CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

1,995
Total CVEs
447
Critical
1,009
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
231
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 26
2 Qnap 21
3 Ivanti 18
4 Fortinet 16
5 Samsung 16
6 Solarwinds 16
7 Fedoraproject 16
8 Siemens 15
9 Adobe 15
10 Debian 13

All Path Traversal CVEs (1,995)

CVE-2024-10361
9.1

This vulnerability allows attackers to delete arbitrary files on servers running vulnerable versions of LibreChat via path traversal in the /api/files...

Mar 20, 2025
CVE-2025-27786
9.1

Applio voice conversion tool versions 3.2.8-bugfix and prior contain a path traversal vulnerability that allows attackers to delete arbitrary files on...

Mar 19, 2025
CVE-2025-1127
9.1

This CVE-2025-1127 vulnerability allows attackers to execute arbitrary code as an unprivileged user and modify any filesystem data through improper pa...

Feb 13, 2025
CVE-2024-53537
9.1

This directory traversal vulnerability in OpenPanel's File Manager allows attackers to access files outside the intended directory structure. Attacker...

Jan 31, 2025
CVE-2024-39786
9.1

This directory traversal vulnerability in Wavlink AC3000 routers allows authenticated attackers to bypass file permissions and access restricted direc...

Jan 14, 2025
CVE-2024-55513
9.1

This vulnerability allows attackers to upload arbitrary files to Raisecom network devices via the /upload_netaction.php web interface endpoint. By cra...

Dec 17, 2024
CVE-2024-11833
9.1

CVE-2024-11833 is a path traversal vulnerability in PlexTrac that allows attackers to write arbitrary files to the server filesystem. This affects Ple...

Dec 13, 2024
CVE-2024-11992
9.1

This is an absolute path traversal vulnerability in Quick.CMS 6.7 that allows remote attackers to bypass security restrictions and download or delete ...

Nov 29, 2024
CVE-2024-52787
9.1

This vulnerability in libre-chat v0.0.6 allows attackers to perform path traversal attacks by uploading files with specially crafted filenames. This c...

Nov 25, 2024
CVE-2024-51747
9.1

This vulnerability allows authenticated Kanboard administrators to read and delete arbitrary files on the server by uploading a modified SQLite databa...

Nov 11, 2024
CVE-2024-41713
9.1

This vulnerability allows unauthenticated attackers to perform path traversal attacks on Mitel MiCollab's NuPoint Unified Messaging component. Attacke...

Oct 21, 2024
CVE-2024-8671
9.1

The WooEvents WordPress plugin has a critical vulnerability that allows unauthenticated attackers to overwrite arbitrary files on the server due to in...

Sep 24, 2024
CVE-2024-38652
9.1

This vulnerability allows remote unauthenticated attackers to delete arbitrary files on Ivanti Avalanche servers through path traversal in the skin ma...

Aug 14, 2024
CVE-2024-21876
9.1

This path traversal vulnerability in Enphase IQ Gateway (formerly Envoy) allows unauthenticated attackers to access or create arbitrary files via URL ...

Aug 12, 2024
CVE-2024-40422
9.1

This vulnerability allows attackers to perform path traversal attacks via the snapshot_path parameter in Devika v1's API endpoint. By manipulating thi...

Jul 24, 2024
CVE-2012-6664
9.1

This vulnerability allows remote attackers to read or write arbitrary files on systems running Distinct Intranet Servers TFTP Server 3.10 and earlier....

Jun 21, 2024
CVE-2024-4315
9.1

CVE-2024-4315 is a Local File Inclusion vulnerability in parisneo/lollms version 9.5 that allows attackers to perform directory traversal attacks on W...

Jun 12, 2024
CVE-2024-1873
9.1

The CVE-2024-1873 vulnerability in parisneo/lollms-webui allows attackers to perform path traversal attacks through an exposed /select_database endpoi...

Jun 6, 2024
CVE-2024-5153
9.1

The Startklar Elementor Addons WordPress plugin contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary f...

Jun 6, 2024
CVE-2024-36104
9.1

This path traversal vulnerability in Apache OFBiz allows attackers to access files outside the intended directory. It affects all Apache OFBiz install...

Jun 4, 2024
CVE-2024-4442
9.1

This vulnerability allows unauthenticated attackers to delete arbitrary files on WordPress sites using the Salon booking system plugin. Attackers can ...

May 21, 2024
CVE-2023-40508
9.1

This vulnerability in LG Simple Editor allows remote attackers without authentication to delete arbitrary files on affected systems by exploiting a di...

May 3, 2024
CVE-2023-40499
9.1

This vulnerability in LG Simple Editor allows remote attackers to delete arbitrary files without authentication by exploiting a directory traversal fl...

May 3, 2024
CVE-2023-40494
9.1

This vulnerability in LG Simple Editor allows remote attackers to delete arbitrary files without authentication by exploiting a directory traversal fl...

May 3, 2024
CVE-2023-40492
9.1

This vulnerability allows unauthenticated remote attackers to delete arbitrary files on systems running vulnerable versions of LG Simple Editor. Attac...

