CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,216
Total CVEs
531
Critical
1,138
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
246
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 19
4 Fedoraproject 19
5 Debian 18
6 Solarwinds 17
7 Fortinet 17
8 Adobe 17
9 Siemens 16
10 Samsung 16

All Path Traversal CVEs (2,216)

CVE-2025-1743
5.3

This critical vulnerability in Pichome 2.1.0 allows remote attackers to perform path traversal attacks via the 'src' parameter in /index.php?mod=textv...

Feb 27, 2025
CVE-2023-38012
5.3

This vulnerability allows remote attackers to perform directory traversal attacks on IBM Cloud Pak System. By sending specially crafted URLs containin...

Jan 25, 2025
CVE-2024-42187
5.3

BigFix Patch Download Plug-ins contain a path traversal vulnerability (CWE-22) that allows authenticated operators to download arbitrary files from th...

Jan 23, 2025
CVE-2025-0615
5.3

This input validation vulnerability in Qualifio's Wheel of Fortune allows attackers to bypass email validation by adding '+' symbols to email addresse...

Jan 21, 2025
CVE-2024-48885
5.3

This path traversal vulnerability (CWE-22) in multiple Fortinet products allows attackers to escalate privileges by sending specially crafted packets....

Jan 16, 2025
CVE-2025-0401
5.3

This critical path traversal vulnerability in the Reggie 1.0 application allows attackers to access arbitrary files on the server by manipulating the ...

Jan 13, 2025
CVE-2024-10585
5.3

The InfiniteWP Client WordPress plugin contains a path traversal vulnerability that allows unauthenticated attackers to read .txt files outside intend...

Jan 8, 2025
CVE-2024-42499
5.3

This path traversal vulnerability in FitNesse allows attackers to check for file existence and potentially read partial file contents by manipulating ...

Nov 15, 2024
CVE-2024-50843
5.3

This vulnerability allows remote attackers to view directory listings in PHPGurukul User Registration & Login and User Management System 3.2 via the /...

Nov 14, 2024
CVE-2024-49766
5.3

This vulnerability in Werkzeug's safe_join() function on Windows with Python < 3.11 allows UNC path bypass, potentially enabling directory traversal a...

Oct 25, 2024
CVE-2024-47563
5.3

An unauthenticated remote attacker can exploit a path traversal vulnerability in Siemens SINEC Security Monitor to write files outside intended direct...

Oct 8, 2024
CVE-2024-43281
5.3

This vulnerability allows attackers to read arbitrary files on WordPress servers by exploiting a path traversal flaw in the Void Elementor Post Grid A...

Aug 19, 2024
CVE-2024-22377
5.3

This vulnerability allows unauthorized users to access the deploy directory on PingFederate runtime nodes, potentially exposing sensitive configuratio...

Jul 9, 2024
CVE-2023-47803
5.3

A path traversal vulnerability in Synology Camera firmware allows remote attackers to read specific non-sensitive files via the Language Settings func...

Jun 28, 2024
CVE-2024-5019
5.3

This vulnerability allows unauthenticated attackers to read arbitrary files on WhatsUp Gold servers with IIS application pool privileges. It affects W...

Jun 25, 2024
CVE-2024-33881
5.3

This vulnerability in Virto Bulk File Download for SharePoint allows attackers to force the server to authenticate to a malicious UNC share, potential...

Jun 24, 2024
CVE-2024-4576
5.3

This CVE describes a directory traversal vulnerability in TIBCO EBX software that allows attackers to access sensitive files outside the intended dire...

Jun 13, 2024
CVE-2024-37169
5.3

This vulnerability in @jmondi/url-to-png allows attackers to read arbitrary files from the server by exploiting Playwright's screenshot feature with f...

Jun 10, 2024
CVE-2024-5550
5.3

This vulnerability in h2oai/h2o-3 version 3.40.0.4 allows remote attackers to view the entire filesystem path structure where the application is hoste...

Jun 6, 2024
CVE-2025-53622
5.2

DSpace has a path traversal vulnerability in its Simple Archive Format (SAF) import functionality that allows attackers to read arbitrary files on the...

Jul 15, 2025
CVE-2025-20949
5.1

A path traversal vulnerability in Samsung Members app allows attackers to read and write arbitrary files with the app's privileges. This affects Samsu...

May 7, 2025
CVE-2024-57777
5.1

A directory traversal vulnerability in Ianproxy v0.1 and earlier allows remote attackers to access sensitive files outside the intended directory. Thi...

Feb 11, 2025
CVE-2024-47566
5.1

This path traversal vulnerability in Fortinet FortiRecorder allows privileged attackers to delete arbitrary files from the underlying filesystem via c...

Jan 14, 2025
CVE-2025-69619
5.0

A path traversal vulnerability in My Text Editor v1.6.2 allows attackers to write arbitrary files to internal storage, potentially causing Denial of S...

