CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (1,990)
This vulnerability allows attackers to perform absolute path traversal attacks in the Wildog/flask-file-server repository, enabling unauthorized file ...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the cinemaproject/monorepo repository. It...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the dainst/cilantro repository. It affect...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the decentraminds/umbral repository. It a...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in OnyxForum, enabling unauthorized file access on the server. It affec...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in Orchest versions before 2022.05.0. By exploiting unsafe usage of Fla...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in the cheo0/MercadoEnLineaBack repository. By exploiting unsafe usage ...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in Ganga software versions before 8.5.10. By exploiting unsafe use of F...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in the iedadata/usap-dc-website repository, enabling unauthorized file ...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server by exploiting an unsafe implementation of Flask's send_file function. It aff...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in the BolunHan/Krypton repository, enabling unauthorized file access. ...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the Delor4/CarceresBE repository. It affe...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the HolgerGraef/MSM repository. It affect...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in the Lukasavicus/WindMill repository up to version 1.0. By exploiting...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the mosaic repository's Flask application...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the PaddlePaddle/Anakin repository. It af...
Jul 11, 2022This vulnerability in Sandboxie allows authenticated users to read files from other users' sandbox folders, bypassing intended isolation. An attacker ...
Nov 29, 2024CVE-2026-24457 is a path traversal vulnerability in OpenMQ's configuration parsing that allows remote attackers to read arbitrary files from the MQ Br...
Mar 5, 2026The basic-ftp Node.js library contains a path traversal vulnerability in the downloadToDir() method. A malicious FTP server can send filenames contain...
Feb 25, 2026This vulnerability in Octopus Deploy allows attackers to delete files or file contents on the host system through an unauthenticated API endpoint lack...
Feb 25, 2026This vulnerability allows authenticated users of SiYuan personal knowledge management system to write files to arbitrary locations on the filesystem d...
Feb 4, 2026DataGear v5.5.0 contains a path traversal vulnerability (CWE-22) that allows attackers to delete arbitrary files on the server. This affects all DataG...
Dec 10, 2025This CVE describes an Improper Access Control vulnerability in Adobe ColdFusion that allows high-privileged attackers to bypass security controls and ...
Dec 10, 2025A directory traversal vulnerability in Robocode's CacheCleaner component allows attackers to delete arbitrary files on the system by manipulating file...
Dec 9, 2025CVE-2025-65346 is a directory traversal vulnerability in alexusmai/laravel-file-manager that allows attackers to write arbitrary files to any location...
Dec 4, 2025CVE-2025-66410 is a path traversal vulnerability in gin-vue-admin that allows attackers to delete arbitrary files and folders on the server by control...
Dec 1, 2025This vulnerability allows unauthenticated attackers to delete arbitrary .tgz files via path traversal in DB Electronica Telecomunicazioni S.p.A. Mozar...
Nov 26, 2025A path restriction bypass vulnerability in SolarWinds Serv-U allows administrators to execute code on directories they shouldn't have access to. This ...
Nov 18, 2025This vulnerability in n8n-workflows allows attackers to perform directory traversal attacks through the download_workflow function in api_server.py. A...
Aug 26, 2025A privilege escalation vulnerability in aiven-db-migrate allows attackers to gain superuser privileges in PostgreSQL databases during migrations from ...
Aug 18, 2025CVE-2025-54794 is a path traversal vulnerability in Claude Code versions below 0.2.111 that allows attackers to bypass directory restrictions and acce...
Aug 5, 2025The Attachment Manager WordPress plugin has an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any file on the s...
Jul 18, 2025The Madara - Core WordPress plugin has an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any file on the server...
Jul 17, 2025This vulnerability in the HT Contact Form WordPress plugin allows unauthenticated attackers to move arbitrary files on the server due to insufficient ...
Jul 15, 2025CVE-2025-53632 is a path traversal vulnerability (zip slip) in Chall-Manager that allows unauthenticated attackers to write arbitrary files outside th...
Jul 10, 2025This vulnerability allows unauthenticated remote attackers to delete arbitrary files on Marvell QConvergeConsole installations. The flaw exists in the...
Jul 7, 2025This vulnerability allows unauthenticated remote attackers to delete arbitrary files on Marvell QConvergeConsole installations. Attackers can exploit ...
Jul 7, 2025The Image Resizer On The Fly WordPress plugin contains an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any fi...
Jun 14, 2025This directory traversal vulnerability in OpenC3 COSMOS allows attackers to access files outside the intended directory via the /script-api/scripts/ e...
Jun 13, 2025This vulnerability in Traefik allows attackers to bypass router path matching rules by using URL-encoded strings in request paths. This could enable a...
May 30, 2025This is a path traversal vulnerability in Kirby CMS that allows attackers to access and execute arbitrary files on the server when dynamic collection ...
May 13, 2025This is a path traversal vulnerability in Kirby CMS that allows attackers to read and execute arbitrary files on the server when dynamic snippet names...
May 13, 2025FoxCMS v1.2.5 contains an arbitrary file deletion vulnerability in the delRestoreSerie method that allows attackers to delete any file on the server. ...
May 5, 2025The Database Toolset WordPress plugin contains an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any file on th...
Apr 24, 2025Traefik reverse proxy versions before 2.11.24, 3.3.6, and 3.4.0-rc2 contain a path traversal vulnerability in path-based routing matchers. Attackers c...
Apr 21, 2025This vulnerability allows attackers to perform directory traversal attacks by sending a specially crafted POST request to the openSIS messaging module...
Apr 3, 2025This vulnerability allows attackers to delete arbitrary files on systems running the aimhubio/aim tracking server. The flaw exists in the LockManager....
Mar 20, 2025This vulnerability in parisneo/lollms-webui allows attackers to delete any file or directory on the system through path traversal in the upload_app fu...
Mar 20, 2025A path traversal vulnerability in the ONNX framework's download_model function allows attackers to overwrite arbitrary files by exploiting malicious t...
Mar 20, 2025This vulnerability allows attackers to delete arbitrary files on servers running vulnerable versions of LibreChat via path traversal in the /api/files...
Mar 20, 2025About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 1,990 CVEs classified as CWE-22, with 446 rated critical and 1,005 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.6.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free