May 3, 2024
CVE-2024-28335
9.1

Lektor CMS versions before 3.3.11 have a path traversal vulnerability that allows remote code execution. Attackers can exploit this by tricking users ...

Mar 27, 2024
CVE-2024-0818
9.1

This vulnerability allows attackers to overwrite arbitrary files on systems running vulnerable versions of PaddlePaddle through path traversal. Attack...

Mar 7, 2024
CVE-2024-25065
9.1

CVE-2024-25065 is a path traversal vulnerability in Apache OFBiz that allows attackers to bypass authentication mechanisms by manipulating file paths....

Feb 29, 2024
CVE-2023-6699
9.1

The WP Compress Image Optimizer WordPress plugin contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary ...

Jan 11, 2024
CVE-2023-47211
9.1

A directory traversal vulnerability in ManageEngine OpManager's uploadMib functionality allows attackers to create arbitrary files on the system by se...

Jan 8, 2024
CVE-2023-46886
9.1

Dreamer CMS versions before 4.0.1 contain a directory traversal vulnerability in the background template management feature. This allows authenticated...

Nov 29, 2023
CVE-2023-46253
9.1

Squidex versions before 7.8.0 have an arbitrary file write vulnerability in the backup restore feature that allows authenticated attackers with squide...

Nov 7, 2023
CVE-2023-5414
9.1

This vulnerability in the Icegram Express WordPress plugin allows administrator-level attackers to perform directory traversal attacks via the show_es...

Oct 20, 2023
CVE-2023-45278
9.1

This CVE describes a directory traversal vulnerability in Yamcs 5.8.6's API storage functionality that allows attackers to delete arbitrary files on t...

Oct 19, 2023
CVE-2023-39407
9.1

CVE-2023-39407 is a path traversal vulnerability in Watchkit that allows unauthorized file access. Attackers can read or modify files outside intended...

Sep 25, 2023
CVE-2020-24113
9.1

This vulnerability allows attackers to perform directory traversal attacks through the contacts file upload interface in Yealink W60B devices. Attacke...

Aug 22, 2023
CVE-2023-39402
9.1

This CVE describes a parameter verification vulnerability in Huawei's installd module that allows unauthorized reading and writing of sandbox files. A...

Aug 13, 2023
CVE-2023-39400
9.1

This CVE describes a parameter verification vulnerability in the installd module that allows unauthorized reading and writing of sandbox files. Attack...

Aug 13, 2023
CVE-2020-27514
9.1

CVE-2020-27514 is a directory traversal vulnerability in ZrLog's admin API that allows remote attackers to delete arbitrary files on the server. This ...

Aug 11, 2023
CVE-2023-33369
9.1

A path traversal vulnerability in Control ID IDSecure 4.7.26.0 and earlier allows attackers to delete arbitrary files on the system filesystem. This c...

Aug 3, 2023
CVE-2023-32521
9.1

This vulnerability allows unauthenticated remote attackers to delete arbitrary files on systems running Trend Micro Mobile Security (Enterprise) 9.8 S...

Jun 26, 2023
CVE-2022-46945
9.1

CVE-2022-46945 is an arbitrary file read vulnerability in Nagvis versions before 1.9.34. Attackers can exploit the NagVisHoverUrl.php component to rea...

May 26, 2023
CVE-2023-26216
9.1

This vulnerability in TIBCO EBX Add-ons allows attackers to upload arbitrary files to web-accessible directories, potentially leading to remote code e...

May 25, 2023
CVE-2023-27812
9.1

CVE-2023-27812 is an arbitrary file deletion vulnerability in bloofox v0.5.2 that allows attackers to delete any file on the server via the delete_fil...

Apr 13, 2023
CVE-2022-2560
9.1

CVE-2022-2560 is an unauthenticated path traversal vulnerability in EnterpriseDT CompleteFTP Server that allows remote attackers to delete arbitrary f...

Mar 29, 2023
CVE-2023-24188
9.1

CVE-2023-24188 is a directory traversal vulnerability in ureport v2.2.9 that allows attackers to delete arbitrary files on the server by exploiting th...

Feb 13, 2023
CVE-2021-37317
9.1

This CVE describes a directory traversal vulnerability in ASUS RT-AC68U router's Cloud Disk feature that allows remote attackers to write arbitrary fi...

Feb 3, 2023
CVE-2022-1953
9.1

This vulnerability allows unauthenticated attackers to delete arbitrary files on WordPress sites running the vulnerable Product Configurator for WooCo...

Jun 27, 2022
CVE-2022-30117
9.1

This vulnerability in Concrete CMS allows authenticated attackers to perform directory traversal via the file upload endpoint, potentially leading to ...

Jun 24, 2022
CVE-2022-32328
9.1

Fast Food Ordering System v1.0 contains an arbitrary file deletion vulnerability in the Master.php component. Attackers can delete any file on the ser...

Jun 14, 2022

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 1,995 CVEs classified as CWE-22, with 447 rated critical and 1,009 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free