CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,197
Total CVEs
530
Critical
1,121
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
245
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 19
4 Fedoraproject 19
5 Solarwinds 17
6 Fortinet 17
7 Debian 17
8 Adobe 16
9 Siemens 16
10 Samsung 16

All Path Traversal CVEs (2,197)

CVE-2024-55401
6.5

This directory traversal vulnerability in 4C Strategies Exonaut allows attackers to access files outside the intended directory structure. Organizatio...

Aug 7, 2025
CVE-2025-53358
6.5

This vulnerability in kotaemon allows attackers to perform directory traversal attacks by submitting malicious file paths containing sequences like '....

Jul 2, 2025
CVE-2025-33035
6.5

A path traversal vulnerability in QNAP File Station 5 allows authenticated attackers to read arbitrary files on the system. This affects all QNAP NAS ...

Jun 6, 2025
CVE-2025-33004
6.5

This vulnerability in IBM Planning Analytics Local allows privileged users to delete files from directories they shouldn't have access to due to impro...

Jun 1, 2025
CVE-2025-20187
6.5

This vulnerability in Cisco Catalyst SD-WAN Manager allows authenticated remote attackers to write arbitrary files via API requests due to improper in...

May 7, 2025
CVE-2025-28354
6.5

This vulnerability allows attackers to perform directory traversal attacks via crafted POST requests in Entrust Corp Printer Manager. Attackers can po...

Apr 25, 2025
CVE-2025-32209
6.5

This path traversal vulnerability in the Total Processing Card Payments for WooCommerce WordPress plugin allows attackers to download arbitrary files ...

Apr 10, 2025
CVE-2025-2519
6.5

The Streamit WordPress theme contains a vulnerability that allows authenticated attackers with subscriber-level access or higher to download arbitrary...

Apr 8, 2025
CVE-2025-31800
6.5

This path traversal vulnerability in the Publitio WordPress plugin allows attackers to read arbitrary files on the server by manipulating file paths. ...

Apr 3, 2025
CVE-2025-30594
6.5

This path traversal vulnerability in the WordPress Include URL plugin allows attackers to download arbitrary files from the server by manipulating URL...

Apr 1, 2025
CVE-2025-2292
EPSS 68.8% 6.5

Xorcom CompletePBX versions through 5.2.35 contain an authenticated path traversal vulnerability in the Backup and Restore functionality. This allows ...

Mar 31, 2025
CVE-2025-27716
6.5

A path traversal vulnerability in the HGW-BL1500HM gateway's USB file-sharing function allows attackers to access or modify files outside intended dir...

Mar 28, 2025
CVE-2025-1310
6.5

The Jobs for WordPress plugin contains a directory traversal vulnerability that allows authenticated users with Subscriber-level access or higher to r...

Mar 26, 2025
CVE-2024-10707
6.5

This vulnerability allows unauthenticated attackers to read arbitrary files on servers running vulnerable versions of gaizhenbiao/chuanhuchatgpt. The ...

Mar 20, 2025
CVE-2024-57170
6.5

SOPlanning 1.53.00 has a directory traversal vulnerability in the upload.php file that allows authenticated attackers to delete arbitrary files by man...

Mar 18, 2025
CVE-2025-27410
EPSS 21.6% 6.5

CVE-2025-27410 is a path traversal vulnerability in PwnDoc's backup restore functionality that allows authenticated administrators to overwrite arbitr...

Feb 28, 2025
CVE-2025-0823
6.5

This directory traversal vulnerability in IBM Cognos Analytics allows remote attackers to read arbitrary files on the server by sending specially craf...

Feb 28, 2025
CVE-2024-54169
6.5

This vulnerability allows authenticated attackers to perform directory traversal attacks on IBM EntireX 11.1 systems. By sending specially crafted URL...

Feb 27, 2025
CVE-2024-55457
EPSS 77.9% 6.5

MasterSAM Star Gate 11 has a directory traversal vulnerability in the /adama/adama/downloadService endpoint. Attackers can manipulate the file paramet...

Feb 20, 2025
CVE-2024-55213
6.5

A directory traversal vulnerability in dhtmlxFileExplorer v8.4.6 allows remote attackers to access sensitive files outside the intended directory via ...

Feb 7, 2025
CVE-2025-0859
6.5

This vulnerability in the BoldGrid Post and Page Builder WordPress plugin allows authenticated attackers with Contributor-level access or higher to pe...

Feb 6, 2025
CVE-2025-0365
6.5

The Jupiter X Core WordPress plugin contains a directory traversal vulnerability in its inline SVG feature. Authenticated attackers with Contributor-l...

Feb 1, 2025
CVE-2024-12885
6.5

This vulnerability allows authenticated WordPress administrators to delete arbitrary directories on the server due to insufficient path validation in ...

Jan 25, 2025
CVE-2024-52363
6.5

IBM InfoSphere Information Server 11.7 contains a directory traversal vulnerability that allows remote attackers to read arbitrary files on the system...