Feb 5, 2026
CVE-2025-69620
5.0

A path traversal vulnerability in Moo Chan Song v4.5.7 allows attackers to write arbitrary files to internal storage, potentially causing Denial of Se...

Feb 4, 2026
CVE-2026-25228
5.0

Signal K Server versions prior to 2.20.3 on Windows systems contain a path traversal vulnerability in the applicationData API. Authenticated users can...

Feb 2, 2026
CVE-2025-14111
5.0

This CVE describes a path traversal vulnerability in Rarlab RAR App for Android that allows attackers to read or write arbitrary files remotely. Only ...

Dec 5, 2025
CVE-2025-8522
5.0

This critical vulnerability in Vvvebjs allows remote attackers to perform path traversal attacks via the 'File' parameter in /save.php. Attackers can ...

Aug 4, 2025
CVE-2024-10933
5.0

This vulnerability in OpenBSD's readdir function allows directory traversal attacks when processing untrusted file systems. Attackers could potentiall...

Dec 5, 2024
CVE-2024-22231
5.0

This vulnerability allows an attacker to create arbitrary directories on a Salt master via directory traversal in the syndic cache directory creation....

Jun 27, 2024
CVE-2024-32111
5.0

This path traversal vulnerability in WordPress allows authenticated users with contributor-level permissions to read arbitrary HTML files on Windows s...

Jun 25, 2024
CVE-2025-13681
4.9

The BFG Tools – Extension Zipper WordPress plugin up to version 1.0.7 contains a path traversal vulnerability in the zip() function. Authenticated a...

Feb 14, 2026
CVE-2025-54162
4.9

This path traversal vulnerability in QNAP File Station 5 allows authenticated administrators to read arbitrary files on the system. Attackers who comp...

Feb 11, 2026
CVE-2026-1246
4.9

The ShortPixel Image Optimizer WordPress plugin contains a path traversal vulnerability that allows authenticated attackers with Editor-level permissi...

Feb 5, 2026
CVE-2025-15487
4.9

The Code Explorer WordPress plugin up to version 1.4.6 contains a path traversal vulnerability in the 'file' parameter. This allows authenticated atta...

Feb 4, 2026
CVE-2025-59381
4.9

A path traversal vulnerability in QNAP operating systems allows authenticated administrators to read arbitrary files. This affects QNAP NAS devices ru...

Jan 2, 2026
CVE-2025-59380
4.9

This CVE describes a path traversal vulnerability in QNAP operating systems that allows authenticated attackers with administrator privileges to read ...

Jan 2, 2026
CVE-2025-12496
4.9

The Zephyr Project Manager WordPress plugin has a directory traversal vulnerability that allows authenticated users with Custom-level access or higher...

Dec 17, 2025
CVE-2025-67819
4.9

This vulnerability in Weaviate OSS allows attackers to read arbitrary files accessible to the service process when specific conditions are met. It aff...

Dec 12, 2025
CVE-2025-13972
4.9

The WatchTowerHQ WordPress plugin contains an arbitrary file read vulnerability that allows authenticated attackers with administrator privileges and ...

Dec 12, 2025
CVE-2025-13677
4.9

The Simple Download Counter WordPress plugin has a path traversal vulnerability that allows authenticated attackers with Administrator privileges to r...

Dec 10, 2025
CVE-2025-20374
4.9

This vulnerability allows authenticated administrators in Cisco Unified CCX web UI to perform directory traversal attacks, potentially accessing arbit...

Nov 5, 2025
CVE-2025-37144
4.9

This vulnerability allows authenticated attackers to download arbitrary files from affected Aruba networking devices through path traversal attacks. I...

Oct 14, 2025
CVE-2025-37145
4.9

This vulnerability allows authenticated attackers to download arbitrary files from AOS-10 GW and AOS-8 Controller/Mobility Conductor systems through a...

Oct 14, 2025
CVE-2025-9950
4.9

The Error Log Viewer WordPress plugin contains a directory traversal vulnerability that allows authenticated attackers with Administrator privileges t...

Oct 11, 2025
CVE-2025-47211
4.9

A path traversal vulnerability in QNAP operating systems allows authenticated attackers with administrator privileges to read arbitrary files. This af...

Oct 3, 2025
CVE-2025-33032
4.9

A path traversal vulnerability in QNAP operating systems allows authenticated attackers with administrator privileges to read arbitrary files. This af...

Aug 29, 2025
CVE-2025-54715
4.9

This path traversal vulnerability in the Barcode Scanner with Inventory & Order Manager WordPress plugin allows attackers to download arbitrary files ...

Aug 14, 2025
CVE-2023-39339
4.9

This vulnerability allows authenticated administrators on Ivanti Policy Secure to read arbitrary files through specially crafted web requests. It affe...

Jul 12, 2025
CVE-2025-53298
4.9

This path traversal vulnerability in the WordPress Plugin Inspector plugin allows attackers to download arbitrary files from the server by manipulatin...

Jun 27, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,216 CVEs classified as CWE-22, with 531 rated critical and 1,138 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free