Dec 9, 2024
CVE-2024-11585
7.5

The WP Hide & Security Enhancer WordPress plugin has a vulnerability that allows unauthenticated attackers to delete arbitrary files on the server due...

Dec 6, 2024
CVE-2024-53490
7.5

Favorites-web 1.3.0 has a directory traversal vulnerability in SecurityFilter.java that allows attackers to access files outside the intended director...

Dec 5, 2024
CVE-2024-11952
7.5

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to include and execute arbitrary PHP files on Windows ...

Dec 4, 2024
CVE-2024-52481
7.5

This path traversal vulnerability in the Jobify WordPress theme allows unauthenticated attackers to read arbitrary files on the server by manipulating...

Nov 28, 2024
CVE-2024-33605
7.5

This path traversal vulnerability in Sharp and Toshiba multifunction printers allows attackers to access arbitrary files on the affected devices by ma...

Nov 26, 2024
CVE-2024-10803
7.5

The MP3 Sticky Player plugin for WordPress has a directory traversal vulnerability in the content/downloader.php file, allowing unauthenticated attack...

Nov 23, 2024
CVE-2023-52332
7.5

This directory traversal vulnerability in Allegra's serveMathJaxLibraries method allows unauthenticated remote attackers to read arbitrary files on th...

Nov 22, 2024
CVE-2024-52449
7.5

This CVE describes a path traversal vulnerability in the WordPress Bootscraper plugin, allowing attackers to include local PHP files via improper path...

Nov 20, 2024
CVE-2024-9935
7.5

This vulnerability allows unauthenticated attackers to read arbitrary files on WordPress servers running the vulnerable PDF Generator Addon for Elemen...

Nov 16, 2024
CVE-2024-52378
7.5

This path traversal vulnerability in the DigiPass WordPress plugin allows attackers to download arbitrary files from the server by manipulating file p...

Nov 14, 2024
CVE-2024-10816
7.5

The LUNA RADIO PLAYER WordPress plugin contains a directory traversal vulnerability in its js/fallback.php file that allows unauthenticated attackers ...

Nov 13, 2024
CVE-2024-39722
7.5

This vulnerability in Ollama allows attackers to discover which files exist on the server via path traversal in the api/push route. It affects all dep...

Oct 31, 2024
CVE-2024-48931
7.5

This vulnerability allows authenticated users of ZimaOS to read arbitrary files on the system by manipulating the 'files' parameter in the API endpoin...

Oct 24, 2024
CVE-2024-49366
7.5

Nginx UI v2.0.0-beta.35 and earlier contains a path traversal vulnerability that allows attackers to write arbitrary files to the server by manipulati...

Oct 21, 2024
CVE-2024-10100
7.5

A path traversal vulnerability in binary-husky/gpt_academic version 3.83 allows attackers to read arbitrary files on the host system by manipulating t...

Oct 17, 2024
CVE-2024-49285
7.5

This path traversal vulnerability in the SSV MailChimp WordPress plugin allows attackers to include local PHP files through improper path validation. ...

Oct 17, 2024
CVE-2024-47645
7.5

This vulnerability allows attackers to perform path traversal attacks in the WordPress WPOptin plugin, enabling local file inclusion of PHP files. Att...

Oct 16, 2024
CVE-2024-47351
7.5

This path traversal vulnerability in the MaxSlider WordPress plugin allows attackers to read arbitrary files on the server by manipulating file paths....

Oct 16, 2024
CVE-2024-45711
7.5

SolarWinds Serv-U contains a directory traversal vulnerability that allows authenticated users to access files outside intended directories. When comb...

Oct 16, 2024
CVE-2024-46898
7.5

SHIRASAGI CMS versions before 1.19.1 have a path traversal vulnerability that allows attackers to read arbitrary files on the server by sending specia...

Oct 15, 2024
CVE-2024-47877
7.5

CVE-2024-47877 is a path traversal vulnerability in the Extract Go library that allows attackers to create symbolic links outside the intended extract...

