CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (2,216)
This critical vulnerability in Pichome 2.1.0 allows remote attackers to perform path traversal attacks via the 'src' parameter in /index.php?mod=textv...
Feb 27, 2025This vulnerability allows remote attackers to perform directory traversal attacks on IBM Cloud Pak System. By sending specially crafted URLs containin...
Jan 25, 2025BigFix Patch Download Plug-ins contain a path traversal vulnerability (CWE-22) that allows authenticated operators to download arbitrary files from th...
Jan 23, 2025This input validation vulnerability in Qualifio's Wheel of Fortune allows attackers to bypass email validation by adding '+' symbols to email addresse...
Jan 21, 2025This path traversal vulnerability (CWE-22) in multiple Fortinet products allows attackers to escalate privileges by sending specially crafted packets....
Jan 16, 2025This critical path traversal vulnerability in the Reggie 1.0 application allows attackers to access arbitrary files on the server by manipulating the ...
Jan 13, 2025The InfiniteWP Client WordPress plugin contains a path traversal vulnerability that allows unauthenticated attackers to read .txt files outside intend...
Jan 8, 2025This path traversal vulnerability in FitNesse allows attackers to check for file existence and potentially read partial file contents by manipulating ...
Nov 15, 2024This vulnerability allows remote attackers to view directory listings in PHPGurukul User Registration & Login and User Management System 3.2 via the /...
Nov 14, 2024This vulnerability in Werkzeug's safe_join() function on Windows with Python < 3.11 allows UNC path bypass, potentially enabling directory traversal a...
Oct 25, 2024An unauthenticated remote attacker can exploit a path traversal vulnerability in Siemens SINEC Security Monitor to write files outside intended direct...
Oct 8, 2024This vulnerability allows attackers to read arbitrary files on WordPress servers by exploiting a path traversal flaw in the Void Elementor Post Grid A...
Aug 19, 2024This vulnerability allows unauthorized users to access the deploy directory on PingFederate runtime nodes, potentially exposing sensitive configuratio...
Jul 9, 2024A path traversal vulnerability in Synology Camera firmware allows remote attackers to read specific non-sensitive files via the Language Settings func...
Jun 28, 2024This vulnerability allows unauthenticated attackers to read arbitrary files on WhatsUp Gold servers with IIS application pool privileges. It affects W...
Jun 25, 2024This vulnerability in Virto Bulk File Download for SharePoint allows attackers to force the server to authenticate to a malicious UNC share, potential...
Jun 24, 2024This CVE describes a directory traversal vulnerability in TIBCO EBX software that allows attackers to access sensitive files outside the intended dire...
Jun 13, 2024This vulnerability in @jmondi/url-to-png allows attackers to read arbitrary files from the server by exploiting Playwright's screenshot feature with f...
Jun 10, 2024This vulnerability in h2oai/h2o-3 version 3.40.0.4 allows remote attackers to view the entire filesystem path structure where the application is hoste...
Jun 6, 2024DSpace has a path traversal vulnerability in its Simple Archive Format (SAF) import functionality that allows attackers to read arbitrary files on the...
Jul 15, 2025A path traversal vulnerability in Samsung Members app allows attackers to read and write arbitrary files with the app's privileges. This affects Samsu...
May 7, 2025A directory traversal vulnerability in Ianproxy v0.1 and earlier allows remote attackers to access sensitive files outside the intended directory. Thi...
Feb 11, 2025This path traversal vulnerability in Fortinet FortiRecorder allows privileged attackers to delete arbitrary files from the underlying filesystem via c...
Jan 14, 2025A path traversal vulnerability in My Text Editor v1.6.2 allows attackers to write arbitrary files to internal storage, potentially causing Denial of S...
Feb 5, 2026A path traversal vulnerability in Moo Chan Song v4.5.7 allows attackers to write arbitrary files to internal storage, potentially causing Denial of Se...
