CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,216
Total CVEs
531
Critical
1,138
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
246
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 19
4 Fedoraproject 19
5 Debian 18
6 Solarwinds 17
7 Fortinet 17
8 Adobe 17
9 Siemens 16
10 Samsung 16

All Path Traversal CVEs (2,216)

CVE-2025-4545
5.4

This vulnerability allows authenticated attackers to delete arbitrary files on CTCMS Content Management System servers via path traversal in the file ...

May 11, 2025
CVE-2025-46559
5.4

This vulnerability in Misskey allows malicious AiScript code to bypass API endpoint restrictions by using directory traversal sequences (../) to acces...

May 5, 2025
CVE-2025-2744
5.4

This critical vulnerability in ruoyi-vue-pro 2.4.1 allows attackers to perform path traversal attacks through the material upload interface. By manipu...

Mar 25, 2025
CVE-2025-2742
5.4

This critical vulnerability in ruoyi-vue-pro 2.4.1 allows remote attackers to perform path traversal attacks through the material upload interface. By...

Mar 25, 2025
CVE-2025-2708
5.4

This critical vulnerability in zhijiantianya ruoyi-vue-pro 2.4.1 allows remote attackers to perform path traversal attacks via the /admin-api/infra/fi...

Mar 24, 2025
CVE-2025-1785
5.4

The Download Manager plugin for WordPress has a directory traversal vulnerability that allows authenticated attackers with Author-level permissions or...

Mar 13, 2025
CVE-2024-48019
5.4

This path traversal vulnerability in Apache Doris allows authenticated application administrators to read arbitrary files from the server filesystem. ...

Feb 4, 2025
CVE-2025-0973
5.4

This critical vulnerability in CmsEasy 7.7.7.9 allows remote attackers to perform path traversal attacks via the select[] parameter in the backAll_act...

Feb 3, 2025
CVE-2024-55659
5.4

This vulnerability in SiYuan personal knowledge management systems allows attackers to write arbitrary files to the host server and execute stored cro...

Dec 12, 2024
CVE-2024-11239
5.4

This critical vulnerability in Landray EKP allows remote attackers to perform path traversal attacks via the deleteFile API endpoint. Attackers can de...

Nov 15, 2024
CVE-2024-39178
5.4

MyPower vc8100 V100R001C00B030 contains an arbitrary file read vulnerability in the /tcpdump/tcpdump.php component via the menu_uuid parameter. This a...

Jul 5, 2024
CVE-2024-37825
5.4

This vulnerability in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0 allows unauthenticated attackers on the same network to perfor...

Jun 24, 2024
CVE-2026-23907
5.3

This CVE describes a path traversal vulnerability in Apache PDFBox's ExtractEmbeddedFiles example code. Attackers can exploit this to write files outs...

Mar 10, 2026
CVE-2026-3719
5.3

This CVE describes a path traversal vulnerability in Tsinghua Unigroup Electronic Archives System version 3.2.210802(62532). Attackers can remotely ex...

Mar 8, 2026
CVE-2026-25527
5.3

This vulnerability in changedetection.io allows unauthenticated attackers to read application source files through a directory traversal flaw in the s...

Feb 19, 2026
CVE-2025-64074
5.3

A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 routers allows remote attackers to delete arbi...

Feb 11, 2026
CVE-2026-25152
5.3

A path traversal vulnerability in Backstage's TechDocs local generator allows attackers to read arbitrary files from the host filesystem when processi...

Jan 30, 2026
CVE-2025-67083
5.3

CVE-2025-67083 is a directory traversal vulnerability in InvoicePlane that allows unauthenticated attackers to read arbitrary files from the server. T...

Jan 15, 2026
CVE-2026-21851
5.3

This CVE describes a Path Traversal (Zip Slip) vulnerability in MONAI's _download_from_ngc_private() function that allows attackers to write arbitrary...

Jan 7, 2026
CVE-2025-69226
5.3

This vulnerability in AIOHTTP allows attackers to determine the existence of absolute path components through path normalization logic in static file ...

Jan 5, 2026
CVE-2025-15432
5.3

This is a path traversal vulnerability in yeqifu carRental software that allows attackers to access arbitrary files on the server by manipulating the ...

Jan 2, 2026
CVE-2025-14699
5.3

A path traversal vulnerability in Municorn FAX App 3.27.0 for Android allows local attackers to access files outside the intended directory. This affe...

Dec 15, 2025
CVE-2025-14617
5.3

A path traversal vulnerability in the Jehovah's Witnesses JW Library App for Android allows local attackers to access files outside the intended direc...

Dec 13, 2025
CVE-2025-13876
5.3

This vulnerability allows local attackers to perform path traversal attacks in the Rareprob HD Video Player All Formats App on Android, potentially ov...

Dec 2, 2025
CVE-2025-13810
5.3

A path traversal vulnerability in jsnjfz WebStack-Guns 1.0 allows remote attackers to read arbitrary files on the server by manipulating the renderPic...