Oct 11, 2024
CVE-2024-47324
7.5

This path traversal vulnerability in the WP Timeline plugin allows attackers to include arbitrary PHP files from the server, potentially leading to re...

Oct 5, 2024
CVE-2024-44016
7.5

This CVE describes a path traversal vulnerability in the Podiant WordPress plugin that allows attackers to include local PHP files through improper pa...

Oct 5, 2024
CVE-2024-44011
7.5

This vulnerability allows attackers to read arbitrary files on the server through path traversal in the WP Ticket Ultra WordPress plugin. It affects a...

Oct 5, 2024
CVE-2024-44013
7.5

This CVE describes a path traversal vulnerability in the VR Calendar WordPress plugin that allows attackers to include local PHP files via improper pa...

Oct 5, 2024
CVE-2024-41163
7.5

An unauthenticated directory traversal vulnerability in Veertu Anka Build's archive functionality allows attackers to access sensitive files outside i...

Oct 3, 2024
CVE-2024-9301
7.5

A path traversal vulnerability in E2Nest allows attackers to read arbitrary files on the server by manipulating file paths. This affects all E2Nest de...

Sep 27, 2024
CVE-2024-46648
7.5

eNMS versions 4.4.0 through 4.7.1 contain a directory traversal vulnerability in the scan_folder function that allows attackers to read arbitrary file...

Sep 20, 2024
CVE-2024-46645
7.5

CVE-2024-46645 is a directory traversal vulnerability in eNMS 4.0.0 that allows attackers to read arbitrary files on the server via the get_tree_files...

Sep 20, 2024
CVE-2024-8752
7.5

CVE-2024-8752 is a directory traversal vulnerability in WebIQ 2.15.9 for Windows that allows remote attackers to read arbitrary files on the system. T...

Sep 16, 2024
CVE-2024-38816
7.5

Spring applications using RouterFunctions to serve static resources with FileSystemResource locations are vulnerable to path traversal attacks. This a...

Sep 13, 2024
CVE-2024-7609
7.5

This path traversal vulnerability in Vidco Software VOC TESTER allows attackers to access files outside the intended directory by manipulating file pa...

Sep 11, 2024
CVE-2024-44867
7.5

CVE-2024-44867 is an arbitrary file read vulnerability in phpok v3.0 that allows attackers to read sensitive files on the server through the /autoload...

Sep 10, 2024
CVE-2024-44720
7.5

SeaCMS v13.1 contains an arbitrary file read vulnerability in admin_safe.php that allows attackers to read sensitive files on the server. This affects...

Sep 9, 2024
CVE-2024-6445
7.5

This path traversal vulnerability in DataFlowX Technology's DataDiodeX allows attackers to access files outside the intended directory by manipulating...

Sep 6, 2024
CVE-2024-45401
7.5

A path traversal vulnerability in stripe-cli allows attackers to overwrite arbitrary files on the system when installing plugins with malformed shortn...

Sep 5, 2024
CVE-2024-45241
7.5

This CVE describes a path traversal vulnerability in CentralSquare CryWolf's GeneralDocs.aspx file that allows unauthenticated attackers to read files...

Aug 26, 2024
CVE-2023-7260
7.5

A path traversal vulnerability in OpenText CX-E Voice allows attackers to access arbitrary files on the system by manipulating file paths. This affect...

Aug 22, 2024
CVE-2024-43022
7.5

This vulnerability allows attackers to perform directory traversal attacks through the downloader.php component in TOSEI online store management syste...

Aug 21, 2024
CVE-2024-43140
7.5

This path traversal vulnerability in the Ultimate Bootstrap Elements for Elementor WordPress plugin allows attackers to include local PHP files throug...

Aug 13, 2024
CVE-2024-42485
7.5

CVE-2024-42485 is a path traversal vulnerability in Filament Excel that allows unauthenticated attackers to download arbitrary files from the server v...

Aug 12, 2024

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,146 CVEs classified as CWE-22, with 506 rated critical and 1,098 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free