CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (2,182)
The BackWPup WordPress plugin up to version 4.0.1 contains a directory traversal vulnerability in the job-specific backup folder configuration. Authen...
Aug 17, 2024The Photo Gallery by 10Web WordPress plugin has a path traversal vulnerability in the esc_dir function that allows authenticated attackers to copy arb...
Jun 7, 2024OpenClaw versions 2026.1.12 through 2026.2.12 contain a path traversal vulnerability in browser download helpers that allows authenticated attackers t...
Feb 20, 2026This path traversal vulnerability in Dell iDRAC9 and iDRAC10 allows authenticated high-privilege attackers to access restricted directories. Attackers...
Nov 6, 2025A relative path traversal vulnerability in Samsung Knox Enterprise allows local attackers to execute arbitrary code by manipulating file paths. This a...
Oct 10, 2025A path traversal vulnerability in ONLYOFFICE Document Server allows remote attackers to copy arbitrary files by manipulating the fileExt parameter in ...
Apr 1, 2025Dell Inventory Collector versions before 12.3.0.6 contain a path traversal vulnerability that allows local authenticated users to write files to arbit...
Jul 31, 2024A path traversal vulnerability in Linksys MR9600 and MX4200 routers allows attackers to mount USB drive partitions to arbitrary file system locations....
Feb 24, 2026The CSV to SortTable WordPress plugin through version 4.2 contains a Local File Inclusion (LFI) vulnerability that allows authenticated users (includi...
Dec 9, 2025This vulnerability in the Developer Loggers for Simple History WordPress plugin allows authenticated attackers with Administrator-level access to perf...
Sep 17, 2025CVE-2025-0694 is a path traversal vulnerability in CODESYS Control that allows attackers with physical access and low privileges to bypass file system...
Mar 18, 2025A path traversal vulnerability in CRI-O's log management functions (UnMountPodLogs and LinkContainerLogs) allows attackers with Pod creation/deletion ...
Jan 28, 2025This CVE describes a path traversal vulnerability in the Cities Shipping Zones for WooCommerce WordPress plugin that allows attackers to include local...
Oct 5, 2024Appium's ZIP extraction function contains a path traversal vulnerability where malicious ZIP files can write files outside the intended destination di...
Mar 10, 2026This vulnerability in IBM webMethods API Gateway and API Management allows attackers to read arbitrary files on the server by manipulating the URL par...
Mar 3, 2026This vulnerability allows authenticated users in Traccar GPS tracking systems to write files outside the intended media directory by setting a device'...
Feb 23, 2026This path traversal vulnerability in Simple File List WordPress plugin allows attackers to download arbitrary files from the server by manipulating fi...
Feb 20, 2026This path traversal vulnerability in the Open User Map WordPress plugin allows attackers to download arbitrary files from the server by manipulating f...
Feb 20, 2026This vulnerability allows authenticated attackers to read arbitrary files on the system by manipulating a filepath parameter to access internal system...
Feb 20, 2026OpenClaw personal AI assistant versions before 2026.2.14 allow authenticated attackers to read arbitrary files from the Gateway host via path traversa...
Feb 20, 2026The WP-DownloadManager plugin for WordPress has a path traversal vulnerability that allows authenticated administrators to delete arbitrary files on t...
Feb 18, 2026Dell Avamar backup software versions before 19.12 with patch 338905 contain a path traversal vulnerability that allows authenticated high-privilege at...
Feb 17, 2026The Element Pack Addons for Elementor WordPress plugin contains an arbitrary file read vulnerability in its SVG widget. Authenticated attackers with c...
Feb 15, 2026A path traversal vulnerability in QNAP File Station 5 allows authenticated attackers to read arbitrary files on the system. This affects QNAP NAS devi...
Feb 11, 2026A path traversal vulnerability in Qsync Central allows authenticated attackers to read arbitrary files on the system. This affects all Qsync Central i...
