CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,165
Total CVEs
515
Critical
1,104
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
244
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Solarwinds 17
5 Fortinet 17
6 Fedoraproject 17
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,165)

CVE-2024-34656
7.3

A path traversal vulnerability in Samsung Notes allows local attackers to execute arbitrary code by manipulating file paths. This affects Samsung Note...

Sep 4, 2024
CVE-2024-7927
7.3

This critical vulnerability in ZZCMS 2023 allows remote attackers to perform path traversal attacks via the skin[] parameter in /admin/class.php?dowha...

Aug 19, 2024
CVE-2024-2602
7.3

This CVE describes a path traversal vulnerability (CWE-22) in Schneider Electric software that allows authenticated users to execute malicious code by...

Jul 11, 2024
CVE-2024-32465
7.3

This CVE describes a vulnerability in Git that allows attackers to bypass security protections when cloning repositories from untrusted sources. Speci...

May 14, 2024
CVE-2023-41973
7.3

This vulnerability in Zscaler Client Connector (ZSATray) allows path traversal attacks by improperly validating the 'previousInstallerName' parameter....

Mar 26, 2024
CVE-2023-24592
7.3

This path traversal vulnerability in Intel oneAPI Toolkits allows authenticated users with local access to potentially escalate privileges by manipula...

Nov 14, 2023
CVE-2021-32840
7.3

SharpZipLib versions before 1.3.3 contain a path traversal vulnerability in TAR file extraction. Attackers can craft malicious TAR archives with '../'...

Jan 26, 2022
CVE-2021-41127
7.3

CVE-2021-41127 is a path traversal vulnerability in Rasa's model loading functionality that allows attackers to overwrite or replace bot files by craf...

Oct 21, 2021
CVE-2021-23391
7.3

CVE-2021-23391 is a path traversal vulnerability in the Calipso package that allows malicious modules to overwrite arbitrary files during installation...

Jun 7, 2021
CVE-2020-3588
7.3

A local privilege escalation vulnerability in Cisco Webex Meetings Desktop App for Windows allows attackers to execute arbitrary code when deployed in...

Nov 6, 2020
CVE-2026-30958
7.2

CVE-2026-30958 is an unauthenticated path traversal vulnerability in OneUptime's workflow documentation endpoint that allows attackers to read arbitra...

Mar 10, 2026
CVE-2025-14675
7.2

The Meta Box WordPress plugin has an arbitrary file deletion vulnerability that allows authenticated attackers with Contributor-level access or higher...

Mar 7, 2026
CVE-2026-27819
7.2

This vulnerability in Vikunja allows attackers to overwrite arbitrary files on the host system by uploading a malicious ZIP archive during configurati...

Feb 25, 2026
CVE-2026-25951
7.2

CVE-2026-25951 is a path traversal vulnerability in FUXA web-based SCADA/HMI software that allows authenticated administrators to bypass directory pro...

Feb 9, 2026
CVE-2025-67684
7.2

Quick.Cart e-commerce software contains a Local File Inclusion and Path Traversal vulnerability in its theme selection mechanism. This allows authenti...

Jan 22, 2026
CVE-2022-50939
7.2

CVE-2022-50939 is a critical file upload vulnerability in e107 CMS version 3.2.1 that allows authenticated administrators to overwrite arbitrary serve...

Jan 13, 2026
CVE-2025-65074
7.2

This vulnerability allows high-privileged attackers to execute arbitrary operating system commands on WaveStore Server through path traversal in the s...

Dec 16, 2025
CVE-2025-67818
7.2

This vulnerability allows attackers with database write access to craft malicious entry names containing absolute paths or directory traversal sequenc...

Dec 12, 2025
CVE-2025-29846
7.2

This vulnerability in Synology's portenable CGI allows authenticated remote users to query the status of installed packages. This information disclosu...

Dec 4, 2025
CVE-2025-13645
7.2

The Modula Image Gallery WordPress plugin versions 2.13.1 to 2.13.2 contain an arbitrary file deletion vulnerability due to insufficient file path val...

Dec 3, 2025
CVE-2025-61941
7.2

A path traversal vulnerability in WXR9300BE6P series firmware allows authenticated administrative users to alter arbitrary files, potentially leading ...

Oct 15, 2025
CVE-2025-10176
7.2

This vulnerability allows authenticated WordPress administrators to delete arbitrary files on the server due to insufficient path validation in the Ha...

Sep 12, 2025
CVE-2025-54926
7.2

This path traversal vulnerability allows authenticated administrators to upload malicious files that can be executed remotely, leading to remote code ...

Aug 20, 2025
CVE-2025-46359
7.2

A path traversal vulnerability in PowerCMS backup/restore feature allows product administrators to execute arbitrary code by restoring malicious backu...

Jul 31, 2025
CVE-2025-54450
7.2

This path traversal vulnerability in Samsung MagicINFO 9 Server allows attackers to escape restricted directories and inject malicious code. It affect...

