CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,192
Total CVEs
525
Critical
1,121
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
245
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 19
4 Fedoraproject 19
5 Solarwinds 17
6 Fortinet 17
7 Debian 17
8 Siemens 16
9 Samsung 16
10 Adobe 15

All Path Traversal CVEs (2,192)

CVE-2025-58693
6.5

This path traversal vulnerability in Fortinet FortiVoice allows privileged attackers to delete arbitrary files from the underlying filesystem via craf...

Jan 13, 2026
CVE-2025-66689
6.5

A path traversal vulnerability in Zen MCP Server allows authenticated attackers to read arbitrary files on the system by bypassing directory blacklist...

Jan 12, 2026
CVE-2025-69267
6.5

This path traversal vulnerability in Broadcom DX NetOps Spectrum allows attackers to access files outside the intended directory by manipulating file ...

Jan 12, 2026
CVE-2025-67004
6.5

This CVE describes a potential directory traversal vulnerability in CouchCMS 2.4 that could allow authenticated admin users to read arbitrary files on...

Jan 9, 2026
CVE-2025-66051
6.5

Vivotek IP7137 cameras with firmware version 0200a are vulnerable to path traversal attacks, allowing authenticated attackers to access files outside ...

Jan 9, 2026
CVE-2026-21857
6.5

This vulnerability allows authenticated REDAXO users with backup permissions to read arbitrary files within the webroot via path traversal in the Back...

Jan 7, 2026
CVE-2025-14867
6.5

The Flashcard WordPress plugin contains a path traversal vulnerability that allows authenticated attackers with contributor-level access or higher to ...

Jan 7, 2026
CVE-2024-42718
6.5

This path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files on the server by manipulating the 'edit-file' pa...

Dec 26, 2025
CVE-2025-64235
6.5

This path traversal vulnerability in the AmentoTech Tuturn WordPress plugin allows attackers to download arbitrary files from the server by manipulati...

Dec 18, 2025
CVE-2025-54748
6.5

This path traversal vulnerability in the MapSVG WordPress plugin allows attackers to download arbitrary files from the server by manipulating file pat...

Dec 18, 2025
CVE-2023-53907
6.5

CVE-2023-53907 is an authenticated file download vulnerability in Bludit's Backup Plugin that allows logged-in users to read arbitrary files through d...

Dec 17, 2025
CVE-2025-65075
6.5

This vulnerability allows high-privileged attackers to perform path traversal attacks through the alog script in WaveView client, enabling file read/d...

Dec 16, 2025
CVE-2025-12960
6.5

The Simple CSV Table WordPress plugin has a directory traversal vulnerability that allows authenticated attackers with Contributor-level access or hig...

Dec 12, 2025
CVE-2025-13891
6.5

This vulnerability allows authenticated WordPress users with Author-level permissions or higher to perform directory traversal attacks via the modula_...

Dec 12, 2025
CVE-2025-14293
6.5

The WP Job Portal WordPress plugin contains an arbitrary file read vulnerability in all versions up to 2.4.0. Authenticated attackers with Subscriber-...

Dec 11, 2025
CVE-2025-67720
6.5

Pyrofork versions 2.3.68 and earlier are vulnerable to path traversal attacks when downloading media files from Telegram messages. Attackers can send ...

Dec 11, 2025
CVE-2025-65814
6.5

CVE-2025-65814 is a directory traversal vulnerability in RHOPHI Analytics LLP Office App-Edit Word v6.4.1 that allows attackers to access files outsid...

Dec 10, 2025
CVE-2025-65815
6.5

CVE-2025-65815 is a directory traversal vulnerability in AB TECHNOLOGY Document Reader that allows attackers to access files outside the intended dire...

Dec 10, 2025
CVE-2021-47724
6.5

STVS ProVision 5.9.10 contains an authenticated path traversal vulnerability in its archive download functionality. Authenticated attackers can manipu...

Dec 9, 2025
CVE-2025-65345
6.5

CVE-2025-65345 is a directory traversal vulnerability in alexusmai/laravel-file-manager versions 3.3.1 and below. It allows attackers to create archiv...

Dec 3, 2025
CVE-2025-12089
6.5

The Data Tables Generator by Supsystic WordPress plugin contains a path traversal vulnerability in its cleanCache() function that allows authenticated...

Nov 13, 2025
CVE-2025-60722
6.5

A path traversal vulnerability in OneDrive for Android allows authenticated attackers to access files outside the intended directory via network reque...

Nov 11, 2025
CVE-2025-12092
6.5

The CYAN Backup WordPress plugin has an arbitrary file deletion vulnerability in versions up to 2.5.4. Authenticated attackers with Administrator priv...

Nov 8, 2025
CVE-2025-12000
6.5

The WPFunnels WordPress plugin contains an arbitrary file deletion vulnerability that allows authenticated attackers with Administrator privileges to ...

