CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

1,990
Total CVEs
446
Critical
1,005
High
7.6
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
231
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 26
2 Qnap 21
3 Ivanti 18
4 Fortinet 16
5 Samsung 16
6 Solarwinds 16
7 Fedoraproject 16
8 Siemens 15
9 Adobe 15
10 Debian 13

All Path Traversal CVEs (1,990)

CVE-2022-31527
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the Wildog/flask-file-server repository, enabling unauthorized file ...

Jul 11, 2022
CVE-2022-31529
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the cinemaproject/monorepo repository. It...

Jul 11, 2022
CVE-2022-31531
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the dainst/cilantro repository. It affect...

Jul 11, 2022
CVE-2022-31533
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the decentraminds/umbral repository. It a...

Jul 11, 2022
CVE-2022-31501
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in OnyxForum, enabling unauthorized file access on the server. It affec...

Jul 11, 2022
CVE-2022-31503
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in Orchest versions before 2022.05.0. By exploiting unsafe usage of Fla...

Jul 11, 2022
CVE-2022-31505
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the cheo0/MercadoEnLineaBack repository. By exploiting unsafe usage ...

Jul 11, 2022
CVE-2022-31507
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in Ganga software versions before 8.5.10. By exploiting unsafe use of F...

Jul 11, 2022
CVE-2022-31509
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the iedadata/usap-dc-website repository, enabling unauthorized file ...

Jul 11, 2022
CVE-2022-31511
9.3

This vulnerability allows attackers to read arbitrary files on the server by exploiting an unsafe implementation of Flask's send_file function. It aff...

Jul 11, 2022
CVE-2022-31513
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the BolunHan/Krypton repository, enabling unauthorized file access. ...

Jul 11, 2022
CVE-2022-31515
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the Delor4/CarceresBE repository. It affe...

Jul 11, 2022
CVE-2022-31517
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the HolgerGraef/MSM repository. It affect...

Jul 11, 2022
CVE-2022-31519
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the Lukasavicus/WindMill repository up to version 1.0. By exploiting...

Jul 11, 2022
CVE-2022-31521
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the mosaic repository's Flask application...

Jul 11, 2022
CVE-2022-31523
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the PaddlePaddle/Anakin repository. It af...

Jul 11, 2022
CVE-2024-49360
9.2

This vulnerability in Sandboxie allows authenticated users to read files from other users' sandbox folders, bypassing intended isolation. An attacker ...

Nov 29, 2024
CVE-2026-24457
9.1

CVE-2026-24457 is a path traversal vulnerability in OpenMQ's configuration parsing that allows remote attackers to read arbitrary files from the MQ Br...

Mar 5, 2026
CVE-2026-27699
9.1

The basic-ftp Node.js library contains a path traversal vulnerability in the downloadToDir() method. A malicious FTP server can send filenames contain...

Feb 25, 2026
CVE-2026-0704
9.1

This vulnerability in Octopus Deploy allows attackers to delete files or file contents on the host system through an unauthenticated API endpoint lack...

Feb 25, 2026
CVE-2026-25539
9.1

This vulnerability allows authenticated users of SiYuan personal knowledge management system to write files to arbitrary locations on the filesystem d...

Feb 4, 2026
CVE-2025-65792
9.1

DataGear v5.5.0 contains a path traversal vulnerability (CWE-22) that allows attackers to delete arbitrary files on the server. This affects all DataG...

Dec 10, 2025
CVE-2025-61811
9.1

This CVE describes an Improper Access Control vulnerability in Adobe ColdFusion that allows high-privileged attackers to bypass security controls and ...

Dec 10, 2025
CVE-2025-14306
9.1

A directory traversal vulnerability in Robocode's CacheCleaner component allows attackers to delete arbitrary files on the system by manipulating file...

Dec 9, 2025
CVE-2025-65346
9.1

CVE-2025-65346 is a directory traversal vulnerability in alexusmai/laravel-file-manager that allows attackers to write arbitrary files to any location...

Dec 4, 2025
CVE-2025-66410
9.1

CVE-2025-66410 is a path traversal vulnerability in gin-vue-admin that allows attackers to delete arbitrary files and folders on the server by control...

Dec 1, 2025
CVE-2025-66251
9.1

This vulnerability allows unauthenticated attackers to delete arbitrary .tgz files via path traversal in DB Electronica Telecomunicazioni S.p.A. Mozar...

