CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (2,197)
This directory traversal vulnerability in 4C Strategies Exonaut allows attackers to access files outside the intended directory structure. Organizatio...
Aug 7, 2025This vulnerability in kotaemon allows attackers to perform directory traversal attacks by submitting malicious file paths containing sequences like '....
Jul 2, 2025A path traversal vulnerability in QNAP File Station 5 allows authenticated attackers to read arbitrary files on the system. This affects all QNAP NAS ...
Jun 6, 2025This vulnerability in IBM Planning Analytics Local allows privileged users to delete files from directories they shouldn't have access to due to impro...
Jun 1, 2025This vulnerability in Cisco Catalyst SD-WAN Manager allows authenticated remote attackers to write arbitrary files via API requests due to improper in...
May 7, 2025This vulnerability allows attackers to perform directory traversal attacks via crafted POST requests in Entrust Corp Printer Manager. Attackers can po...
Apr 25, 2025This path traversal vulnerability in the Total Processing Card Payments for WooCommerce WordPress plugin allows attackers to download arbitrary files ...
Apr 10, 2025The Streamit WordPress theme contains a vulnerability that allows authenticated attackers with subscriber-level access or higher to download arbitrary...
Apr 8, 2025This path traversal vulnerability in the Publitio WordPress plugin allows attackers to read arbitrary files on the server by manipulating file paths. ...
Apr 3, 2025This path traversal vulnerability in the WordPress Include URL plugin allows attackers to download arbitrary files from the server by manipulating URL...
Apr 1, 2025Xorcom CompletePBX versions through 5.2.35 contain an authenticated path traversal vulnerability in the Backup and Restore functionality. This allows ...
Mar 31, 2025A path traversal vulnerability in the HGW-BL1500HM gateway's USB file-sharing function allows attackers to access or modify files outside intended dir...
Mar 28, 2025The Jobs for WordPress plugin contains a directory traversal vulnerability that allows authenticated users with Subscriber-level access or higher to r...
Mar 26, 2025This vulnerability allows unauthenticated attackers to read arbitrary files on servers running vulnerable versions of gaizhenbiao/chuanhuchatgpt. The ...
Mar 20, 2025SOPlanning 1.53.00 has a directory traversal vulnerability in the upload.php file that allows authenticated attackers to delete arbitrary files by man...
Mar 18, 2025CVE-2025-27410 is a path traversal vulnerability in PwnDoc's backup restore functionality that allows authenticated administrators to overwrite arbitr...
Feb 28, 2025This directory traversal vulnerability in IBM Cognos Analytics allows remote attackers to read arbitrary files on the server by sending specially craf...
Feb 28, 2025This vulnerability allows authenticated attackers to perform directory traversal attacks on IBM EntireX 11.1 systems. By sending specially crafted URL...
Feb 27, 2025MasterSAM Star Gate 11 has a directory traversal vulnerability in the /adama/adama/downloadService endpoint. Attackers can manipulate the file paramet...
Feb 20, 2025A directory traversal vulnerability in dhtmlxFileExplorer v8.4.6 allows remote attackers to access sensitive files outside the intended directory via ...
Feb 7, 2025This vulnerability in the BoldGrid Post and Page Builder WordPress plugin allows authenticated attackers with Contributor-level access or higher to pe...
Feb 6, 2025The Jupiter X Core WordPress plugin contains a directory traversal vulnerability in its inline SVG feature. Authenticated attackers with Contributor-l...
Feb 1, 2025This vulnerability allows authenticated WordPress administrators to delete arbitrary directories on the server due to insufficient path validation in ...
Jan 25, 2025IBM InfoSphere Information Server 11.7 contains a directory traversal vulnerability that allows remote attackers to read arbitrary files on the system...
Jan 17, 2025A path traversal vulnerability in rsync's --safe-links option allows attackers to write files outside intended directories when the client fails to pr...
