CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
10,495 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 10 of 210
- CVE-2024-10902CRITICALCVSS 9.8EG 9.82025-03-20
In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthorized attackers to upload arbitrary files to the victim's file…
- CVE-2025-2505CRITICALCVSS 9.8EG 9.82025-03-20
The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP fil…
- CVE-2025-27783CRITICALCVSS 9.8EG 9.82025-03-19
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in train.py. This issue may lead to writing arbitrary files on the Applio server. It can also be used in conjunction with an unsafe d…
- CVE-2025-27782CRITICALCVSS 9.8EG 9.82025-03-19
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in inference.py. This issue may lead to writing arbitrary files on the Applio server. It can also be used in conjunction with an unsa…
- CVE-2025-1661CRITICALCVSS 9.8EG 9.82025-03-11
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.6.5 via the 'template' parameter of the woof_text_search AJAX action. This make…
- CVE-2024-8262CRITICALCVSS 9.8EG 9.82025-03-03
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allows Path Traversal. This issue affects OBS: before 24.0927.
- CVE-2024-38292CRITICALCVSS 9.8EG 9.82025-02-27
In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalation.
- CVE-2024-13725CRITICALCVSS 9.8EG 9.82025-02-18
The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service parameter. This makes it possible for unauthenticated attackers to include PHP files on t…
- CVE-2024-10763CRITICALCVSS 9.8EG 9.82025-02-13
The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via the 'campress_woocommerce_get_ajax_products' function. This makes it possible for unauthenticated attackers to include an…
- CVE-2025-0493CRITICALCVSS 9.8EG 9.82025-01-31
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in all versions up to, and including, 4.2.14 via the tabname parameter. This makes it possib…
- CVE-2024-13545CRITICALCVSS 9.8EG 9.82025-01-24
The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, a…
- CVE-2024-10811CRITICALCVSS 9.8EG 9.82025-01-14
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
- CVE-2024-11642CRITICALCVSS 9.8EG 9.82025-01-09
The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including…
- CVE-2024-54148CRITICALCVSS 9.8EG 9.82024-12-23
Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the server. The vulnerability is fixed in 0.13.1.
- CVE-2021-26102CRITICALCVSS 9.8EG 9.82024-12-19
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting s…
- CVE-2024-55515CRITICALCVSS 9.8EG 9.82024-12-17
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded.
- CVE-2024-46909CRITICALCVSS 9.8EG 9.82024-12-02
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
- CVE-2024-53676CRITICALCVSS 9.8EG 9.82024-11-27
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
- CVE-2023-51639CRITICALCVSS 9.8EG 9.82024-11-22
Allegra downloadExportedChart Directory Traversal Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this…
- CVE-2024-11315CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2024-11314CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2024-11313CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2024-11312CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2024-11311CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2024-50649CRITICALCVSS 9.8EG 9.82024-11-15
The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.
- CVE-2024-50648CRITICALCVSS 9.8EG 9.82024-11-15
yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.
- CVE-2024-48510CRITICALCVSS 9.8EG 9.82024-11-13
Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component NOTE: This vulnerability only affects products that are no longer su…
- CVE-2024-11150CRITICALCVSS 9.8EG 9.82024-11-13
The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 16.6. This makes it pos…
- CVE-2024-10470CRITICALCVSS 9.8EG 9.82024-11-09
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in…
- CVE-2024-10625CRITICALCVSS 9.8EG 9.82024-11-09
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 17.7. This makes …
- CVE-2024-39332CRITICALCVSS 9.8EG 9.82024-10-31
Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via modification of shell scripts on the server.
- CVE-2024-5982CRITICALCVSS 9.8EG 9.82024-10-29
A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling in multiple features, including user upload, directory creation, and template loading. Spec…
- CVE-2024-41717CRITICALCVSS 9.8EG 9.82024-10-22
Kieback & Peter's DDC4000 series is vulnerable to a path traversal vulnerability, which may allow an unauthenticated attacker to read files on the system.
- CVE-2019-25213CRITICALCVSS 9.8EG 9.82024-10-16
The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due to insufficient validation on the aam-media parameter. This allows unauthenticated attacker…
- CVE-2024-9047CRITICALCVSS 9.8EG 9.82024-10-12
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside …
- CVE-2024-46446CRITICALCVSS 9.8EG 9.82024-10-07
Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Websi…
- CVE-2024-46376CRITICALCVSS 9.8EG 9.82024-09-18
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/admin_class.php.
- CVE-2024-46375CRITICALCVSS 9.8EG 9.82024-09-18
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_class.php.
- CVE-2024-7961CRITICALCVSS 9.8EG 9.82024-09-12
A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to the server that could result in a remote code execution.
- CVE-2024-7950CRITICALCVSS 9.8EG 9.82024-09-04
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitrary Settings Update, and User Creation in all versions up to, and including, 2.1.6 via s…
- CVE-2024-45256CRITICALCVSS 9.8EG 9.82024-08-26
An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occu…
- CVE-2023-7249CRITICALCVSS 9.8EG 9.82024-08-12
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.
- CVE-2024-42469CRITICALCVSS 9.8EG 9.82024-08-12
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. Prior to version 4.2.1, CometVisu's file system endpoints don't require authentication and additionally the endpoint to …
- CVE-2024-39226CRITICALCVSS 9.8EG 9.82024-08-06
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contai…
- CVE-2024-28698CRITICALCVSS 9.8EG 9.82024-07-22
Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter component.
- CVE-2024-41704CRITICALCVSS 9.8EG 9.82024-07-22
LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.
- CVE-2024-6164CRITICALCVSS 9.8EG 9.82024-07-18
The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated attacker to include and execute PHP files on the server, allowing the exec…
- CVE-2024-40524CRITICALCVSS 9.8EG 9.82024-07-15
Directory Traversal vulnerability in xmind2testcase v.1.5 allows a remote attacker to execute arbitrary code via the webtool\application.py component.
- CVE-2024-39171CRITICALCVSS 9.8EG 9.82024-07-09
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.
- CVE-2024-6127CRITICALCVSS 9.8EG 9.82024-06-27
BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptog…
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →