CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,216
Total CVEs
531
Critical
1,138
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
246
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 19
4 Fedoraproject 19
5 Debian 18
6 Solarwinds 17
7 Fortinet 17
8 Adobe 16
9 Siemens 16
10 Samsung 16

All Path Traversal CVEs (2,216)

CVE-2025-49089
6.3

MoneyPrinterTurbo 1.2.6 contains a path traversal vulnerability that allows attackers to read arbitrary files on the server via specially crafted down...

Sep 15, 2025
CVE-2025-10233
6.3

This path traversal vulnerability in kalcaddle kodbox 1.61 allows remote attackers to read or write arbitrary files by manipulating the 'path' paramet...

Sep 10, 2025
CVE-2025-8729
6.3

This is a critical path traversal vulnerability in MigoXLab LMeterX 1.2.0 that allows attackers to access arbitrary files on the server by manipulatin...

Aug 8, 2025
CVE-2025-6774
6.3

This critical path traversal vulnerability in gooaclok819 sublinkX allows attackers to access arbitrary files on the server by manipulating the filena...

Jun 27, 2025
CVE-2025-6453
6.3

A critical path traversal vulnerability in diyhi bbs 6.8 allows remote attackers to manipulate directory paths via the dirName parameter in the API co...

Jun 22, 2025
CVE-2025-6108
6.3

This critical vulnerability in Spring-Boot-In-Action allows attackers to perform path traversal attacks via the filename parameter in the watermarkTes...

Jun 16, 2025
CVE-2025-5509
6.3

This critical vulnerability in quequnlong shiyi-blog allows remote attackers to perform path traversal attacks via the /api/file/upload endpoint. By m...

Jun 3, 2025
CVE-2025-4893
6.3

This critical path traversal vulnerability in jammy928 CoinExchange_CryptoExchange_Java allows attackers to write arbitrary files to server directorie...

May 18, 2025
CVE-2025-4868
6.3

This critical vulnerability in merikbest ecommerce-spring-reactjs allows attackers to perform path traversal attacks via the filename parameter in the...

May 18, 2025
CVE-2023-42961
6.3

This vulnerability allows a sandboxed process to bypass sandbox restrictions through a path handling issue. It affects Apple iOS, iPadOS, and macOS us...

Apr 11, 2025
CVE-2025-2363
6.3

This critical vulnerability in lenve VBlog allows remote attackers to perform path traversal attacks via the uploadImg function's filename parameter. ...

Mar 17, 2025
CVE-2024-57248
6.3

CVE-2024-57248 is a directory traversal vulnerability in Gleamtech FileVista 9.2.0.0 that allows attackers to bypass access controls and upload malici...

Feb 7, 2025
CVE-2024-9032
6.3

A critical path traversal vulnerability in SourceCodester Simple Forum-Discussion System 1.0 allows remote attackers to access arbitrary files on the ...

Sep 20, 2024
CVE-2024-8782
6.3

This critical vulnerability in JFinalCMS allows remote attackers to perform path traversal attacks via the 'name' parameter in the delete function of ...

Sep 13, 2024
CVE-2023-26321
6.3

This path traversal vulnerability in Xiaomi File Manager allows attackers to write arbitrary files to sensitive locations by manipulating file paths. ...

Aug 28, 2024
CVE-2024-41373
6.3

CVE-2024-41373 is a path traversal vulnerability in ICEcoder 8.1 that allows attackers to read arbitrary files on the server via lib/backup-versions-p...

Jul 26, 2024
CVE-2024-33870
6.3

This vulnerability in Ghostscript allows path traversal attacks via crafted PostScript documents, enabling unauthorized file access when the current d...

Jul 3, 2024
CVE-2024-23793
6.3

This path traversal vulnerability in OTRS and ((OTRS)) Community Edition allows authenticated users (agents or customers) to upload malicious files to...

Jun 6, 2024
CVE-2021-47849
6.2

Mini Mouse 9.3.0 contains a path traversal vulnerability that allows attackers to access sensitive system directories through API requests. By manipul...

Jan 21, 2026
CVE-2025-15066
6.2

This vulnerability allows attackers to access files outside the intended directory through path traversal in Innorix WP. It affects all versions of In...

Dec 29, 2025
CVE-2025-63918
6.2

PDFPatcher contains a directory traversal vulnerability (CWE-22) where the executable fails to validate user-supplied file paths, allowing attackers t...

Nov 17, 2025
CVE-2025-6210
6.2

This vulnerability in the ObsidianReader class of llama_index allows attackers to bypass path restrictions using hardlinks, potentially accessing sens...

Jul 7, 2025
CVE-2024-47292
6.2

A path traversal vulnerability in the Bluetooth module allows attackers to access files outside the intended directory. This affects devices with vuln...

Sep 27, 2024
CVE-2024-1629
6.2

A path traversal vulnerability in the 'deleteFiles' function of GE HealthCare's Common Service Desktop component allows attackers to delete arbitrary ...