Jul 23, 2025
CVE-2025-6265
7.2

This path traversal vulnerability in Zyxel NWA50AX PRO access points allows authenticated administrators to delete critical files like configuration f...

Jul 15, 2025
CVE-2025-34076
EPSS 21.3% 7.2

An authenticated local file inclusion vulnerability in Microweber CMS allows authenticated users to read arbitrary files from the filesystem. Attacker...

Jul 2, 2025
CVE-2025-23092
7.2

This vulnerability allows authenticated administrators in Mitel OpenScape Accounting Management to conduct path traversal attacks due to insufficient ...

Jun 23, 2025
CVE-2025-5740
7.2

This path traversal vulnerability allows authenticated users on a web server to write arbitrary files by manipulating file paths. It affects Schneider...

Jun 10, 2025
CVE-2025-48940
7.2

This vulnerability in MyBB forum software allows attackers to perform local file inclusion (LFI) through improper input validation in the upgrade comp...

Jun 2, 2025
CVE-2025-4857
7.2

The Newsletters plugin for WordPress contains a Local File Inclusion vulnerability that allows authenticated attackers with Administrator privileges t...

May 31, 2025
CVE-2024-13914
7.2

This vulnerability allows authenticated WordPress administrators to perform Local File Inclusion attacks via the File Manager Advanced Shortcode plugi...

May 15, 2025
CVE-2025-3300
7.2

The WPMasterToolKit WordPress plugin contains a directory traversal vulnerability that allows authenticated attackers with Administrator privileges to...

Apr 24, 2025
CVE-2025-3294
7.2

The WP Editor WordPress plugin allows authenticated attackers with Administrator privileges to overwrite arbitrary files on the server due to missing ...

Apr 17, 2025
CVE-2025-2749
7.2

This vulnerability allows authenticated users of Kentico Xperience's Staging Sync Server to upload arbitrary files to path-relative locations via path...

Mar 24, 2025
CVE-2024-7034
7.2

CVE-2024-7034 allows attackers to write arbitrary files on systems running vulnerable open-webui versions by exploiting directory traversal in file up...

Mar 20, 2025
CVE-2025-27395
7.2

This vulnerability in Siemens SCALANCE LPE9403 industrial routers allows authenticated high-privilege attackers to read and write arbitrary files via ...

Mar 11, 2025
CVE-2025-24494
7.2

This path traversal vulnerability in Ixia/IxNetwork products allows device administrators to upload malicious files to arbitrary locations, potentiall...

Mar 5, 2025
CVE-2024-13910
7.2

This vulnerability allows authenticated WordPress administrators to delete arbitrary files on the server due to insufficient path validation in the Da...

Mar 1, 2025
CVE-2024-13158
EPSS 39.2% 7.2

This vulnerability allows remote authenticated attackers with admin privileges to execute arbitrary code on Ivanti EPM systems by exploiting an unboun...

Jan 14, 2025
CVE-2024-36512
7.2

This path traversal vulnerability in Fortinet FortiManager and FortiAnalyzer allows attackers to execute arbitrary code or commands via specially craf...

Jan 14, 2025
CVE-2024-44030
7.2

This vulnerability allows attackers to perform path traversal attacks in the Checkout Mestres WP WordPress plugin, potentially leading to local file i...

Oct 2, 2024
CVE-2024-25659
7.2

Infinera TNMS 19.10.3 has an insecure default SFTP server configuration that allows attackers to traverse outside the designated user home directory. ...

Oct 1, 2024
CVE-2023-26691
7.2

This vulnerability allows remote attackers to execute arbitrary code on CS-Cart MultiVendor systems through directory traversal in zip file handling d...

Sep 25, 2024
CVE-2024-42501
7.2

An authenticated path traversal vulnerability in ArubaOS allows attackers to install unsigned packages on the underlying operating system. This enable...

Sep 17, 2024
CVE-2024-38878
7.2

This vulnerability allows authenticated users to exploit a path traversal flaw in the diagnostics data export API endpoint. Attackers can download arb...

Aug 2, 2024
CVE-2024-27178
7.2

This CVE-2024-27178 vulnerability in ToshibaTec products allows attackers to achieve remote code execution by exploiting a path traversal weakness to ...

Jun 14, 2024
CVE-2024-27176
7.2

This vulnerability allows attackers to achieve remote code execution by overwriting files through session ID manipulation. It primarily affects Toshib...

Jun 14, 2024
CVE-2023-41877
7.2

This CVE describes a path traversal vulnerability in GeoServer that allows administrators with access to the admin console to misconfigure log file lo...

Mar 20, 2024
CVE-2024-27081
7.2

This vulnerability in ESPHome's dashboard component allows authenticated attackers to read and write arbitrary files within the configuration director...

Feb 26, 2024

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,165 CVEs classified as CWE-22, with 515 rated critical and 1,104 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free