CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,216
Total CVEs
531
Critical
1,138
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
246
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Fedoraproject 19
4 Ivanti 19
5 Debian 18
6 Solarwinds 17
7 Fortinet 17
8 Adobe 17
9 Siemens 16
10 Samsung 16

All Path Traversal CVEs (2,216)

CVE-2025-47513
4.9

This path traversal vulnerability in Infocob CRM Forms WordPress plugin allows attackers to download arbitrary files from the server by manipulating f...

May 23, 2025
CVE-2025-46486
4.9

This path traversal vulnerability in the Nomupay Payment Processing Gateway WordPress plugin allows attackers to download arbitrary files from the ser...

May 23, 2025
CVE-2025-3577
4.9

This path traversal vulnerability in Zyxel AMG1302-T10B firmware allows authenticated administrators to access restricted directories via crafted HTTP...

Apr 22, 2025
CVE-2025-31827
4.9

This path traversal vulnerability in the Fonto WordPress plugin allows attackers to download arbitrary files from the server by manipulating file path...

Apr 3, 2025
CVE-2025-1973
4.9

This vulnerability in the Export and Import Users and Customers WordPress plugin allows authenticated attackers with Administrator privileges to perfo...

Mar 22, 2025
CVE-2024-13920
4.9

This vulnerability allows authenticated WordPress administrators to perform directory traversal attacks via the Order Export & Order Import for WooCom...

Mar 20, 2025
CVE-2025-23416
4.9

This path traversal vulnerability (CWE-22) in Ixia/Keysight products allows attackers to delete arbitrary files on the system. It affects Ixia/Keysigh...

Mar 5, 2025
CVE-2024-51966
4.9

A path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below allows authenticated administrators to access files outside intended dire...

Mar 3, 2025
CVE-2024-51958
4.9

A path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below allows remote authenticated attackers with admin privileges to access fil...

Mar 3, 2025
CVE-2025-26779
4.9

This path traversal vulnerability in the Keep Backup Daily WordPress plugin allows attackers to download arbitrary files from the server by manipulati...

Feb 16, 2025
CVE-2024-47264
4.9

This path traversal vulnerability in Synology Active Backup for Business allows authenticated administrators to delete arbitrary files on the system. ...

Feb 13, 2025
CVE-2025-24605
4.9

This path traversal vulnerability in the WOLF WordPress plugin allows attackers to access files outside the intended directory. It affects all WordPre...

Feb 3, 2025
CVE-2023-0092
4.9

This vulnerability allows authenticated users with read access to the Juju controller model to download arbitrary files from the controller's filesyst...

Jan 31, 2025
CVE-2025-24611
4.9

This path traversal vulnerability in WP Ultimate Exporter allows attackers to read arbitrary files on the server by manipulating file paths. It affect...

Jan 24, 2025
CVE-2024-56248
4.9

This path traversal vulnerability in the WPMasterToolKit WordPress plugin allows attackers to download arbitrary files from the server by manipulating...

Jan 2, 2025
CVE-2024-54452
4.9

A directory traversal and local file inclusion vulnerability in Kurmi Provisioning Suite allows authenticated administrators to access arbitrary files...

Dec 27, 2024
CVE-2024-37043
4.9

This path traversal vulnerability in QNAP operating systems allows remote attackers with administrator access to read arbitrary files outside intended...

Nov 22, 2024
CVE-2024-37046
4.9

This path traversal vulnerability in QNAP operating systems allows remote attackers with administrator access to read arbitrary files outside intended...

Nov 22, 2024
CVE-2024-52055
4.9

This vulnerability allows an authenticated administrator user in Wowza Streaming Engine to read arbitrary files on the server through path traversal. ...

Nov 21, 2024
CVE-2024-52396
4.9

This path traversal vulnerability in the WOLF WordPress plugin allows attackers to access files outside the intended directory by manipulating file pa...

Nov 14, 2024
CVE-2024-48224
4.9

Funadmin v5.0.2 contains an arbitrary file read vulnerability in the /curd/index/editfile endpoint. This allows attackers to read sensitive files from...

Oct 25, 2024
CVE-2024-36814
4.9

This vulnerability allows authenticated attackers to read arbitrary files on the underlying operating system with root privileges. It affects Adguard ...

Oct 8, 2024
CVE-2024-37410
4.9

This path traversal vulnerability in PowerPack Lite for Beaver Builder allows attackers to access files outside the intended directory. It affects Wor...

Jul 9, 2024
CVE-2024-37266
4.9

This path traversal vulnerability in Tutor LMS WordPress plugin allows attackers to access files outside the intended directory. It affects all Tutor ...

Jul 9, 2024
CVE-2024-35712
4.9

This path traversal vulnerability in Jordy Meow Database Cleaner WordPress plugin allows attackers to read arbitrary files on the server by manipulati...