Jan 17, 2025
CVE-2024-12088
6.5

A path traversal vulnerability in rsync's --safe-links option allows attackers to write files outside intended directories when the client fails to pr...

Jan 14, 2025
CVE-2023-42229
6.5

Pat Infinite Solutions HelpdeskAdvanced versions up to 11.0.33 contain a directory traversal vulnerability in the WSConnector SOAP service. Authentica...

Jan 13, 2025
CVE-2024-12105
6.5

This vulnerability allows authenticated users of WhatsUp Gold to craft HTTP requests that can disclose sensitive information. It affects all WhatsUp G...

Dec 31, 2024
CVE-2024-56142
6.5

This vulnerability in pghoard allows attackers to perform path traversal attacks, potentially gaining disk access with the same privileges as the pgho...

Dec 17, 2024
CVE-2024-54259
6.5

This path traversal vulnerability in DELUCKS SEO WordPress plugin allows attackers to download arbitrary files from the server by manipulating file pa...

Dec 13, 2024
CVE-2023-51648
6.5

This vulnerability allows authenticated remote attackers to read arbitrary files on Allegra installations via directory traversal in the getFileConten...

Nov 22, 2024
CVE-2023-52334
6.5

This directory traversal vulnerability in Allegra's downloadAttachmentGlobal function allows authenticated attackers to read arbitrary files on the se...

Nov 22, 2024
CVE-2024-51751
6.5

This vulnerability in Gradio allows attackers with access to the application to read arbitrary files from the server when using File or UploadButton c...

Nov 6, 2024
CVE-2024-9676
6.5

A symlink traversal vulnerability in the containers/storage library used by Podman, Buildah, and CRI-O allows malicious container images to cause deni...

Oct 15, 2024
CVE-2024-46977
6.5

OpenC3 COSMOS contains a path traversal vulnerability in LocalMode's open_local_file method that allows authenticated users with adequate permissions ...

Oct 2, 2024
CVE-2024-44048
6.5

This vulnerability allows authenticated attackers to perform local file inclusion (LFI) through path traversal in the Product Carousel Slider & Grid U...

Sep 23, 2024
CVE-2024-46647
6.5

CVE-2024-46647 is a directory traversal vulnerability in eNMS versions 4.4.0 through 4.7.1 that allows attackers to upload files to arbitrary location...

Sep 20, 2024
CVE-2024-45189
6.5

Mage AI has a path traversal vulnerability in its Git Content request that allows remote users with the 'Viewer' role to read arbitrary files from the...

Aug 23, 2024
CVE-2024-7602
6.5

This vulnerability allows authenticated remote attackers to perform directory traversal attacks on Logsign Unified SecOps Platform installations. By e...

Aug 21, 2024
CVE-2024-43129
6.5

This path traversal vulnerability in the WordPress BetterDocs plugin allows attackers to include local PHP files through improper path validation. It ...

Aug 13, 2024
CVE-2024-39688
6.5

This vulnerability in Bert-VITS2 allows attackers to write arbitrary files to the server by manipulating the data_dir parameter. It affects all users ...

Jul 22, 2024
CVE-2024-31947
6.5

Authenticated users in StoneFly Storage Concentrator (SC and SCVM) versions before 8.0.4.26 can exploit a directory traversal vulnerability via the On...

Jul 12, 2024
CVE-2024-38715
6.5

This vulnerability allows attackers to perform path traversal attacks in the ExS Widgets WordPress plugin, enabling PHP local file inclusion. Attacker...

Jul 12, 2024
CVE-2024-38706
6.5

This path traversal vulnerability in the HT Mega WordPress plugin allows attackers to access files outside the intended directory by manipulating file...

Jul 12, 2024
CVE-2024-37520
6.5

This path traversal vulnerability in the ShopBuilder WordPress plugin allows attackers to access files outside the intended directory. It affects Word...

Jul 9, 2024
CVE-2024-37499
6.5

This path traversal vulnerability in the vCita Online Booking & Scheduling Calendar WordPress plugin allows attackers to access files outside the inte...

Jul 9, 2024
CVE-2024-37454
6.5

This path traversal vulnerability in the AWSM Team WordPress plugin allows attackers to read arbitrary files on the server by manipulating file paths....

Jul 9, 2024
CVE-2024-37547
6.5

This CVE describes a path traversal vulnerability in the Livemesh Addons for Elementor WordPress plugin. It allows attackers to read arbitrary files o...

Jul 6, 2024
CVE-2024-5017
6.5

This path traversal vulnerability in WhatsUp Gold allows unauthenticated attackers to access files outside the intended directory via specially crafte...

Jun 25, 2024
CVE-2024-35778
6.5

This CVE describes a path traversal vulnerability in the WordPress Slideshow SE plugin that allows authenticated users with author-level permissions t...

Jun 21, 2024
CVE-2024-36527
6.5

CVE-2024-36527 is a directory traversal vulnerability in puppeteer-renderer that allows attackers to read sensitive server files by manipulating URL p...

Jun 17, 2024

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,197 CVEs classified as CWE-22, with 530 rated critical and 1,121 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free