Nov 8, 2025
CVE-2025-64433
6.5

This vulnerability in KubeVirt allows a malicious user with control over a PersistentVolumeClaim (PVC) to read arbitrary files from the virt-launcher ...

Nov 7, 2025
CVE-2025-57712
6.5

A path traversal vulnerability in Qsync Central allows authenticated attackers to read arbitrary files on the system. This affects all Qsync Central i...

Nov 7, 2025
CVE-2025-34238
6.5

This vulnerability allows authenticated network administrators in Advantech WebAccess/VPN to read arbitrary files accessible to the web user (www-data...

Nov 6, 2025
CVE-2025-41073
6.5

This path traversal vulnerability in TESI Gandia Integra Total version 4.4.2236.1 allows authenticated attackers to download ZIP files containing sens...

Oct 23, 2025
CVE-2025-58591
6.5

This vulnerability allows remote attackers to brute-force directory and file paths to access sensitive information like private keys and configuration...

Oct 6, 2025
CVE-2025-58590
6.5

This vulnerability allows attackers to brute-force directory and file paths, potentially exposing sensitive information stored in accessible locations...

Oct 6, 2025
CVE-2025-54293
6.5

This path traversal vulnerability in Canonical LXD 5.0 LTS allows authenticated remote attackers to read arbitrary files on the host system by manipul...

Oct 2, 2025
CVE-2025-11182
6.5

This vulnerability in GTONE ChangeFlow allows attackers to traverse directory paths and download arbitrary files without integrity checks. It affects ...

Oct 2, 2025
CVE-2025-8559
6.5

The All in One Music Player WordPress plugin contains a path traversal vulnerability that allows authenticated attackers with Contributor-level access...

Sep 30, 2025
CVE-2025-10307
6.5

The Backuply WordPress plugin has a vulnerability allowing authenticated attackers with Administrator privileges to delete arbitrary files on the serv...

Sep 26, 2025
CVE-2025-9215
6.5

This vulnerability allows authenticated attackers with Subscriber-level access or higher to perform path traversal attacks via the file_download() fun...

Sep 17, 2025
CVE-2025-58162
6.5

CVE-2025-58162 is an arbitrary file write vulnerability in MobSF version 4.4.0. Authenticated users can upload specially crafted files to write arbitr...

Sep 2, 2025
CVE-2025-33036
6.5

A path traversal vulnerability in Qsync Central allows authenticated remote attackers to read arbitrary files on the system. This affects all QNAP use...

Aug 29, 2025
CVE-2025-33038
6.5

A path traversal vulnerability in Qsync Central allows authenticated remote attackers to read arbitrary files on the system. This affects all Qsync Ce...

Aug 29, 2025
CVE-2025-30270
6.5

A path traversal vulnerability in QNAP operating systems allows authenticated attackers to read arbitrary files. This affects QTS and QuTS hero users ...

Aug 29, 2025
CVE-2025-54819
6.5

A path traversal vulnerability in SS1 Ver.16.0.0.10 and earlier allows remote authenticated attackers to overwrite legitimate files by manipulating fi...

Aug 28, 2025
CVE-2025-20344
6.5

This vulnerability allows authenticated administrators to exploit path traversal via crafted backup files in Cisco Nexus Dashboard, potentially gainin...

Aug 27, 2025
CVE-2025-8562
6.5

The Custom Query Shortcode WordPress plugin contains a path traversal vulnerability that allows authenticated attackers with Contributor-level access ...

Aug 25, 2025
CVE-2025-47650
6.5

This path traversal vulnerability in Infility Global WordPress plugin allows attackers to access files outside the intended directory. It affects all ...

Aug 20, 2025
CVE-2025-0818
6.5

This CVE describes a directory traversal vulnerability in elFinder versions 2.1.64 and prior when used in WordPress plugins. Unauthenticated attackers...

Aug 13, 2025
CVE-2025-8749
6.5

This path traversal vulnerability in MiR robot software allows authenticated users to access arbitrary files on the robot's file system through specia...

Aug 8, 2025
CVE-2024-55401
6.5

This directory traversal vulnerability in 4C Strategies Exonaut allows attackers to access files outside the intended directory structure. Organizatio...

Aug 7, 2025
CVE-2025-53358
6.5

This vulnerability in kotaemon allows attackers to perform directory traversal attacks by submitting malicious file paths containing sequences like '....

Jul 2, 2025
CVE-2025-33035
6.5

A path traversal vulnerability in QNAP File Station 5 allows authenticated attackers to read arbitrary files on the system. This affects all QNAP NAS ...

Jun 6, 2025
CVE-2025-33004
6.5

This vulnerability in IBM Planning Analytics Local allows privileged users to delete files from directories they shouldn't have access to due to impro...

Jun 1, 2025
CVE-2025-20187
6.5

This vulnerability in Cisco Catalyst SD-WAN Manager allows authenticated remote attackers to write arbitrary files via API requests due to improper in...

May 7, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,192 CVEs classified as CWE-22, with 525 rated critical and 1,121 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free