CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,202
Total CVEs
531
Critical
1,125
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
245
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 19
4 Fedoraproject 19
5 Debian 18
6 Solarwinds 17
7 Fortinet 17
8 Adobe 16
9 Siemens 16
10 Samsung 16

All Path Traversal CVEs (2,202)

CVE-2024-37454
6.5

This path traversal vulnerability in the AWSM Team WordPress plugin allows attackers to read arbitrary files on the server by manipulating file paths....

Jul 9, 2024
CVE-2024-37547
6.5

This CVE describes a path traversal vulnerability in the Livemesh Addons for Elementor WordPress plugin. It allows attackers to read arbitrary files o...

Jul 6, 2024
CVE-2024-5017
6.5

This path traversal vulnerability in WhatsUp Gold allows unauthenticated attackers to access files outside the intended directory via specially crafte...

Jun 25, 2024
CVE-2024-35778
6.5

This CVE describes a path traversal vulnerability in the WordPress Slideshow SE plugin that allows authenticated users with author-level permissions t...

Jun 21, 2024
CVE-2024-36527
6.5

CVE-2024-36527 is a directory traversal vulnerability in puppeteer-renderer that allows attackers to read sensitive server files by manipulating URL p...

Jun 17, 2024
CVE-2024-35474
6.5

A directory traversal vulnerability in iceice666 ResourcePack Server allows remote attackers to read arbitrary files on the server by manipulating fil...

Jun 10, 2024
CVE-2024-34384
6.5

This vulnerability allows attackers to read arbitrary files on the server through path traversal in the Sina Extension for Elementor WordPress plugin....

Jun 4, 2024
CVE-2024-33541
6.5

This vulnerability allows attackers to read arbitrary files on the server through path traversal in the Better Elementor Addons WordPress plugin. It a...

Jun 4, 2024
CVE-2024-28880
6.5

A path traversal vulnerability in MosP kintai kanri V4.6.6 and earlier allows authenticated remote attackers to access sensitive system files. This af...

May 28, 2024
CVE-2024-36079
6.5

This vulnerability in Vaultize allows authenticated users to create temporary files outside intended directories by manipulating filename parameters d...

May 24, 2024
CVE-2024-30509
6.5

This path traversal vulnerability in the WordPress SellKit plugin allows attackers to download arbitrary files from the server by manipulating file pa...

May 17, 2024
CVE-2024-34712
6.5

CVE-2024-34712 is a path traversal vulnerability in the Oceanic Discord library for NodeJS. Attackers can manipulate input to functions like removeBan...

May 14, 2024
CVE-2024-24908
6.5

CVE-2024-24908 is a path traversal vulnerability in Dell PowerProtect DM5500 that allows authenticated high-privilege attackers to delete arbitrary fi...

May 8, 2024
CVE-2023-42129
6.5

This vulnerability in A10 Thunder ADC allows authenticated remote attackers to perform directory traversal attacks, potentially disclosing sensitive f...

May 3, 2024
CVE-2023-40512
6.5

This vulnerability in LG Simple Editor allows authenticated attackers to bypass authentication and perform directory traversal attacks via the getImag...

May 3, 2024
CVE-2023-40514
6.5

This vulnerability in LG Simple Editor allows authenticated attackers to bypass authentication and perform directory traversal attacks via the getImag...

May 3, 2024
CVE-2023-0241
6.5

CVE-2023-0241 is a directory traversal vulnerability in pgAdmin 4 that allows authenticated users to access or modify files outside the intended direc...

Mar 27, 2023
CVE-2026-28800
6.4

CVE-2026-28800 is a critical remote code execution vulnerability in Natro Macro (an AutoHotkey-based Bee Swarm Simulator macro) that allows attackers ...

Mar 6, 2026
CVE-2025-35053
6.4

CVE-2025-35053 allows authenticated users in Newforma Info Exchange (NIX) to read and delete arbitrary files with NetworkService privileges via the '/...

Oct 9, 2025
CVE-2025-24330
6.4

A path traversal vulnerability in Nokia Single RAN baseband software allows attackers to access unauthorized files or directories by sending crafted S...

Jul 2, 2025
CVE-2025-48744
6.4

This vulnerability in SIGB PMB allows attackers to perform Local File Inclusion (LFI) and achieve remote code execution. It affects all installations ...

May 27, 2025
CVE-2026-3051
6.3

This CVE describes a path traversal vulnerability in DataLinkDC Dinky's GitRepository component. Attackers can manipulate the projectName parameter to...

Feb 24, 2026
CVE-2026-1812
6.3

This is a path traversal vulnerability in bolo-solo blogging software that allows attackers to manipulate file paths during blog import operations. At...

Feb 3, 2026
CVE-2026-1811
6.3

This CVE describes a path traversal vulnerability in bolo-blog's bolo-solo software that allows attackers to manipulate file paths through the importF...

Feb 3, 2026
CVE-2026-1810
6.3

This CVE describes a path traversal vulnerability in bolo-blog's bolo-solo software up to version 2.6.4. Attackers can exploit the unpackFilteredZip f...

