CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (2,221)
This CVE describes a path traversal vulnerability in JoeyBling bootplus that allows attackers to access files outside the intended directory by manipu...
Jan 24, 2025This CVE describes a path traversal vulnerability in Shanghai Lingdang Information Technology's Lingdang CRM software. Attackers can manipulate the 'p...
Jan 14, 2025An authenticated attacker can exploit this vulnerability in AC500 V3 products to read system-wide files and configurations. This affects all AC500 V3 ...
Jan 7, 2025This CVE-2024-12793 is a path traversal vulnerability in PbootCMS that allows attackers to access files outside the intended directory by manipulating...
Dec 19, 2024This CVE describes a path traversal vulnerability in InvoicePlane's invoices.php file that allows attackers to access arbitrary files on the server by...
Dec 16, 2024This CVE describes a path traversal vulnerability in Samsung's Quick Share Agent on Android devices. It allows adjacent attackers (on the same network...
Dec 3, 2024This path traversal vulnerability in Samsung's ThemeCenter allows physical attackers with device access to copy APK files to arbitrary locations using...
Dec 3, 2024This vulnerability affects multiple Siemens industrial network devices where improper filename validation for certificates allows authenticated remote...
Nov 12, 2024RockOA v2.6.5 contains a directory traversal vulnerability in the beifenAction.php file that allows attackers to read arbitrary files on the server by...
Oct 23, 2024This path traversal vulnerability in TpMeCMS allows attackers to access files outside the intended directory by manipulating the 'lang' parameter in t...
Sep 15, 2024This vulnerability allows remote attackers to perform path traversal attacks in Yunke Online School System versions up to 3.0.6. By manipulating the '...
Sep 12, 2024This vulnerability allows remote attackers to perform path traversal attacks via the 'sitio' parameter in the /abcd/opac/php/otros_sitios.php file in ...
Sep 4, 2024This CVE describes a path traversal vulnerability in BeikeShop's exportZip function that allows attackers to access files outside the intended directo...
Aug 26, 2024The WordPress File Upload plugin contains a directory traversal vulnerability that allows authenticated attackers with Contributor-level access or hig...
Jul 16, 2024This vulnerability allows remote attackers to perform directory traversal attacks on IBM Datacap Navigator systems. By sending specially crafted URLs ...
Jul 15, 2024This vulnerability allows directory traversal attacks in Django applications that use custom Storage subclasses. Attackers can potentially read or wri...
Jul 10, 2024The Spectra WordPress plugin (formerly Ultimate Addons for Gutenberg) has a path traversal vulnerability that allows authenticated users with contribu...
May 2, 2024This CVE describes a directory traversal vulnerability in SaltStack's master cache creation that allows attackers to write or overwrite files outside ...
Jun 13, 2025CVE-2026-29190 is a path traversal vulnerability in Karapace's backup reader that allows arbitrary file read when processing malicious backup files. T...
Mar 7, 2026A path traversal vulnerability in Vim's tar.vim plugin allows specially crafted tar archives to overwrite arbitrary files when opened. This affects Vi...
Jul 15, 2025A path traversal vulnerability in Samsung's Document scanner allows local attackers to delete arbitrary files with the application's elevated privileg...
Aug 6, 2025A path validation vulnerability in macOS allows applications to escape their sandbox restrictions. This affects macOS Ventura, Sonoma, and Sequoia ver...
Jul 30, 2025A path validation vulnerability in macOS allows applications to bypass directory restrictions and access protected user data. This affects macOS Ventu...
Jul 30, 2025This vulnerability involves insecure permissions in Netgear WNR614 JNR1010V2 routers, allowing attackers to access URLs and directories embedded withi...
Jun 6, 2024This CVE describes a path traversal vulnerability in MuYuCMS 2.7's Template Management Page. Attackers can remotely exploit the delete_dir_file functi...