Feb 4, 2026Signal K Server versions prior to 2.20.3 on Windows systems contain a path traversal vulnerability in the applicationData API. Authenticated users can...
Feb 2, 2026This CVE describes a path traversal vulnerability in Rarlab RAR App for Android that allows attackers to read or write arbitrary files remotely. Only ...
Dec 5, 2025This critical vulnerability in Vvvebjs allows remote attackers to perform path traversal attacks via the 'File' parameter in /save.php. Attackers can ...
Aug 4, 2025This vulnerability in OpenBSD's readdir function allows directory traversal attacks when processing untrusted file systems. Attackers could potentiall...
Dec 5, 2024This vulnerability allows an attacker to create arbitrary directories on a Salt master via directory traversal in the syndic cache directory creation....
Jun 27, 2024This path traversal vulnerability in WordPress allows authenticated users with contributor-level permissions to read arbitrary HTML files on Windows s...
Jun 25, 2024The BFG Tools – Extension Zipper WordPress plugin up to version 1.0.7 contains a path traversal vulnerability in the zip() function. Authenticated a...
Feb 14, 2026This path traversal vulnerability in QNAP File Station 5 allows authenticated administrators to read arbitrary files on the system. Attackers who comp...
Feb 11, 2026The ShortPixel Image Optimizer WordPress plugin contains a path traversal vulnerability that allows authenticated attackers with Editor-level permissi...
Feb 5, 2026The Code Explorer WordPress plugin up to version 1.4.6 contains a path traversal vulnerability in the 'file' parameter. This allows authenticated atta...
Feb 4, 2026A path traversal vulnerability in QNAP operating systems allows authenticated administrators to read arbitrary files. This affects QNAP NAS devices ru...
Jan 2, 2026This CVE describes a path traversal vulnerability in QNAP operating systems that allows authenticated attackers with administrator privileges to read ...
Jan 2, 2026The Zephyr Project Manager WordPress plugin has a directory traversal vulnerability that allows authenticated users with Custom-level access or higher...
Dec 17, 2025This vulnerability in Weaviate OSS allows attackers to read arbitrary files accessible to the service process when specific conditions are met. It aff...
Dec 12, 2025The WatchTowerHQ WordPress plugin contains an arbitrary file read vulnerability that allows authenticated attackers with administrator privileges and ...
Dec 12, 2025The Simple Download Counter WordPress plugin has a path traversal vulnerability that allows authenticated attackers with Administrator privileges to r...
Dec 10, 2025This vulnerability allows authenticated administrators in Cisco Unified CCX web UI to perform directory traversal attacks, potentially accessing arbit...
Nov 5, 2025This vulnerability allows authenticated attackers to download arbitrary files from affected Aruba networking devices through path traversal attacks. I...
Oct 14, 2025This vulnerability allows authenticated attackers to download arbitrary files from AOS-10 GW and AOS-8 Controller/Mobility Conductor systems through a...
Oct 14, 2025The Error Log Viewer WordPress plugin contains a directory traversal vulnerability that allows authenticated attackers with Administrator privileges t...
Oct 11, 2025A path traversal vulnerability in QNAP operating systems allows authenticated attackers with administrator privileges to read arbitrary files. This af...
Oct 3, 2025A path traversal vulnerability in QNAP operating systems allows authenticated attackers with administrator privileges to read arbitrary files. This af...
Aug 29, 2025This path traversal vulnerability in the Barcode Scanner with Inventory & Order Manager WordPress plugin allows attackers to download arbitrary files ...
Aug 14, 2025This vulnerability allows authenticated administrators on Ivanti Policy Secure to read arbitrary files through specially crafted web requests. It affe...
Jul 12, 2025This path traversal vulnerability in the WordPress Plugin Inspector plugin allows attackers to download arbitrary files from the server by manipulatin...
Jun 27, 2025About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 2,216 CVEs classified as CWE-22, with 531 rated critical and 1,138 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free