May 14, 2024
CVE-2026-28486
6.1

OpenClaw versions 2026.1.16-2 through 2026.2.13 contain a path traversal vulnerability in archive extraction during installation commands. Attackers c...

Mar 5, 2026
CVE-2026-28457
6.1

OpenClaw versions before 2026.2.14 have a path traversal vulnerability in sandbox skill mirroring when enabled. Attackers can craft skill packages wit...

Mar 5, 2026
CVE-2025-65076
6.1

CVE-2025-65076 is a path traversal vulnerability in WaveView client's ilog script that allows high-privileged attackers to read or delete any file on ...

Dec 16, 2025
CVE-2025-46096
6.1

A directory traversal vulnerability in Solon v3.1.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via the solon-faas-luffy com...

Jun 13, 2025
CVE-2025-40592
6.1

A zip path traversal vulnerability in Mendix Studio Pro allows attackers to write or modify arbitrary files outside a developer's project directory by...

Jun 12, 2025
CVE-2026-20982
6.0

A path traversal vulnerability in ShortcutService on Samsung devices allows a privileged local attacker to create arbitrary files with system privileg...

Feb 4, 2026
CVE-2025-69820
6.0

A directory traversal vulnerability in Beam beta9 v0.1.521 allows remote attackers to access sensitive files outside the intended directory via the jo...

Jan 22, 2026
CVE-2025-43934
6.0

This path traversal vulnerability in Dell PowerProtect Data Domain allows high-privileged local attackers to access restricted directories, potentiall...

Oct 7, 2025
CVE-2024-36508
6.0

This path traversal vulnerability in Fortinet FortiManager and FortiAnalyzer allows authenticated admin users with diagnose privileges to delete arbit...

Feb 11, 2025
CVE-2024-45598
6.0

This vulnerability in Cacti allows administrators to read arbitrary local files on the server by manipulating the Poller Standard Error Log Path param...

Jan 27, 2025
CVE-2024-2552
6.0

This CVE describes a command injection vulnerability in Palo Alto Networks PAN-OS software that allows authenticated administrators to bypass system r...

Nov 14, 2024
CVE-2023-33310
6.0

This CVE describes a path traversal vulnerability in the Unite Gallery Lite WordPress plugin that allows attackers to include local PHP files. Attacke...

May 17, 2024
CVE-2025-12002
5.9

The Feeds for YouTube Pro WordPress plugin has an arbitrary file read vulnerability that allows unauthenticated attackers to read any file on the serv...

Jan 17, 2026
CVE-2025-41242
5.9

Spring Framework MVC applications can be vulnerable to path traversal attacks when deployed on non-compliant Servlet containers, potentially allowing ...

Aug 18, 2025
CVE-2025-4187
5.9

This vulnerability allows unauthenticated attackers to perform directory traversal attacks via the userpro_fbconnect() function in the UserPro WordPre...

Jun 14, 2025
CVE-2024-23334
EPSS 93.5% 5.9

This CVE describes a directory traversal vulnerability in aiohttp when using static routes with 'follow_symlinks=True'. Attackers can access arbitrary...

Jan 29, 2024
CVE-2025-54659
5.8

This path traversal vulnerability in Fortinet FortiSOAR Agent Communication Bridge allows unauthenticated attackers to read files accessible to the fo...

Mar 10, 2026
CVE-2026-24137
5.8

This vulnerability in sigstore's legacy TUF client allows a malicious TUF repository to trigger arbitrary file overwriting by exploiting path traversa...

Jan 23, 2026
CVE-2025-8917
5.8

A path traversal vulnerability in allegroai/clearml v2.0.1 allows attackers to write arbitrary files outside intended directories via improper handlin...

Oct 5, 2025
CVE-2025-42970
5.8

CVE-2025-42970 is a path traversal vulnerability in SAPCAR archive extraction tool that allows attackers to overwrite arbitrary files on a victim's sy...

Jul 8, 2025
CVE-2025-27098
5.8

GraphQL Mesh has a path traversal vulnerability in its static file handler that allows attackers to access arbitrary files on the server filesystem. T...

Feb 20, 2025
CVE-2025-1035
EPSS 21.2% 5.7

This path traversal vulnerability in Komtera Technologies KLog Server allows attackers to manipulate web input to access files outside the intended di...

Feb 18, 2025
CVE-2024-46327
5.7

This directory traversal vulnerability in VONETS VAP11G-300 routers allows attackers to access sensitive files by manipulating HTTP requests. Attacker...

Sep 26, 2024
CVE-2024-3484
5.7

This path traversal vulnerability in OpenText iManager 3.2.6.0200 allows attackers to access files outside the intended directory. It can lead to priv...

May 15, 2024
CVE-2025-13435
5.6

CVE-2025-13435 is a path traversal vulnerability in Dreampie Resty's HttpClient module that allows attackers to access arbitrary files on the server b...

Nov 20, 2025
CVE-2025-22241
5.6

This vulnerability in SaltStack allows attackers to overwrite files in the pki directory by exploiting improper path validation when processing on-dem...

Jun 13, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,216 CVEs classified as CWE-22, with 531 rated critical and 1,138 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free