Feb 24, 2026This vulnerability in GreenCMS allows remote attackers to perform path traversal attacks by manipulating sqlFiles or zipFiles parameters in the File H...
Dec 29, 2025This path traversal vulnerability in Desktop Alert PingAlert allows attackers to load arbitrary external content by manipulating file paths. It affect...
Nov 14, 2025This vulnerability allows local network attackers to perform path traversal attacks via the firmware update service in D-Link DCS-850L cameras. By man...
Dec 30, 2025A vulnerability in Astro framework's development server allows attackers to read arbitrary local image files through the image optimization endpoint. ...
Nov 19, 2025This CVE describes a path traversal vulnerability in jshERP up to version 3.6 that allows remote attackers to manipulate file paths during plugin inst...
Jan 29, 2026A directory traversal vulnerability in SOLIDserver IPAM v8.2.3 allows authenticated administrators to list directories outside their authorized scope ...
Dec 2, 2025This vulnerability in ChestnutCMS allows attackers to perform path traversal attacks via the resourceDownload function, enabling unauthorized file rea...
Nov 10, 2025This CVE describes a path traversal vulnerability in D-Link DCS-700L IP cameras running firmware version 1.03.09. Attackers on the local network can e...
Jan 28, 2026A path traversal vulnerability in Brocade Fabric OS allows local admin users to access files outside intended directories, potentially exposing sensit...
Jun 19, 2025This vulnerability allows attackers to stage files outside the repository boundaries using path traversal sequences (../) in the git_add tool. It affe...
Feb 26, 2026This vulnerability allows unauthenticated attackers to perform path traversal and content injection in DynamicWeb's JobRunnerBackground.aspx file, lea...
Feb 19, 2026This is an unauthenticated path traversal vulnerability in AMR Printer Management 1.01 Beta web service that allows attackers to read arbitrary files ...
Feb 18, 2026A path traversal vulnerability in Digitek ADT1100 and DT950 devices allows attackers to access arbitrary files on the server's file system by manipula...
Feb 5, 2026A relative path traversal vulnerability in Lexmark's Embedded Solutions Framework allows attackers to access files outside intended directories and ex...
Feb 3, 2026This vulnerability in Wikimedia Foundation's CheckUser extension allows unauthorized access to sensitive user contribution data. It affects administra...
Feb 3, 2026This vulnerability in Wikimedia Foundation's TextExtracts extension allows attackers to execute arbitrary code or access sensitive data through improp...
Feb 3, 2026This vulnerability in Wikimedia Foundation's Thanks extension allows attackers to execute unauthorized actions through the ThanksQueryHelper.php file....
Feb 3, 2026This vulnerability in MediaWiki's EnhancedChangesList.php allows attackers to potentially execute unauthorized actions or access sensitive data throug...
Feb 3, 2026This vulnerability in Wikimedia Foundation's CheckUser extension allows unauthorized access to user information. It affects systems running CheckUser ...
Feb 3, 2026This vulnerability in MediaWiki's ApiQueryAllPages.php allows attackers to potentially access or manipulate page data through the API. It affects Medi...
Feb 3, 2026This vulnerability in Wikimedia Foundation's CheckUser extension allows unauthorized access to user information through the UserInfoHandler API endpoi...
Feb 3, 2026This vulnerability in MediaWiki's AuthManager.php allows attackers to bypass authentication mechanisms under specific conditions. It affects all Media...
Feb 2, 2026This vulnerability in MediaWiki's block list functionality could allow attackers to access sensitive information or perform unauthorized actions. It a...
Feb 2, 2026This CVE describes a path traversal vulnerability in pip's wheel archive extraction. When installing a maliciously crafted wheel file, attackers can w...
Feb 2, 2026EAP Legislator contains a path traversal vulnerability in its file extraction functionality. Attackers can craft malicious zipx archives that, when op...
Feb 2, 2026About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 2,221 CVEs classified as CWE-22, with 535 rated critical and 1,138 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free