CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,176
Total CVEs
517
Critical
1,113
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
245
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Fedoraproject 18
5 Solarwinds 17
6 Fortinet 17
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,176)

CVE-2024-9597
7.1

A path traversal vulnerability in parisneo/lollms v12 allows attackers to delete arbitrary directories on the system by exploiting improper validation...

Mar 20, 2025
CVE-2025-24019
7.1

This vulnerability in YesWiki allows any authenticated user to delete arbitrary files owned by the PHP-FPM process user, potentially leading to data l...

Jan 21, 2025
CVE-2024-21799
7.1

This path traversal vulnerability in Intel Extension for Transformers allows authenticated local users to access files outside intended directories, p...

Nov 13, 2024
CVE-2024-49760
7.1

OpenRefine versions before 3.8.3 contain a path traversal vulnerability in the load-language command that allows attackers to read arbitrary JSON file...

Oct 24, 2024
CVE-2024-45178
7.1

CVE-2024-45178 is a path traversal vulnerability in za-internet C-MOR Video Surveillance 5.2401 that allows authenticated attackers to download arbitr...

Sep 5, 2024
CVE-2024-38746
7.1

This path traversal vulnerability in the MakeStories WordPress plugin allows attackers to read arbitrary files on the server and perform server-side r...

Aug 1, 2024
CVE-2024-38717
7.1

This CVE describes a path traversal vulnerability in the Booking Ultra Pro WordPress plugin that allows attackers to include arbitrary local PHP files...

Jul 12, 2024
CVE-2024-35428
7.1

ZKTeco ZKBio CVSecurity 6.1.1 has a directory traversal vulnerability in the BaseMediaFile component that allows authenticated users to delete arbitra...

May 30, 2024
CVE-2023-46205
7.1

This vulnerability allows attackers to read arbitrary files on the server through path traversal in the Ultimate Addons for WPBakery Page Builder Word...

May 17, 2024
CVE-2023-25050
7.1

This path traversal vulnerability in the Shortcodes Ultimate WordPress plugin allows attackers to download arbitrary files from the server by manipula...

May 17, 2024
CVE-2024-31552
7.1

CVE-2024-31552 is an arbitrary file download vulnerability in CuteHttpFileServer v3.1 that allows attackers to download any file from the server files...

Apr 19, 2024
CVE-2024-27984
7.1

This path traversal vulnerability in Ivanti Avalanche's web component allows authenticated remote attackers to delete specific files or cause denial o...

Apr 19, 2024
CVE-2024-23216
7.1

This CVE describes a path traversal vulnerability in macOS that allows malicious applications to overwrite arbitrary files on the system. It affects m...

Mar 8, 2024
CVE-2024-25859
7.1

A path traversal vulnerability in Blesta's upload directory allows attackers to access files outside intended boundaries. This can lead to account tak...

Feb 28, 2024
CVE-2024-1163
7.1

CVE-2024-1163 is a path traversal vulnerability in mapshaper that allows attackers to access files outside the intended directory, potentially exposin...

Feb 13, 2024
CVE-2023-43802
7.1

This vulnerability allows local attackers or those who bypass CORS restrictions to execute arbitrary code with the privileges of the Arduino Create Ag...

Oct 18, 2023
CVE-2023-25303
7.1

CVE-2023-25303 is a directory traversal vulnerability in ATLauncher that allows attackers to create arbitrary files outside the installation directory...

Apr 4, 2023
CVE-2022-29094
7.1

This vulnerability allows authenticated non-admin users to delete or overwrite arbitrary files on systems running vulnerable versions of Dell SupportA...

Jun 10, 2022
CVE-2021-26619
7.1

CVE-2021-26619 is a path traversal vulnerability in BigFileAgent that allows remote attackers to delete arbitrary files on affected systems. This can ...

Feb 18, 2022
CVE-2021-3960
7.1

This path traversal vulnerability in Bitdefender GravityZone's UpdateServer component allows attackers to escape restricted directories and execute ar...

Dec 16, 2021
CVE-2021-41449
7.1

This vulnerability allows remote unauthenticated attackers to perform path traversal attacks on Netgear RAX35, RAX38, and RAX40 routers, enabling acce...

Dec 9, 2021
CVE-2021-36286
7.1

Dell SupportAssist Client Consumer versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability. Attackers can exploit NTFS symbolic li...

Sep 28, 2021
CVE-2021-20692
7.1

A directory traversal vulnerability in Archive collectively operation utility allows attackers to create or overwrite files anywhere on the system by ...

Apr 7, 2021
CVE-2021-27276
7.1

This vulnerability in NETGEAR ProSAFE Network Management System allows authenticated attackers to bypass authentication and delete arbitrary files via...

Mar 29, 2021
CVE-2021-23340
7.1

This CVE describes an authenticated Local File Inclusion vulnerability in Pimcore's CustomReportController. An authenticated user can exploit unsaniti...