Nov 26, 2025
CVE-2025-40549
9.1

A path restriction bypass vulnerability in SolarWinds Serv-U allows administrators to execute code on directories they shouldn't have access to. This ...

Nov 18, 2025
CVE-2025-55526
9.1

This vulnerability in n8n-workflows allows attackers to perform directory traversal attacks through the download_workflow function in api_server.py. A...

Aug 26, 2025
CVE-2025-55282
9.1

A privilege escalation vulnerability in aiven-db-migrate allows attackers to gain superuser privileges in PostgreSQL databases during migrations from ...

Aug 18, 2025
CVE-2025-54794
9.1

CVE-2025-54794 is a path traversal vulnerability in Claude Code versions below 0.2.111 that allows attackers to bypass directory restrictions and acce...

Aug 5, 2025
CVE-2025-7643
9.1

The Attachment Manager WordPress plugin has an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any file on the s...

Jul 18, 2025
CVE-2025-7712
9.1

The Madara - Core WordPress plugin has an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any file on the server...

Jul 17, 2025
CVE-2025-7360
9.1

This vulnerability in the HT Contact Form WordPress plugin allows unauthenticated attackers to move arbitrary files on the server due to insufficient ...

Jul 15, 2025
CVE-2025-53632
9.1

CVE-2025-53632 is a path traversal vulnerability (zip slip) in Chall-Manager that allows unauthenticated attackers to write arbitrary files outside th...

Jul 10, 2025
CVE-2025-6805
EPSS 12.3% 9.1

This vulnerability allows unauthenticated remote attackers to delete arbitrary files on Marvell QConvergeConsole installations. The flaw exists in the...

Jul 7, 2025
CVE-2025-6798
EPSS 12.3% 9.1

This vulnerability allows unauthenticated remote attackers to delete arbitrary files on Marvell QConvergeConsole installations. Attackers can exploit ...

Jul 7, 2025
CVE-2025-6065
9.1

The Image Resizer On The Fly WordPress plugin contains an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any fi...

Jun 14, 2025
CVE-2025-28384
9.1

This directory traversal vulnerability in OpenC3 COSMOS allows attackers to access files outside the intended directory via the /script-api/scripts/ e...

Jun 13, 2025
CVE-2025-47952
9.1

This vulnerability in Traefik allows attackers to bypass router path matching rules by using URL-encoded strings in request paths. This could enable a...

May 30, 2025
CVE-2025-31493
9.1

This is a path traversal vulnerability in Kirby CMS that allows attackers to access and execute arbitrary files on the server when dynamic collection ...

May 13, 2025
CVE-2025-30159
9.1

This is a path traversal vulnerability in Kirby CMS that allows attackers to read and execute arbitrary files on the server when dynamic snippet names...

May 13, 2025
CVE-2025-45238
9.1

FoxCMS v1.2.5 contains an arbitrary file deletion vulnerability in the delRestoreSerie method that allows attackers to delete any file on the server. ...

May 5, 2025
CVE-2025-3065
9.1

The Database Toolset WordPress plugin contains an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any file on th...

Apr 24, 2025
CVE-2025-32431
9.1

Traefik reverse proxy versions before 2.11.24, 3.3.6, and 3.4.0-rc2 contain a path traversal vulnerability in path-based routing matchers. Attackers c...

Apr 21, 2025
CVE-2025-22927
9.1

This vulnerability allows attackers to perform directory traversal attacks by sending a specially crafted POST request to the openSIS messaging module...

Apr 3, 2025
CVE-2024-8769
9.1

This vulnerability allows attackers to delete arbitrary files on systems running the aimhubio/aim tracking server. The flaw exists in the LockManager....

Mar 20, 2025
CVE-2024-8581
9.1

This vulnerability in parisneo/lollms-webui allows attackers to delete any file or directory on the system through path traversal in the upload_app fu...

Mar 20, 2025
CVE-2024-7776
9.1

A path traversal vulnerability in the ONNX framework's download_model function allows attackers to overwrite arbitrary files by exploiting malicious t...

Mar 20, 2025
CVE-2024-10361
9.1

This vulnerability allows attackers to delete arbitrary files on servers running vulnerable versions of LibreChat via path traversal in the /api/files...

Mar 20, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 1,990 CVEs classified as CWE-22, with 446 rated critical and 1,005 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.6.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free