Feb 3, 2026
CVE-2025-14182
6.3

This CVE describes a path traversal vulnerability in Sobey Media Convergence System versions 2.0 and 2.1. Attackers can remotely exploit the /sobey-mc...

Dec 7, 2025
CVE-2025-13875
6.3

This vulnerability allows remote attackers to perform path traversal attacks in Yohann0617 oci-helper versions up to 3.2.4. By manipulating file argum...

Dec 2, 2025
CVE-2025-13791
6.3

This vulnerability allows remote attackers to perform path traversal attacks via the project import function in Scada-LTS. By exploiting improper path...

Nov 30, 2025
CVE-2025-13265
6.3

This CVE describes a path traversal vulnerability in the lsfusion platform's unpackFile function that allows remote attackers to write files outside i...

Nov 17, 2025
CVE-2025-13246
6.3

This CVE describes a path traversal vulnerability in the JwtAuthenticationFilter component of shsuishang ShopSuite ModulithShop. Attackers can exploit...

Nov 16, 2025
CVE-2025-12922
6.3

This vulnerability allows remote attackers to perform path traversal attacks via the xml_file parameter in OpenClinica's CRF Data Import component. At...

Nov 10, 2025
CVE-2025-12203
6.3

This CVE describes a path traversal vulnerability in givanz Vvveb CMS up to version 1.0.7.3. Attackers can manipulate file paths through the Code Edit...

Oct 27, 2025
CVE-2025-11842
6.3

CVE-2025-11842 is a path traversal vulnerability in Shazwazza Smidge's Bundle Handler component that allows attackers to access files outside the inte...

Oct 16, 2025
CVE-2025-11630
6.3

This CVE describes a path traversal vulnerability in RainyGao DocSys up to version 2.02.36. Attackers can remotely exploit the file upload function to...

Oct 12, 2025
CVE-2025-11607
6.3

A path traversal vulnerability in MoneyPrinterTurbo's API endpoint allows attackers to write arbitrary files to the server filesystem by manipulating ...

Oct 11, 2025
CVE-2025-11139
6.3

This is a path traversal vulnerability in Bjskzy Zhiyou ERP that allows attackers to manipulate file paths in the uploadStudioFile function. Remote ex...

Sep 29, 2025
CVE-2025-10777
6.3

This CVE describes a path traversal vulnerability in JSC R7 R7-Office Document Server's /downloadas/ endpoint. Attackers can manipulate the 'cmd' para...

Sep 22, 2025
CVE-2025-49089
6.3

MoneyPrinterTurbo 1.2.6 contains a path traversal vulnerability that allows attackers to read arbitrary files on the server via specially crafted down...

Sep 15, 2025
CVE-2025-10233
6.3

This path traversal vulnerability in kalcaddle kodbox 1.61 allows remote attackers to read or write arbitrary files by manipulating the 'path' paramet...

Sep 10, 2025
CVE-2025-8729
6.3

This is a critical path traversal vulnerability in MigoXLab LMeterX 1.2.0 that allows attackers to access arbitrary files on the server by manipulatin...

Aug 8, 2025
CVE-2025-6774
6.3

This critical path traversal vulnerability in gooaclok819 sublinkX allows attackers to access arbitrary files on the server by manipulating the filena...

Jun 27, 2025
CVE-2025-6453
6.3

A critical path traversal vulnerability in diyhi bbs 6.8 allows remote attackers to manipulate directory paths via the dirName parameter in the API co...

Jun 22, 2025
CVE-2025-6108
6.3

This critical vulnerability in Spring-Boot-In-Action allows attackers to perform path traversal attacks via the filename parameter in the watermarkTes...

Jun 16, 2025
CVE-2025-5509
6.3

This critical vulnerability in quequnlong shiyi-blog allows remote attackers to perform path traversal attacks via the /api/file/upload endpoint. By m...

Jun 3, 2025
CVE-2025-4893
6.3

This critical path traversal vulnerability in jammy928 CoinExchange_CryptoExchange_Java allows attackers to write arbitrary files to server directorie...

May 18, 2025
CVE-2025-4868
6.3

This critical vulnerability in merikbest ecommerce-spring-reactjs allows attackers to perform path traversal attacks via the filename parameter in the...

May 18, 2025
CVE-2023-42961
6.3

This vulnerability allows a sandboxed process to bypass sandbox restrictions through a path handling issue. It affects Apple iOS, iPadOS, and macOS us...

Apr 11, 2025
CVE-2025-2363
6.3

This critical vulnerability in lenve VBlog allows remote attackers to perform path traversal attacks via the uploadImg function's filename parameter. ...

Mar 17, 2025
CVE-2024-57248
6.3

CVE-2024-57248 is a directory traversal vulnerability in Gleamtech FileVista 9.2.0.0 that allows attackers to bypass access controls and upload malici...

Feb 7, 2025
CVE-2024-9032
6.3

A critical path traversal vulnerability in SourceCodester Simple Forum-Discussion System 1.0 allows remote attackers to access arbitrary files on the ...

Sep 20, 2024

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,202 CVEs classified as CWE-22, with 531 rated critical and 1,125 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free