Feb 18, 2021
CVE-2020-26405
7.1

This path traversal vulnerability in GitLab's package upload functionality allows authenticated attackers to save packages to arbitrary locations on t...

Nov 17, 2020
CVE-2025-13699
7.0

This vulnerability in MariaDB's mariadb-dump utility allows remote attackers to execute arbitrary code via directory traversal in view names. Attacker...

Dec 23, 2025
CVE-2023-5097
7.0

This vulnerability allows attackers to perform path traversal attacks on HYPR Workforce Access for Windows by exploiting improper input validation. It...

Jan 16, 2024
CVE-2023-38176
7.0

This vulnerability in Azure Arc-enabled servers allows authenticated attackers to elevate privileges to SYSTEM/root level on affected machines. It aff...

Aug 8, 2023
CVE-2023-2270
7.0

This vulnerability allows local users on Windows systems to write arbitrary files via a relative path vulnerability in the Netskope client service, wh...

Jun 15, 2023
CVE-2025-42946
6.9

This directory traversal vulnerability in SAP S/4HANA Bank Communication Management allows authenticated attackers with high privileges to access sens...

Aug 12, 2025
CVE-2026-21360
6.8

This path traversal vulnerability in Adobe Commerce allows high-privileged attackers to bypass security restrictions and access files or directories o...

Mar 11, 2026
CVE-2025-14728
6.8

CVE-2025-14728 is a directory traversal vulnerability in Rapid7 Velociraptor on Linux servers that allows rogue clients to write files outside the des...

Dec 29, 2025
CVE-2025-66302
6.8

Grav CMS versions before 1.8.0-beta.27 contain a path traversal vulnerability in the backup tool that allows authenticated administrators to read arbi...

Dec 1, 2025
CVE-2025-66206
6.8

This CVE describes a path traversal vulnerability in Frappe web framework that allows attackers to retrieve arbitrary files from the server if the ful...

Dec 1, 2025
CVE-2025-62449
6.8

This path traversal vulnerability in Visual Studio Code CoPilot Chat Extension allows an authorized local attacker to access files outside the intende...

Nov 11, 2025
CVE-2025-42894
6.8

This CVE describes a Path Traversal vulnerability in SAP Business Connector that allows authenticated administrators with adjacent access to manipulat...

Nov 11, 2025
CVE-2025-8023
6.8

This vulnerability allows system administrators in Mattermost to perform path traversal attacks by manipulating template file destination paths. Attac...

Aug 21, 2025
CVE-2025-36530
6.8

This vulnerability allows restricted admin users in Mattermost to install unauthorized custom plugins via path traversal during plugin imports. It byp...

Aug 21, 2025
CVE-2025-7694
6.8

The Woffice Core WordPress plugin allows authenticated attackers with Contributor-level access or higher to delete arbitrary server files due to insuf...

Aug 2, 2025
CVE-2025-6233
6.8

This vulnerability allows system administrators in Mattermost to read arbitrary files on the server through path traversal in bulk import JSONL files....

Jul 18, 2025
CVE-2025-31174
6.8

A path traversal vulnerability in the DFS module allows attackers to access files outside the intended directory. This affects Huawei products using t...

Apr 7, 2025
CVE-2025-23059
6.8

This vulnerability in HPE Aruba ClearPass Policy Manager allows authenticated high-privilege attackers to access sensitive directories through the web...

Feb 4, 2025
CVE-2024-56331
6.8

Uptime Kuma has an improper URL handling vulnerability that allows authenticated attackers to read sensitive local files on the server. By exploiting ...

Dec 20, 2024
CVE-2023-5505
6.8

The BackWPup WordPress plugin up to version 4.0.1 contains a directory traversal vulnerability in the job-specific backup folder configuration. Authen...

Aug 17, 2024
CVE-2024-5481
6.8

The Photo Gallery by 10Web WordPress plugin has a path traversal vulnerability in the esc_dir function that allows authenticated attackers to copy arb...

Jun 7, 2024
CVE-2026-26972
6.7

OpenClaw versions 2026.1.12 through 2026.2.12 contain a path traversal vulnerability in browser download helpers that allows authenticated attackers t...

Feb 20, 2026
CVE-2025-22397
6.7

This path traversal vulnerability in Dell iDRAC9 and iDRAC10 allows authenticated high-privilege attackers to access restricted directories. Attackers...

Nov 6, 2025
CVE-2025-21048
6.7

A relative path traversal vulnerability in Samsung Knox Enterprise allows local attackers to execute arbitrary code by manipulating file paths. This a...

Oct 10, 2025
CVE-2023-46988
6.7

A path traversal vulnerability in ONLYOFFICE Document Server allows remote attackers to copy arbitrary files by manipulating the fileExt parameter in ...

Apr 1, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,176 CVEs classified as CWE-22, with 517 rated critical and 1,113 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free