Feb 11, 2026CVE-2026-25760 is an authenticated path traversal vulnerability in Sliver's website content subsystem that allows authenticated operators to read arbi...
Feb 6, 2026This vulnerability in Gogs allows attackers to read or write arbitrary files on the server through path traversal in Git hook editing functionality. A...
Feb 6, 2026OpenClaw versions before 2026.1.30 contain a path traversal vulnerability in the isValidMedia() function that allows reading arbitrary files on the sy...
Feb 4, 2026CVE-2026-24053 is a path traversal vulnerability in Claude Code that allows attackers to bypass directory restrictions and write files outside the cur...
Feb 3, 2026Webile 1.0.1 contains an unauthenticated directory traversal vulnerability that allows attackers to manipulate file paths and access sensitive system ...
Feb 1, 2026Free Photo & Video Vault 0.0.2 contains a directory traversal vulnerability that allows remote attackers to manipulate web requests and access sensiti...
Feb 1, 2026This vulnerability allows authenticated Umbraco backoffice users to perform path traversal attacks, enabling them to enumerate and read arbitrary file...
Jan 29, 2026A directory traversal vulnerability in 66biolinks v44.0.0 allows attackers to write files outside intended directories when uploading ZIP archives. Th...
Jan 28, 2026This path traversal vulnerability in SeaTheme BM Content Builder WordPress plugin allows attackers to download arbitrary files from the server by mani...
Jan 22, 2026This path traversal vulnerability in TMS Management Console allows authenticated users to read arbitrary files on the server by manipulating the fileP...
Jan 22, 2026Chainlit versions before 2.9.4 contain an arbitrary file read vulnerability where authenticated clients can manipulate element paths to copy server fi...
Jan 20, 2026This CVE describes a path traversal vulnerability in SiYuan's file copy endpoint that allows authenticated users to copy arbitrary files from the serv...
Jan 19, 2026This vulnerability allows authenticated attackers with Contributor-level WordPress access to read arbitrary files on the server through the Gutenberg ...
Jan 17, 2026A path traversal vulnerability in TOA Corporation TRIFORA 3 series network cameras allows authenticated users with monitoring privileges or higher to ...
Jan 16, 2026The Gotham Block Extra Light WordPress plugin contains an arbitrary file read vulnerability in all versions up to 1.5.0. Authenticated attackers with ...
Jan 14, 2026This path traversal vulnerability in Fortinet FortiVoice allows privileged attackers to delete arbitrary files from the underlying filesystem via craf...
Jan 13, 2026A path traversal vulnerability in Zen MCP Server allows authenticated attackers to read arbitrary files on the system by bypassing directory blacklist...
Jan 12, 2026This path traversal vulnerability in Broadcom DX NetOps Spectrum allows attackers to access files outside the intended directory by manipulating file ...
Jan 12, 2026This CVE describes a potential directory traversal vulnerability in CouchCMS 2.4 that could allow authenticated admin users to read arbitrary files on...
Jan 9, 2026Vivotek IP7137 cameras with firmware version 0200a are vulnerable to path traversal attacks, allowing authenticated attackers to access files outside ...
Jan 9, 2026This vulnerability allows authenticated REDAXO users with backup permissions to read arbitrary files within the webroot via path traversal in the Back...
Jan 7, 2026The Flashcard WordPress plugin contains a path traversal vulnerability that allows authenticated attackers with contributor-level access or higher to ...
Jan 7, 2026This path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files on the server by manipulating the 'edit-file' pa...
Dec 26, 2025This path traversal vulnerability in the AmentoTech Tuturn WordPress plugin allows attackers to download arbitrary files from the server by manipulati...
Dec 18, 2025This path traversal vulnerability in the MapSVG WordPress plugin allows attackers to download arbitrary files from the server by manipulating file pat...
Dec 18, 2025About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 2,182 CVEs classified as CWE-22, with 519 rated critical and 1,117 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free