CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (2,176)
A path traversal vulnerability in parisneo/lollms v12 allows attackers to delete arbitrary directories on the system by exploiting improper validation...
Mar 20, 2025This vulnerability in YesWiki allows any authenticated user to delete arbitrary files owned by the PHP-FPM process user, potentially leading to data l...
Jan 21, 2025This path traversal vulnerability in Intel Extension for Transformers allows authenticated local users to access files outside intended directories, p...
Nov 13, 2024OpenRefine versions before 3.8.3 contain a path traversal vulnerability in the load-language command that allows attackers to read arbitrary JSON file...
Oct 24, 2024CVE-2024-45178 is a path traversal vulnerability in za-internet C-MOR Video Surveillance 5.2401 that allows authenticated attackers to download arbitr...
Sep 5, 2024This path traversal vulnerability in the MakeStories WordPress plugin allows attackers to read arbitrary files on the server and perform server-side r...
Aug 1, 2024This CVE describes a path traversal vulnerability in the Booking Ultra Pro WordPress plugin that allows attackers to include arbitrary local PHP files...
Jul 12, 2024ZKTeco ZKBio CVSecurity 6.1.1 has a directory traversal vulnerability in the BaseMediaFile component that allows authenticated users to delete arbitra...
May 30, 2024This vulnerability allows attackers to read arbitrary files on the server through path traversal in the Ultimate Addons for WPBakery Page Builder Word...
May 17, 2024This path traversal vulnerability in the Shortcodes Ultimate WordPress plugin allows attackers to download arbitrary files from the server by manipula...
May 17, 2024CVE-2024-31552 is an arbitrary file download vulnerability in CuteHttpFileServer v3.1 that allows attackers to download any file from the server files...
Apr 19, 2024This path traversal vulnerability in Ivanti Avalanche's web component allows authenticated remote attackers to delete specific files or cause denial o...
Apr 19, 2024This CVE describes a path traversal vulnerability in macOS that allows malicious applications to overwrite arbitrary files on the system. It affects m...
Mar 8, 2024A path traversal vulnerability in Blesta's upload directory allows attackers to access files outside intended boundaries. This can lead to account tak...
Feb 28, 2024CVE-2024-1163 is a path traversal vulnerability in mapshaper that allows attackers to access files outside the intended directory, potentially exposin...
Feb 13, 2024This vulnerability allows local attackers or those who bypass CORS restrictions to execute arbitrary code with the privileges of the Arduino Create Ag...
Oct 18, 2023CVE-2023-25303 is a directory traversal vulnerability in ATLauncher that allows attackers to create arbitrary files outside the installation directory...
Apr 4, 2023This vulnerability allows authenticated non-admin users to delete or overwrite arbitrary files on systems running vulnerable versions of Dell SupportA...
Jun 10, 2022CVE-2021-26619 is a path traversal vulnerability in BigFileAgent that allows remote attackers to delete arbitrary files on affected systems. This can ...
Feb 18, 2022This path traversal vulnerability in Bitdefender GravityZone's UpdateServer component allows attackers to escape restricted directories and execute ar...
Dec 16, 2021This vulnerability allows remote unauthenticated attackers to perform path traversal attacks on Netgear RAX35, RAX38, and RAX40 routers, enabling acce...
Dec 9, 2021Dell SupportAssist Client Consumer versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability. Attackers can exploit NTFS symbolic li...
Sep 28, 2021A directory traversal vulnerability in Archive collectively operation utility allows attackers to create or overwrite files anywhere on the system by ...
Apr 7, 2021This vulnerability in NETGEAR ProSAFE Network Management System allows authenticated attackers to bypass authentication and delete arbitrary files via...
Mar 29, 2021This CVE describes an authenticated Local File Inclusion vulnerability in Pimcore's CustomReportController. An authenticated user can exploit unsaniti...
