CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,216
Total CVEs
531
Critical
1,138
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
246
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 19
4 Fedoraproject 19
5 Debian 18
6 Solarwinds 17
7 Fortinet 17
8 Adobe 17
9 Siemens 16
10 Samsung 16

All Path Traversal CVEs (2,216)

CVE-2026-3188
4.3

This CVE describes a path traversal vulnerability in feiyuchuixue sz-boot-parent up to version 1.3.2-beta. Attackers can manipulate the templateName p...

Feb 25, 2026
CVE-2026-2683
4.3

This CVE describes a path traversal vulnerability in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Attackers can remotely exploit th...

Feb 18, 2026
CVE-2026-2216
4.3

This path traversal vulnerability in rachelos WeRSS we-mp-rss allows remote attackers to read arbitrary files on the server by manipulating the filena...

Feb 9, 2026
CVE-2026-2111
4.3

JeecgBoot versions up to 3.9.0 contain a path traversal vulnerability in the Retrieval-Augmented Generation Module's /airag/knowledge/doc/edit endpoin...

Feb 7, 2026
CVE-2025-63372
4.3

Articentgroup Zip Rar Extractor Tool 1.345.93.0 contains a directory traversal vulnerability in its ZIP file processing component. Attackers can explo...

Feb 3, 2026
CVE-2026-1549
4.3

This CVE describes a path traversal vulnerability in jishenghua jshERP's PluginController component. Attackers can exploit the /jshERP-boot/plugin/upl...

Jan 28, 2026
CVE-2026-0571
4.3

This CVE describes a path traversal vulnerability in the yeqifu warehouse software that allows attackers to read arbitrary files on the server by mani...

Jan 2, 2026
CVE-2025-14910
4.3

This CVE describes a path traversal vulnerability in the FTP daemon service of Edimax BR-6208AC routers. Attackers can exploit this remotely to access...

Dec 19, 2025
CVE-2025-67653
4.3

Advantech WebAccess/SCADA is vulnerable to directory traversal (CWE-22), allowing attackers to check if arbitrary files exist on the system. This affe...

Dec 18, 2025
CVE-2025-14521
4.3

This CVE describes a path traversal vulnerability in baowzh hfly's admin interface that allows attackers to read arbitrary files on the server. The vu...

Dec 11, 2025
CVE-2025-67643
4.3

The Jenkins Redpen - Pipeline Reporter for Jira Plugin vulnerability allows attackers with Item/Configure permission to bypass path validation and ret...

Dec 10, 2025
CVE-2025-65287
4.3

An unauthenticated directory traversal vulnerability in SNMP Web Pro 1.1 allows remote attackers to read arbitrary files on the server. The vulnerabil...

Dec 9, 2025
CVE-2025-14224
4.3

A path traversal vulnerability in Yottamaster DM2, DM3, and DM200 NAS devices allows attackers to upload files to arbitrary locations via the file upl...

Dec 8, 2025
CVE-2025-14220
4.3

This vulnerability in ORICO CD3510 version 1.9.12 allows remote attackers to perform path traversal attacks via the file upload component. This could ...

Dec 8, 2025
CVE-2025-29844
4.3

This vulnerability allows remote authenticated users to read file metadata and path information through a FileStation CGI component. It affects Synolo...

Dec 4, 2025
CVE-2025-29845
4.3

This vulnerability allows authenticated users to read .srt subtitle files on Synology Video Station systems. It affects Synology Video Station install...

Dec 4, 2025
CVE-2025-12626
4.3

This CVE describes a path traversal vulnerability in jeecgboot jeewx-boot that allows attackers to manipulate the imgurl parameter to access arbitrary...

Nov 3, 2025
CVE-2025-11914
4.3

This CVE describes a path traversal vulnerability in Shenzhen Ruiming Technology's Streamax Crocus system version 1.3.40. Attackers can manipulate the...

Oct 17, 2025
CVE-2025-11913
4.3

This CVE describes a path traversal vulnerability in Shenzhen Ruiming Technology's Streamax Crocus system version 1.3.40. Attackers can remotely explo...

Oct 17, 2025
CVE-2025-11034
4.3

This CVE describes a path traversal vulnerability in Dibo Data Decision Making System's downloadImpTemplet function. Attackers can manipulate the file...

Sep 26, 2025
CVE-2025-11016
4.3

A path traversal vulnerability in kodbox up to version 1.61.09 allows attackers to access files outside the intended directory by manipulating the 'pa...

Sep 26, 2025
CVE-2025-10766
4.3

This CVE describes a path traversal vulnerability in SeriaWei ZKEACMS up to version 4.3. Attackers can manipulate the ID parameter in the Download fun...

Sep 21, 2025
CVE-2025-10236
4.3

This vulnerability allows attackers to perform path traversal attacks through the LaTeX file handler in gpt_academic. By manipulating the \input{} arg...

Sep 11, 2025
CVE-2025-10245
4.3

A path traversal vulnerability in Display Painéis TGA allows attackers to access files outside the intended directory by manipulating the 'current_fo...

