CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (2,216)
This path traversal vulnerability in Infocob CRM Forms WordPress plugin allows attackers to download arbitrary files from the server by manipulating f...
May 23, 2025This path traversal vulnerability in the Nomupay Payment Processing Gateway WordPress plugin allows attackers to download arbitrary files from the ser...
May 23, 2025This path traversal vulnerability in Zyxel AMG1302-T10B firmware allows authenticated administrators to access restricted directories via crafted HTTP...
Apr 22, 2025This path traversal vulnerability in the Fonto WordPress plugin allows attackers to download arbitrary files from the server by manipulating file path...
Apr 3, 2025This vulnerability in the Export and Import Users and Customers WordPress plugin allows authenticated attackers with Administrator privileges to perfo...
Mar 22, 2025This vulnerability allows authenticated WordPress administrators to perform directory traversal attacks via the Order Export & Order Import for WooCom...
Mar 20, 2025This path traversal vulnerability (CWE-22) in Ixia/Keysight products allows attackers to delete arbitrary files on the system. It affects Ixia/Keysigh...
Mar 5, 2025A path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below allows authenticated administrators to access files outside intended dire...
Mar 3, 2025A path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below allows remote authenticated attackers with admin privileges to access fil...
Mar 3, 2025This path traversal vulnerability in the Keep Backup Daily WordPress plugin allows attackers to download arbitrary files from the server by manipulati...
Feb 16, 2025This path traversal vulnerability in Synology Active Backup for Business allows authenticated administrators to delete arbitrary files on the system. ...
Feb 13, 2025This path traversal vulnerability in the WOLF WordPress plugin allows attackers to access files outside the intended directory. It affects all WordPre...
Feb 3, 2025This vulnerability allows authenticated users with read access to the Juju controller model to download arbitrary files from the controller's filesyst...
Jan 31, 2025This path traversal vulnerability in WP Ultimate Exporter allows attackers to read arbitrary files on the server by manipulating file paths. It affect...
Jan 24, 2025This path traversal vulnerability in the WPMasterToolKit WordPress plugin allows attackers to download arbitrary files from the server by manipulating...
Jan 2, 2025A directory traversal and local file inclusion vulnerability in Kurmi Provisioning Suite allows authenticated administrators to access arbitrary files...
Dec 27, 2024This path traversal vulnerability in QNAP operating systems allows remote attackers with administrator access to read arbitrary files outside intended...
Nov 22, 2024This path traversal vulnerability in QNAP operating systems allows remote attackers with administrator access to read arbitrary files outside intended...
Nov 22, 2024This vulnerability allows an authenticated administrator user in Wowza Streaming Engine to read arbitrary files on the server through path traversal. ...
Nov 21, 2024This path traversal vulnerability in the WOLF WordPress plugin allows attackers to access files outside the intended directory by manipulating file pa...
Nov 14, 2024Funadmin v5.0.2 contains an arbitrary file read vulnerability in the /curd/index/editfile endpoint. This allows attackers to read sensitive files from...
Oct 25, 2024This vulnerability allows authenticated attackers to read arbitrary files on the underlying operating system with root privileges. It affects Adguard ...
Oct 8, 2024This path traversal vulnerability in PowerPack Lite for Beaver Builder allows attackers to access files outside the intended directory. It affects Wor...
Jul 9, 2024This path traversal vulnerability in Tutor LMS WordPress plugin allows attackers to access files outside the intended directory. It affects all Tutor ...
Jul 9, 2024This path traversal vulnerability in Jordy Meow Database Cleaner WordPress plugin allows attackers to read arbitrary files on the server by manipulati...
Jun 10, 2024This path traversal vulnerability in the Woocommerce - Recent Purchases plugin allows attackers to include local PHP files on the server through impro...
Jun 4, 2024This path traversal vulnerability in the German Mesky GMAce WordPress plugin allows attackers to download arbitrary files from the server by manipulat...
May 17, 2024This vulnerability allows authenticated administrators in Adobe ColdFusion to read arbitrary files on the server through path traversal. Attackers wit...
Mar 23, 2023This vulnerability allows a rogue administrator in Concrete CMS to inject malicious JavaScript code through the Image Editor Background Color feature,...
Sep 25, 2024This CVE describes a path traversal vulnerability in Sanluan PublicCMS that allows attackers to write files to arbitrary locations on the server. The ...
Jan 18, 2026This vulnerability in TinyFileManager allows attackers to perform path traversal attacks by manipulating the 'fullpath' parameter in tinyfilemanager.p...
Dec 28, 2025CVE-2025-12250 is a path traversal vulnerability in OpenWGA 7.11.12 Build 737 that allows attackers to access files outside the intended directory via...
Oct 27, 2025This vulnerability in ChurchCRM allows attackers to perform path traversal attacks via the restoreFile parameter in the backup restore functionality. ...
Oct 19, 2025This vulnerability allows authenticated privileged users to modify non-sensitive files through path traversal in the CLI's limited shell. It affects E...
Aug 6, 2025This critical vulnerability in jshERP allows remote attackers to perform path traversal attacks via the Title parameter in the exportExcelByParam func...
Jul 14, 2025This critical vulnerability in Doufox allows remote attackers to perform path traversal attacks by manipulating the 'dir' parameter in the /?s=doudou&...
Mar 12, 2025This vulnerability allows authenticated remote attackers to bypass authentication and execute arbitrary code on Allegra installations via directory tr...
Nov 22, 2024This vulnerability allows authenticated remote attackers to bypass authentication and execute arbitrary code via a directory traversal flaw in Allegra...
Nov 22, 2024CVE-2025-11563 is a path traversal vulnerability in wcurl where URLs containing percent-encoded slashes (like %2F or %5C) can trick the tool into savi...
Feb 25, 2026CVE-2025-12757 is an information disclosure vulnerability in AXIS Camera Station Pro where non-admin users can access restricted information. This aff...
Feb 10, 2026This vulnerability in HIKSEMI NAS products allows attackers to access sensitive system files through improper filename handling. It affects users of c...
Jan 30, 2026This path traversal vulnerability in Canonical LXD LXD-UI allows authenticated attackers to access or modify resources outside intended directories by...
Oct 2, 2025This vulnerability allows authenticated attackers on the same network to create arbitrary files on OPNsense systems. The flaw exists in the backup con...
Dec 23, 2025A path traversal vulnerability in SecureDrop Client allows attackers with existing code execution in one virtual machine to achieve code execution in ...
Feb 13, 2025OpenClaw versions before 2026.2.17 contain a path traversal vulnerability in the $include directive that allows attackers with config modification cap...
Mar 11, 2026A path traversal vulnerability in QNAP File Station 5 allows local attackers with administrator privileges to read arbitrary files and system data. Th...
Feb 11, 2026A path traversal vulnerability in Smartbit CommV Smartschool App allows attackers with local access to manipulate file paths through the be.smartschoo...
Dec 15, 2025This CVE describes a path traversal vulnerability in the atlaszz AI Photo Team Galleryit App 1.3.8.2 on Android. It allows local attackers to access f...
Dec 15, 2025A path traversal vulnerability in System Information Reporter (SIR) versions 1.0.3 and earlier allows authenticated high-privilege users to create or ...
Jun 26, 2025A path traversal vulnerability in the lollms-webui allows attackers to perform vectorize operations on arbitrary .sqlite files on the victim's compute...
Oct 11, 2024About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 2,216 CVEs classified as CWE-22, with 531 rated critical and 1,138 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free