Feb 18, 2021This path traversal vulnerability in GitLab's package upload functionality allows authenticated attackers to save packages to arbitrary locations on t...
Nov 17, 2020This vulnerability in MariaDB's mariadb-dump utility allows remote attackers to execute arbitrary code via directory traversal in view names. Attacker...
Dec 23, 2025This vulnerability allows attackers to perform path traversal attacks on HYPR Workforce Access for Windows by exploiting improper input validation. It...
Jan 16, 2024This vulnerability in Azure Arc-enabled servers allows authenticated attackers to elevate privileges to SYSTEM/root level on affected machines. It aff...
Aug 8, 2023This vulnerability allows local users on Windows systems to write arbitrary files via a relative path vulnerability in the Netskope client service, wh...
Jun 15, 2023This directory traversal vulnerability in SAP S/4HANA Bank Communication Management allows authenticated attackers with high privileges to access sens...
Aug 12, 2025This path traversal vulnerability in Adobe Commerce allows high-privileged attackers to bypass security restrictions and access files or directories o...
Mar 11, 2026CVE-2025-14728 is a directory traversal vulnerability in Rapid7 Velociraptor on Linux servers that allows rogue clients to write files outside the des...
Dec 29, 2025Grav CMS versions before 1.8.0-beta.27 contain a path traversal vulnerability in the backup tool that allows authenticated administrators to read arbi...
Dec 1, 2025This CVE describes a path traversal vulnerability in Frappe web framework that allows attackers to retrieve arbitrary files from the server if the ful...
Dec 1, 2025This path traversal vulnerability in Visual Studio Code CoPilot Chat Extension allows an authorized local attacker to access files outside the intende...
Nov 11, 2025This CVE describes a Path Traversal vulnerability in SAP Business Connector that allows authenticated administrators with adjacent access to manipulat...
Nov 11, 2025This vulnerability allows system administrators in Mattermost to perform path traversal attacks by manipulating template file destination paths. Attac...
Aug 21, 2025This vulnerability allows restricted admin users in Mattermost to install unauthorized custom plugins via path traversal during plugin imports. It byp...
Aug 21, 2025The Woffice Core WordPress plugin allows authenticated attackers with Contributor-level access or higher to delete arbitrary server files due to insuf...
Aug 2, 2025This vulnerability allows system administrators in Mattermost to read arbitrary files on the server through path traversal in bulk import JSONL files....
Jul 18, 2025A path traversal vulnerability in the DFS module allows attackers to access files outside the intended directory. This affects Huawei products using t...
Apr 7, 2025This vulnerability in HPE Aruba ClearPass Policy Manager allows authenticated high-privilege attackers to access sensitive directories through the web...
Feb 4, 2025Uptime Kuma has an improper URL handling vulnerability that allows authenticated attackers to read sensitive local files on the server. By exploiting ...
Dec 20, 2024The BackWPup WordPress plugin up to version 4.0.1 contains a directory traversal vulnerability in the job-specific backup folder configuration. Authen...
Aug 17, 2024The Photo Gallery by 10Web WordPress plugin has a path traversal vulnerability in the esc_dir function that allows authenticated attackers to copy arb...
Jun 7, 2024OpenClaw versions 2026.1.12 through 2026.2.12 contain a path traversal vulnerability in browser download helpers that allows authenticated attackers t...
Feb 20, 2026This path traversal vulnerability in Dell iDRAC9 and iDRAC10 allows authenticated high-privilege attackers to access restricted directories. Attackers...
Nov 6, 2025A relative path traversal vulnerability in Samsung Knox Enterprise allows local attackers to execute arbitrary code by manipulating file paths. This a...
Oct 10, 2025A path traversal vulnerability in ONLYOFFICE Document Server allows remote attackers to copy arbitrary files by manipulating the fileExt parameter in ...
Apr 1, 2025About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 2,176 CVEs classified as CWE-22, with 517 rated critical and 1,113 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free