CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,182
Total CVEs
519
Critical
1,117
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
245
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Fedoraproject 18
5 Solarwinds 17
6 Fortinet 17
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,182)

CVE-2023-5505
6.8

The BackWPup WordPress plugin up to version 4.0.1 contains a directory traversal vulnerability in the job-specific backup folder configuration. Authen...

Aug 17, 2024
CVE-2024-5481
6.8

The Photo Gallery by 10Web WordPress plugin has a path traversal vulnerability in the esc_dir function that allows authenticated attackers to copy arb...

Jun 7, 2024
CVE-2026-26972
6.7

OpenClaw versions 2026.1.12 through 2026.2.12 contain a path traversal vulnerability in browser download helpers that allows authenticated attackers t...

Feb 20, 2026
CVE-2025-22397
6.7

This path traversal vulnerability in Dell iDRAC9 and iDRAC10 allows authenticated high-privilege attackers to access restricted directories. Attackers...

Nov 6, 2025
CVE-2025-21048
6.7

A relative path traversal vulnerability in Samsung Knox Enterprise allows local attackers to execute arbitrary code by manipulating file paths. This a...

Oct 10, 2025
CVE-2023-46988
6.7

A path traversal vulnerability in ONLYOFFICE Document Server allows remote attackers to copy arbitrary files by manipulating the fileExt parameter in ...

Apr 1, 2025
CVE-2024-37129
6.7

Dell Inventory Collector versions before 12.3.0.6 contain a path traversal vulnerability that allows local authenticated users to write files to arbit...

Jul 31, 2024
CVE-2026-25603
6.6

A path traversal vulnerability in Linksys MR9600 and MX4200 routers allows attackers to mount USB drive partitions to arbitrary file system locations....

Feb 24, 2026
CVE-2025-13070
6.6

The CSV to SortTable WordPress plugin through version 4.2 contains a Local File Inclusion (LFI) vulnerability that allows authenticated users (includi...

Dec 9, 2025
CVE-2025-10050
6.6

This vulnerability in the Developer Loggers for Simple History WordPress plugin allows authenticated attackers with Administrator-level access to perf...

Sep 17, 2025
CVE-2025-0694
6.6

CVE-2025-0694 is a path traversal vulnerability in CODESYS Control that allows attackers with physical access and low privileges to bypass file system...

Mar 18, 2025
CVE-2025-0750
6.6

A path traversal vulnerability in CRI-O's log management functions (UnMountPodLogs and LinkContainerLogs) allows attackers with Pod creation/deletion ...

Jan 28, 2025
CVE-2024-47309
6.6

This CVE describes a path traversal vulnerability in the Cities Shipping Zones for WooCommerce WordPress plugin that allows attackers to include local...

Oct 5, 2024
CVE-2026-30973
6.5

Appium's ZIP extraction function contains a path traversal vulnerability where malicious ZIP files can write files outside the intended destination di...

Mar 10, 2026
CVE-2026-2606
6.5

This vulnerability in IBM webMethods API Gateway and API Management allows attackers to read arbitrary files on the server by manipulating the URL par...

Mar 3, 2026
CVE-2026-23521
6.5

This vulnerability allows authenticated users in Traccar GPS tracking systems to write files outside the intended media directory by setting a device'...

Feb 23, 2026
CVE-2026-24953
6.5

This path traversal vulnerability in Simple File List WordPress plugin allows attackers to download arbitrary files from the server by manipulating fi...

Feb 20, 2026
CVE-2025-68002
6.5

This path traversal vulnerability in the Open User Map WordPress plugin allows attackers to download arbitrary files from the server by manipulating f...

Feb 20, 2026
CVE-2025-59819
6.5

This vulnerability allows authenticated attackers to read arbitrary files on the system by manipulating a filepath parameter to access internal system...

Feb 20, 2026
CVE-2026-26329
6.5

OpenClaw personal AI assistant versions before 2026.2.14 allow authenticated attackers to read arbitrary files from the Gateway host via path traversa...

Feb 20, 2026
CVE-2026-2426
6.5

The WP-DownloadManager plugin for WordPress has a path traversal vulnerability that allows authenticated administrators to delete arbitrary files on t...

Feb 18, 2026
CVE-2025-36598
6.5

Dell Avamar backup software versions before 19.12 with patch 338905 contain a path traversal vulnerability that allows authenticated high-privilege at...

Feb 17, 2026
CVE-2026-1793
6.5

The Element Pack Addons for Elementor WordPress plugin contains an arbitrary file read vulnerability in its SVG widget. Authenticated attackers with c...

Feb 15, 2026
CVE-2025-66278
6.5

A path traversal vulnerability in QNAP File Station 5 allows authenticated attackers to read arbitrary files on the system. This affects QNAP NAS devi...

Feb 11, 2026
CVE-2025-58470
6.5

A path traversal vulnerability in Qsync Central allows authenticated attackers to read arbitrary files on the system. This affects all Qsync Central i...