Jan 14, 2025Pat Infinite Solutions HelpdeskAdvanced versions up to 11.0.33 contain a directory traversal vulnerability in the WSConnector SOAP service. Authentica...
Jan 13, 2025This vulnerability allows authenticated users of WhatsUp Gold to craft HTTP requests that can disclose sensitive information. It affects all WhatsUp G...
Dec 31, 2024This vulnerability in pghoard allows attackers to perform path traversal attacks, potentially gaining disk access with the same privileges as the pgho...
Dec 17, 2024This path traversal vulnerability in DELUCKS SEO WordPress plugin allows attackers to download arbitrary files from the server by manipulating file pa...
Dec 13, 2024This vulnerability allows authenticated remote attackers to read arbitrary files on Allegra installations via directory traversal in the getFileConten...
Nov 22, 2024This directory traversal vulnerability in Allegra's downloadAttachmentGlobal function allows authenticated attackers to read arbitrary files on the se...
Nov 22, 2024This vulnerability in Gradio allows attackers with access to the application to read arbitrary files from the server when using File or UploadButton c...
Nov 6, 2024A symlink traversal vulnerability in the containers/storage library used by Podman, Buildah, and CRI-O allows malicious container images to cause deni...
Oct 15, 2024OpenC3 COSMOS contains a path traversal vulnerability in LocalMode's open_local_file method that allows authenticated users with adequate permissions ...
Oct 2, 2024This vulnerability allows authenticated attackers to perform local file inclusion (LFI) through path traversal in the Product Carousel Slider & Grid U...
Sep 23, 2024CVE-2024-46647 is a directory traversal vulnerability in eNMS versions 4.4.0 through 4.7.1 that allows attackers to upload files to arbitrary location...
Sep 20, 2024Mage AI has a path traversal vulnerability in its Git Content request that allows remote users with the 'Viewer' role to read arbitrary files from the...
Aug 23, 2024This vulnerability allows authenticated remote attackers to perform directory traversal attacks on Logsign Unified SecOps Platform installations. By e...
Aug 21, 2024This path traversal vulnerability in the WordPress BetterDocs plugin allows attackers to include local PHP files through improper path validation. It ...
Aug 13, 2024This vulnerability in Bert-VITS2 allows attackers to write arbitrary files to the server by manipulating the data_dir parameter. It affects all users ...
Jul 22, 2024Authenticated users in StoneFly Storage Concentrator (SC and SCVM) versions before 8.0.4.26 can exploit a directory traversal vulnerability via the On...
Jul 12, 2024This vulnerability allows attackers to perform path traversal attacks in the ExS Widgets WordPress plugin, enabling PHP local file inclusion. Attacker...
Jul 12, 2024This path traversal vulnerability in the HT Mega WordPress plugin allows attackers to access files outside the intended directory by manipulating file...
Jul 12, 2024This path traversal vulnerability in the ShopBuilder WordPress plugin allows attackers to access files outside the intended directory. It affects Word...
Jul 9, 2024This path traversal vulnerability in the vCita Online Booking & Scheduling Calendar WordPress plugin allows attackers to access files outside the inte...
Jul 9, 2024This path traversal vulnerability in the AWSM Team WordPress plugin allows attackers to read arbitrary files on the server by manipulating file paths....
Jul 9, 2024This CVE describes a path traversal vulnerability in the Livemesh Addons for Elementor WordPress plugin. It allows attackers to read arbitrary files o...
Jul 6, 2024This path traversal vulnerability in WhatsUp Gold allows unauthenticated attackers to access files outside the intended directory via specially crafte...
Jun 25, 2024This CVE describes a path traversal vulnerability in the WordPress Slideshow SE plugin that allows authenticated users with author-level permissions t...
Jun 21, 2024CVE-2024-36527 is a directory traversal vulnerability in puppeteer-renderer that allows attackers to read sensitive server files by manipulating URL p...
Jun 17, 2024About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 2,197 CVEs classified as CWE-22, with 530 rated critical and 1,121 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free