CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (1,995)
CVE-2022-24840 is a path traversal vulnerability in django-s3file that allows attackers to access or delete files across an entire AWS S3 bucket. All ...
Jun 9, 2022This is a path traversal vulnerability in HID Mercury Intelligent Controllers that allows authenticated attackers to upload files anywhere on the file...
Jun 6, 2022CVE-2022-25591 is an arbitrary file deletion vulnerability in BlogEngine.NET that allows attackers to delete files within the web server root director...
May 13, 2022This path traversal vulnerability in StruxureWare Data Center Expert allows attackers to access files outside the intended directory, potentially lead...
Apr 13, 2022CVE-2022-26960 is a path traversal vulnerability in elFinder's connector.minimal.php that allows unauthenticated attackers to read, write, and browse ...
Mar 21, 2022CVE-2022-23357 is a directory traversal vulnerability in mozilo2.0 CMS that allows attackers to access arbitrary files on the server via the 'curent_d...
Feb 3, 2022CVE-2021-40525 is a path traversal vulnerability in Apache James ManagedSieve implementation that allows attackers to read and write arbitrary files o...
Jan 4, 2022This vulnerability in Qibosoft v7 allows attackers to delete arbitrary files via the /admin/index.php endpoint with specific parameters. Attackers can...
Dec 27, 2021This CVE describes an authenticated directory traversal vulnerability in Lantronix PremierWave 2050's Web Manager FsTFtp functionality. An attacker wi...
Dec 22, 2021CVE-2021-45015 is an arbitrary file deletion vulnerability in TaoCMS that allows attackers to delete any file on the server. This affects TaoCMS 3.0.2...
Dec 14, 2021This CVE describes a path traversal vulnerability in Huawei smartphones running HarmonyOS that allows attackers to create arbitrary files. Successful ...
Dec 7, 2021This path traversal vulnerability in Huawei smartphones allows attackers to delete arbitrary files on affected devices. The vulnerability affects Huaw...
Dec 7, 2021This vulnerability allows attackers to create arbitrary files on Huawei smartphones by exploiting improper pathname restrictions. It affects Huawei de...
Dec 7, 2021This CVE describes a path traversal vulnerability in the Barcode plugin for GLPI that allows attackers to read arbitrary files on the server. It affec...
Nov 24, 2021CVE-2021-33724 is an arbitrary file deletion vulnerability in Siemens SINEC NMS that allows attackers to delete files or directories at user-controlle...
Oct 12, 2021ECOA BAS controller has an unauthenticated path traversal vulnerability that allows remote attackers to delete arbitrary files via a specific GET para...
Sep 30, 2021The OMGF WordPress plugin before version 4.5.4 has an unauthenticated path traversal vulnerability in its REST API. This allows attackers to overwrite...
Sep 20, 2021This vulnerability allows attackers to exploit a path traversal flaw in Schneider Electric's Harmony HMI products when accessed via FTP. Attackers cou...
Sep 2, 2021This vulnerability in TensorFlow allows attackers to overwrite arbitrary files on the system when tf.keras.utils.get_file is used with extract=True on...
Jun 30, 2021CVE-2021-34363 is a path traversal vulnerability in thefuck Python package that allows attackers to delete arbitrary files via the 'undo archive opera...
Jun 10, 2021MetInfo 7.0 beta contains a path traversal vulnerability that allows attackers to delete and modify critical INI configuration files. This affects all...
May 24, 2021This vulnerability allows authenticated attackers with network access to WAGO PFC200 devices to access the file system with elevated privileges via sp...
May 24, 2021This vulnerability allows attackers to delete arbitrary files on the server through directory traversal in the file deletion functionality of transfer...
May 24, 2021This path traversal vulnerability in iCMS v7.0.13 allows remote attackers to delete arbitrary folders on the server by sending specially crafted HTTP ...
Apr 30, 2021CVE-2020-17563 is a path traversal vulnerability in FeiFeiCMS v4.0 that allows remote attackers to delete arbitrary files on the server by sending a s...