Jun 10, 2024
CVE-2024-35634
4.9

This path traversal vulnerability in the Woocommerce - Recent Purchases plugin allows attackers to include local PHP files on the server through impro...

Jun 4, 2024
CVE-2023-23872
4.9

This path traversal vulnerability in the German Mesky GMAce WordPress plugin allows attackers to download arbitrary files from the server by manipulat...

May 17, 2024
CVE-2023-26361
4.9

This vulnerability allows authenticated administrators in Adobe ColdFusion to read arbitrary files on the server through path traversal. Attackers wit...

Mar 23, 2023
CVE-2024-8291
4.8

This vulnerability allows a rogue administrator in Concrete CMS to inject malicious JavaScript code through the Image Editor Background Color feature,...

Sep 25, 2024
CVE-2026-1111
4.7

This CVE describes a path traversal vulnerability in Sanluan PublicCMS that allows attackers to write files to arbitrary locations on the server. The ...

Jan 18, 2026
CVE-2025-15138
4.7

This vulnerability in TinyFileManager allows attackers to perform path traversal attacks by manipulating the 'fullpath' parameter in tinyfilemanager.p...

Dec 28, 2025
CVE-2025-12250
4.7

CVE-2025-12250 is a path traversal vulnerability in OpenWGA 7.11.12 Build 737 that allows attackers to access files outside the intended directory via...

Oct 27, 2025
CVE-2025-11939
4.7

This vulnerability in ChurchCRM allows attackers to perform path traversal attacks via the restoreFile parameter in the backup restore functionality. ...

Oct 19, 2025
CVE-2025-48394
4.7

This vulnerability allows authenticated privileged users to modify non-sensitive files through path traversal in the CLI's limited shell. It affects E...

Aug 6, 2025
CVE-2025-7566
4.7

This critical vulnerability in jshERP allows remote attackers to perform path traversal attacks via the Title parameter in the exportExcelByParam func...

Jul 14, 2025
CVE-2025-2215
4.7

This critical vulnerability in Doufox allows remote attackers to perform path traversal attacks by manipulating the 'dir' parameter in the /?s=doudou&...

Mar 12, 2025
CVE-2023-51646
4.7

This vulnerability allows authenticated remote attackers to bypass authentication and execute arbitrary code on Allegra installations via directory tr...

Nov 22, 2024
CVE-2023-51640
4.7

This vulnerability allows authenticated remote attackers to bypass authentication and execute arbitrary code via a directory traversal flaw in Allegra...

Nov 22, 2024
CVE-2025-11563
4.6

CVE-2025-11563 is a path traversal vulnerability in wcurl where URLs containing percent-encoded slashes (like %2F or %5C) can trick the tool into savi...

Feb 25, 2026
CVE-2025-12757
4.6

CVE-2025-12757 is an information disclosure vulnerability in AXIS Camera Station Pro where non-admin users can access restricted information. This aff...

Feb 10, 2026
CVE-2026-22625
4.6

This vulnerability in HIKSEMI NAS products allows attackers to access sensitive system files through improper filename handling. It affects users of c...

Jan 30, 2026
CVE-2025-54292
4.6

This path traversal vulnerability in Canonical LXD LXD-UI allows authenticated attackers to access or modify resources outside intended directories by...

Oct 2, 2025
CVE-2025-13698
4.5

This vulnerability allows authenticated attackers on the same network to create arbitrary files on OPNsense systems. The flaw exists in the backup con...

Dec 23, 2025
CVE-2025-24889
4.5

A path traversal vulnerability in SecureDrop Client allows attackers with existing code execution in one virtual machine to achieve code execution in ...

Feb 13, 2025
CVE-2026-32061
4.4

OpenClaw versions before 2026.2.17 contain a path traversal vulnerability in the $include directive that allows attackers with config modification cap...

Mar 11, 2026
CVE-2025-62856
4.4

A path traversal vulnerability in QNAP File Station 5 allows local attackers with administrator privileges to read arbitrary files and system data. Th...

Feb 11, 2026
CVE-2025-14702
4.4

A path traversal vulnerability in Smartbit CommV Smartschool App allows attackers with local access to manipulate file paths through the be.smartschoo...

Dec 15, 2025
CVE-2025-14698
4.4

This CVE describes a path traversal vulnerability in the atlaszz AI Photo Team Galleryit App 1.3.8.2 on Android. It allows local attackers to access f...

Dec 15, 2025
CVE-2025-3722
4.4

A path traversal vulnerability in System Information Reporter (SIR) versions 1.0.3 and earlier allows authenticated high-privilege users to create or ...

Jun 26, 2025
CVE-2024-6971
4.4

A path traversal vulnerability in the lollms-webui allows attackers to perform vectorize operations on arbitrary .sqlite files on the victim's compute...

Oct 11, 2024

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,216 CVEs classified as CWE-22, with 531 rated critical and 1,138 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free