Sep 11, 2025
CVE-2025-34176
4.3

This vulnerability allows authenticated attackers with 'WebCfg - Services: suricata package' permissions to perform directory traversal attacks in pfS...

Sep 9, 2025
CVE-2025-34173
4.3

This vulnerability allows authenticated attackers with Snort package permissions to perform directory traversal attacks in pfSense CE's Snort IP reput...

Sep 9, 2025
CVE-2025-6465
4.3

This vulnerability allows authenticated users with file upload permissions to overwrite file attachment thumbnails via path traversal in Mattermost's ...

Aug 21, 2025
CVE-2025-54959
4.3

Powered BLUE Server versions 0.20130927 and prior contain a path traversal vulnerability that allows attackers to read arbitrary files on the server. ...

Aug 8, 2025
CVE-2025-7625
4.3

This critical vulnerability in YiJiuSmile kkFileViewOfficeEdit allows remote attackers to perform path traversal attacks via the 'url' parameter in th...

Jul 14, 2025
CVE-2025-6854
4.3

This path traversal vulnerability in Langchain-Chatchat allows attackers to access files outside the intended directory via the /v1/files endpoint. It...

Jun 29, 2025
CVE-2025-5880
4.3

This path traversal vulnerability in Whistle 2.9.98 allows attackers to access arbitrary files on the server by manipulating the filename parameter in...

Jun 9, 2025
CVE-2025-5714
4.3

This CVE describes a path traversal vulnerability in SoluçõesCoop iSoluçõesWEB's profile update component. Attackers can manipulate the 'nomeArqui...

Jun 6, 2025
CVE-2025-5544
4.3

This CVE describes a path traversal vulnerability in the aaluoxiang oa_system that allows attackers to read arbitrary files on the server. The vulnera...

Jun 3, 2025
CVE-2025-5160
4.3

A path traversal vulnerability in H3C SecCenter SMP-E1114P02 allows attackers to access arbitrary files on the system by manipulating the 'Name' param...

May 26, 2025
CVE-2025-5158
4.3

This CVE describes a path traversal vulnerability in H3C SecCenter SMP-E1114P02 that allows attackers to access arbitrary files on the system by manip...

May 25, 2025
CVE-2025-4530
4.3

This CVE describes a path traversal vulnerability in the feng_ha_ha/megagao ssm-erp and production_ssm software versions 1.0. Attackers can exploit th...

May 11, 2025
CVE-2025-4329
4.3

This vulnerability in 74CMS allows attackers to perform path traversal attacks by manipulating the 'url' parameter in the download function. Attackers...

May 6, 2025
CVE-2025-4078
4.3

This vulnerability in Wangshen SecGate 3600 2400 allows attackers to perform path traversal attacks via the file_name parameter in the log_export_file...

Apr 29, 2025
CVE-2024-30143
4.3

This vulnerability in HCL AppScan Traffic Recorder allows attackers to bypass directory restrictions through filename manipulation, potentially access...

Mar 13, 2025
CVE-2022-25773
4.3

CVE-2022-25773 is a path traversal vulnerability in Mautic's asset upload functionality that allows authenticated users to upload files to directories...

Feb 26, 2025
CVE-2025-1543
4.3

This vulnerability in iteachyou Dreamer CMS 4.1.3 allows remote attackers to perform path traversal attacks via the /resource/js/ueditor-1.4.3.3 file....

Feb 21, 2025
CVE-2025-1336
4.3

This path traversal vulnerability in CmsEasy 7.7.7.9 allows attackers to delete arbitrary files on the server by manipulating the imgname parameter in...

Feb 16, 2025
CVE-2025-1228
4.3

This vulnerability allows remote attackers to perform path traversal attacks in olajowon Loggrove's Logfile Update Handler. By manipulating the 'path'...

Feb 12, 2025
CVE-2024-8685
4.3

This path traversal vulnerability in Revolution Pi allows authenticated attackers to list directories on the device by manipulating the 'dir' paramete...

Feb 10, 2025
CVE-2025-0572
4.3

This vulnerability allows authenticated remote attackers to write arbitrary files to the Sante PACS Server filesystem via directory traversal in DCM f...

Jan 30, 2025
CVE-2025-0703
4.3

This CVE describes a path traversal vulnerability in JoeyBling bootplus that allows attackers to access files outside the intended directory by manipu...

Jan 24, 2025
CVE-2025-0461
4.3

This CVE describes a path traversal vulnerability in Shanghai Lingdang Information Technology's Lingdang CRM software. Attackers can manipulate the 'p...

Jan 14, 2025
CVE-2024-12429
4.3

An authenticated attacker can exploit this vulnerability in AC500 V3 products to read system-wide files and configurations. This affects all AC500 V3 ...

Jan 7, 2025
CVE-2024-12793
4.3

This CVE-2024-12793 is a path traversal vulnerability in PbootCMS that allows attackers to access files outside the intended directory by manipulating...

Dec 19, 2024
CVE-2024-12362
4.3

This CVE describes a path traversal vulnerability in InvoicePlane's invoices.php file that allows attackers to access arbitrary files on the server by...

Dec 16, 2024

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,216 CVEs classified as CWE-22, with 531 rated critical and 1,138 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free