Apr 22, 2021CVE-2021-20078 is a path traversal vulnerability in ManageEngine OpManager's Spark Gateway component that allows remote attackers to delete arbitrary ...
Apr 1, 2021This directory traversal vulnerability in ELECOM File Manager allows remote attackers to create or overwrite arbitrary files within directories access...
Feb 12, 2021CVE-2020-15097 is a path traversal vulnerability in loklak server that allows attackers to read and write arbitrary files on the server filesystem. Th...
Feb 2, 2021This vulnerability in the mozwire Rust crate allows attackers to perform directory traversal attacks, enabling them to overwrite local configuration f...
Dec 31, 2020CVE-2020-26837 is a path traversal vulnerability in SAP Solution Manager 7.2's User Experience Monitoring component that allows authenticated users to...
Dec 9, 2020This vulnerability allows a malicious mail server to overwrite arbitrary files on Apple devices through a path handling issue in mail processing. It a...
Oct 22, 2020CVE-2020-18191 is a directory traversal vulnerability in GetSimpleCMS 3.3.15 that allows remote attackers to delete arbitrary files via the /admin/log...
Oct 2, 2020This vulnerability allows attackers to modify and upload arbitrary files by exploiting improper pathname limitations in Circuit Provisioning and File ...
May 20, 2025This vulnerability in oxidized-web allows unauthenticated attackers to execute arbitrary commands as the Linux user running the oxidized-web service. ...
Mar 3, 2025This vulnerability in Nix package manager allows attackers to write arbitrary files to any location the Nix process can access. When the Nix daemon ru...
Sep 10, 2024This vulnerability in the Bit Form WordPress plugin allows authenticated attackers with Administrator-level access to read and delete arbitrary files ...
Aug 20, 2024This vulnerability allows unauthenticated attackers to perform local file inclusion (LFI) through path traversal in the ListingPro WordPress plugin. A...
Aug 1, 2024This vulnerability allows unauthenticated attackers to perform path traversal attacks, leading to local file inclusion in the Consulting Elementor Wid...
Jun 24, 2024This vulnerability allows unauthenticated attackers to perform path traversal attacks in the StylemixThemes MegaMenu WordPress plugin, leading to loca...
Jun 10, 2024This vulnerability allows unauthenticated attackers to perform path traversal attacks in the Stockholm WordPress theme, leading to local file inclusio...
Jun 4, 2024This vulnerability allows unauthenticated attackers to perform path traversal attacks in the XStore WordPress theme, leading to local file inclusion. ...
Jun 4, 2024This CVE describes a vulnerability in Git where specially crafted repositories with submodules can trick Git into writing files into a .git/ directory...
May 14, 2024This vulnerability allows an attacker with local access to a Microsoft Azure Kubernetes Service (AKS) confidential container to elevate privileges and...
Mar 12, 2024CVE-2023-35169 is a critical directory traversal vulnerability in PHP-IMAP library that allows unauthenticated attackers to achieve remote code execut...
Jun 23, 2023A path traversal vulnerability in Samsung Galaxy Themes Service allows attackers to access arbitrary files with system-level privileges. This affects ...
Mar 16, 2023A directory traversal vulnerability in GateManager's file upload function allows authenticated administrators to read and write arbitrary files on the...
Feb 15, 2021This vulnerability in SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files via a crafted cookie, leading to remote command executi...
Aug 7, 2020OpenSift versions before 1.6.3-alpha contain a path traversal vulnerability (CWE-22) in multiple storage helpers that don't properly enforce directory...
Mar 6, 2026The Worry Proof Backup WordPress plugin contains a path traversal vulnerability that allows authenticated attackers with Subscriber-level access or hi...
Feb 26, 2026This CVE allows attackers with read/write access to Vitess backup storage locations to manipulate backup manifest files and perform path traversal att...
Feb 26, 2026About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 1,995 CVEs classified as CWE-22, with 447 rated critical and 1,009 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free