Dec 1, 2025
CVE-2025-12972
5.3

CVE-2025-12972 is a path traversal vulnerability in Fluent Bit's out_file plugin that allows attackers to write files outside the intended output dire...

Nov 24, 2025
CVE-2025-64765
5.3

This vulnerability allows attackers to bypass middleware validation checks in Astro web applications by using URL-encoded path variants. The mismatch ...

Nov 19, 2025
CVE-2025-13266
5.3

This CVE describes a path traversal vulnerability in wwwlike vlife software up to version 2.0.1. Attackers can manipulate the fileName parameter in th...

Nov 17, 2025
CVE-2025-13261
5.3

A path traversal vulnerability in the lsfusion platform allows attackers to manipulate the Version parameter in DownloadFileRequestHandler to access a...

Nov 17, 2025
CVE-2025-42919
5.3

CVE-2025-42919 is an information disclosure vulnerability in SAP NetWeaver Application Server Java that allows unauthenticated attackers to access int...

Nov 11, 2025
CVE-2025-53951
5.3

This path traversal vulnerability in Fortinet FortiDLP Agent's Outlookproxy plugin allows authenticated attackers to escalate privileges to LocalServi...

Oct 16, 2025
CVE-2025-42906
5.3

SAP Commerce Cloud contains a path traversal vulnerability that allows users to access the Administration Console from addresses where it's not explic...

Oct 14, 2025
CVE-2025-43889
5.3

Dell PowerProtect Data Domain systems running vulnerable DD OS versions contain a path traversal vulnerability in the UI that allows unauthenticated r...

Oct 7, 2025
CVE-2025-11336
5.3

This CVE describes a path traversal vulnerability in Four-Faith Water Conservancy Informatization Platform that allows attackers to access arbitrary f...

Oct 6, 2025
CVE-2025-11337
5.3

This CVE describes a path traversal vulnerability in Four-Faith Water Conservancy Informatization Platform up to version 2.2. Attackers can remotely m...

Oct 6, 2025
CVE-2025-61586
5.3

FreshRSS versions 1.26.3 and below contain a path traversal vulnerability in the theme field that allows attackers to enumerate server directories. Th...

Sep 30, 2025
CVE-2025-11018
5.3

This CVE describes a path traversal vulnerability in Four-Faith Water Conservancy Informatization Platform 1.0 that allows attackers to access arbitra...

Sep 26, 2025
CVE-2025-56869
5.3

This directory traversal vulnerability in Sync In server allows authenticated attackers to read and write arbitrary files on the system by exploiting ...

Sep 19, 2025
CVE-2025-10708
5.3

This CVE describes a path traversal vulnerability in Four-Faith Water Conservancy Informatization Platform 1.0. Attackers can manipulate the fileName ...

Sep 19, 2025
CVE-2025-10709
5.3

This CVE describes a path traversal vulnerability in Four-Faith Water Conservancy Informatization Platform 1.0. Attackers can manipulate the fileName ...

Sep 19, 2025
CVE-2025-10472
5.3

A path traversal vulnerability in MoneyPrinterTurbo allows attackers to access arbitrary files on the server by manipulating the file_path parameter i...

Sep 15, 2025
CVE-2025-58751
5.3

This vulnerability in Vite allows attackers to bypass server.fs restrictions and access files outside the public directory when specific conditions ar...

Sep 8, 2025
CVE-2025-53505
5.3

Group-Office versions before 6.8.119 and 25.0.20 contain a path traversal vulnerability that allows attackers to access files outside the intended dir...

Aug 21, 2025
CVE-2025-49559
5.3

This CVE describes a path traversal vulnerability in Adobe Commerce that allows attackers to bypass security restrictions and modify limited data with...

Aug 12, 2025
CVE-2025-8516
5.3

This CVE describes a path traversal vulnerability in Kingdee Cloud-Starry-Sky Enterprise Edition that allows attackers to delete arbitrary files by ma...

Aug 4, 2025
CVE-2024-12718
5.3

This CVE describes a path traversal vulnerability in Python's tarfile module when using extraction filters. It allows attackers to modify file metadat...

Jun 3, 2025
CVE-2025-46565
5.3

This vulnerability in Vite allows attackers to bypass file access restrictions and read sensitive files from the project root directory. Only affects ...

May 1, 2025
CVE-2025-27299
5.3

This path traversal vulnerability in the MyTicket Events WordPress plugin allows attackers to read files outside the intended directory. It affects al...

Apr 17, 2025
CVE-2025-3043
5.3

This critical vulnerability in GuoMinJim PersonManage 1.0 allows remote attackers to perform path traversal attacks via the Request parameter in the /...

Apr 1, 2025
CVE-2024-12217
5.3

This vulnerability in the gradio-app/gradio repository allows attackers to bypass file access restrictions on Windows systems using NTFS Alternate Dat...

Mar 20, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,216 CVEs classified as CWE-22, with 531 rated critical and 1,138 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free