Feb 11, 2026
CVE-2026-25760
6.5

CVE-2026-25760 is an authenticated path traversal vulnerability in Sliver's website content subsystem that allows authenticated operators to read arbi...

Feb 6, 2026
CVE-2026-23633
6.5

This vulnerability in Gogs allows attackers to read or write arbitrary files on the server through path traversal in Git hook editing functionality. A...

Feb 6, 2026
CVE-2026-25475
6.5

OpenClaw versions before 2026.1.30 contain a path traversal vulnerability in the isValidMedia() function that allows reading arbitrary files on the sy...

Feb 4, 2026
CVE-2026-24053
6.5

CVE-2026-24053 is a path traversal vulnerability in Claude Code that allows attackers to bypass directory restrictions and write files outside the cur...

Feb 3, 2026
CVE-2022-50950
6.5

Webile 1.0.1 contains an unauthenticated directory traversal vulnerability that allows attackers to manipulate file paths and access sensitive system ...

Feb 1, 2026
CVE-2021-47921
6.5

Free Photo & Video Vault 0.0.2 contains a directory traversal vulnerability that allows remote attackers to manipulate web requests and access sensiti...

Feb 1, 2026
CVE-2026-24687
6.5

This vulnerability allows authenticated Umbraco backoffice users to perform path traversal attacks, enabling them to enumerate and read arbitrary file...

Jan 29, 2026
CVE-2025-69601
6.5

A directory traversal vulnerability in 66biolinks v44.0.0 allows attackers to write files outside intended directories when uploading ZIP archives. Th...

Jan 28, 2026
CVE-2025-69055
6.5

This path traversal vulnerability in SeaTheme BM Content Builder WordPress plugin allows attackers to download arbitrary files from the server by mani...

Jan 22, 2026
CVE-2025-69612
6.5

This path traversal vulnerability in TMS Management Console allows authenticated users to read arbitrary files on the server by manipulating the fileP...

Jan 22, 2026
CVE-2026-22218
6.5

Chainlit versions before 2.9.4 contain an arbitrary file read vulnerability where authenticated clients can manipulate element paths to copy server fi...

Jan 20, 2026
CVE-2026-23851
6.5

This CVE describes a path traversal vulnerability in SiYuan's file copy endpoint that allows authenticated users to copy arbitrary files from the serv...

Jan 19, 2026
CVE-2025-13725
6.5

This vulnerability allows authenticated attackers with Contributor-level WordPress access to read arbitrary files on the server through the Gutenberg ...

Jan 17, 2026
CVE-2026-22876
6.5

A path traversal vulnerability in TOA Corporation TRIFORA 3 series network cameras allows authenticated users with monitoring privileges or higher to ...

Jan 16, 2026
CVE-2025-15020
6.5

The Gotham Block Extra Light WordPress plugin contains an arbitrary file read vulnerability in all versions up to 1.5.0. Authenticated attackers with ...

Jan 14, 2026
CVE-2025-58693
6.5

This path traversal vulnerability in Fortinet FortiVoice allows privileged attackers to delete arbitrary files from the underlying filesystem via craf...

Jan 13, 2026
CVE-2025-66689
6.5

A path traversal vulnerability in Zen MCP Server allows authenticated attackers to read arbitrary files on the system by bypassing directory blacklist...

Jan 12, 2026
CVE-2025-69267
6.5

This path traversal vulnerability in Broadcom DX NetOps Spectrum allows attackers to access files outside the intended directory by manipulating file ...

Jan 12, 2026
CVE-2025-67004
6.5

This CVE describes a potential directory traversal vulnerability in CouchCMS 2.4 that could allow authenticated admin users to read arbitrary files on...

Jan 9, 2026
CVE-2025-66051
6.5

Vivotek IP7137 cameras with firmware version 0200a are vulnerable to path traversal attacks, allowing authenticated attackers to access files outside ...

Jan 9, 2026
CVE-2026-21857
6.5

This vulnerability allows authenticated REDAXO users with backup permissions to read arbitrary files within the webroot via path traversal in the Back...

Jan 7, 2026
CVE-2025-14867
6.5

The Flashcard WordPress plugin contains a path traversal vulnerability that allows authenticated attackers with contributor-level access or higher to ...

Jan 7, 2026
CVE-2024-42718
6.5

This path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files on the server by manipulating the 'edit-file' pa...

Dec 26, 2025
CVE-2025-64235
6.5

This path traversal vulnerability in the AmentoTech Tuturn WordPress plugin allows attackers to download arbitrary files from the server by manipulati...

Dec 18, 2025
CVE-2025-54748
6.5

This path traversal vulnerability in the MapSVG WordPress plugin allows attackers to download arbitrary files from the server by manipulating file pat...

Dec 18, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,182 CVEs classified as CWE-22, with 519 rated critical and 1,117 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free