CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
8,850 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 148 of 177
- CVE-2025-55214MEDIUMCVSS 6.9EG 6.92025-08-18
Copier library and CLI app for rendering project templates. From 7.1.0 to before 9.9.1, Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which…
- CVE-2025-55282CRITICALCVSS 9.1EG 9.12025-08-18
aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows a user to elevate to superuser inside PostgreSQL databases during a migration from an untrusted source server. …
- CVE-2025-55295MEDIUMCVSS 6.5EG 6.52025-08-19
qBit Manage is a tool that helps manage tedious tasks in qBittorrent and automate them. A path traversal vulnerability exists in qbit_manage's web API that allows authenticated users to read arbitrary files from the server filesystem throu…
- CVE-2025-5544HIGHCVSS 7.5EG 7.52025-06-03
A vulnerability was found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. It has been rated as problematic. Affected by this issue is the function image of the file src/main/java/cn/gson/oasys/controller/user/Userpa…
- CVE-2025-5545HIGHCVSS 7.5EG 7.52025-06-04
A vulnerability classified as problematic has been found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. This affects the function image of the file src/main/java/cn/gson/oasys/controller/process/ProcedureController…
- CVE-2025-55523LOWCVSS 3.5EG 3.52025-08-21
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.
- CVE-2025-55526CRITICALCVSS 9.1EG 9.12025-08-26
n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py
- CVE-2025-56427HIGHCVSS 7.5EG 7.52025-12-04
Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir function.
- CVE-2025-56430HIGHCVSS 7.5EG 7.52025-12-10
Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the deleteDirectory function.
- CVE-2025-56431HIGHCVSS 7.5EG 7.52025-12-10
Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the file_get_contents() function.
- CVE-2025-56815HIGHCVSS 7.1EG 7.12025-09-24
Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to save the uploaded file to a path controllable by the user, and lacks strict verification …
- CVE-2025-56816HIGHCVSS 8.8EG 8.82025-09-24
Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attackers to upload arbitrary YAML files to the config/jdbc-driver-ext.yml path. The application parses this file using Snake…
- CVE-2025-56869MEDIUMCVSS 5.3EG 5.32025-09-19
Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write access to the system via FilesManager.saveMultipart function in backend/src/applications/files/services/files-manager.se…
- CVE-2025-5714MEDIUMCVSS 4.3EG 4.32025-06-06
A vulnerability was found in SoluçõesCoop iSoluçõesWEB up to 20250516. It has been classified as problematic. This affects an unknown part of the file /sys/up.upload.php of the component Profile Information Update. The manipulation of …
- CVE-2025-5740HIGHCVSS 7.2EG 7.22025-06-10
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file writes when an authenticated user on the web server manipulates file path.
- CVE-2025-5741MEDIUMCVSS 4.9EG 4.92025-06-10
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file reads from the charging station. The exploitation of this vulnerability does require an authenticat…
- CVE-2025-57644CRITICALCVSS 9.1EG 9.12025-09-19
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. In addition, i…
- CVE-2025-57682MEDIUMCVSS 6.5EG 6.52025-09-22
Directory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary files from an S3 bucket through its CloudFront distribution via the "POST /api/file/s3/get-presigned-get-url-proxy" API
- CVE-2025-57697MEDIUMCVSS 6.5EG 6.52025-11-07
AstrBot Project v3.5.22 has an arbitrary file read vulnerability in function _encode_image_bs64. Since the _encode_image_bs64 function defined in entities.py opens the image specified by the user in the request body and returns the image c…
- CVE-2025-57698HIGHCVSS 7.5EG 7.52025-11-07
AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the interface '/plugin/install-upload' parses the filename from the request body provided by the user, and directly uses th…
- CVE-2025-57712MEDIUMCVSS 6.5EG 6.52025-11-07
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed th…
- CVE-2025-57753MEDIUMCVSS 6.0EG 6.02025-08-21
vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible with a crafted request. The vulnerability is fixed in 2.3.2 and 3.1.2.
- CVE-2025-58072HIGHCVSS 7.5EG 7.52025-08-28
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, arbitrary files may be viewed by a remote…
- CVE-2025-58158HIGHCVSS 8.8EG 8.82025-08-29
Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Developer Environments, and Artifact Registries. Prior to version 3.3.0, Open Source Harness git LFS server (Gitness) exposes a…
- CVE-2025-58161MEDIUMCVSS 4.3EG 4.32025-09-02
MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path verification via os.path.commonprefix, which allows an authenticated user to download files outside the DWD_DIR download …
- CVE-2025-58162MEDIUMCVSS 6.5EG 6.52025-09-02
MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write arbitrary files to any directory writable by the user of the MobSF process. This issue has…
- CVE-2025-58173HIGHCVSS 8.8EG 8.82025-12-16
FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration parameter, it's possible to call `install.php` and perform various administrative actions as …
- CVE-2025-58320HIGHCVSS 7.3EG 7.32025-09-11
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
- CVE-2025-58321CRITICALCVSS 10.0EG 10.02025-09-11
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
- CVE-2025-58355HIGHCVSS 7.7EG 7.72025-09-04
Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or override arbitrary files with uncontrolled data through its SSH API. This issue is fixed in version 0.10.0.
- CVE-2025-58423HIGHCVSS 8.8EG 8.82025-11-06
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-service condition, traverse directories, or read/write files, within the context of the local system account.
- CVE-2025-58438CRITICALCVSS 9.4EG 9.42025-09-06
internetarchive is a Python and Command-Line Interface to Archive.org In versions 5.5.0 and below, there is a directory traversal (path traversal) vulnerability in the File.download() method of the internetarchive library. The file.downloa…
- CVE-2025-58470MEDIUMCVSS 6.5EG 6.52026-02-11
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed th…
- CVE-2025-58590MEDIUMCVSS 6.5EG 6.52025-10-06
It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information.
- CVE-2025-58591MEDIUMCVSS 6.5EG 6.52025-10-06
A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerable for gathering sensitive information.
- CVE-2025-58693MEDIUMCVSS 6.5EG 6.52026-01-13
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a privileged attacker to delete files from the underlying fil…
- CVE-2025-58751MEDIUMCVSS 5.3EG 5.32025-09-08
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly e…
- CVE-2025-58755HIGHCVSS 8.8EG 8.82025-09-09
MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extractall(output_dir)` is used directly to process compressed files. It is used in many places in the project. In versions up …
- CVE-2025-58769LOWCVSS 3.3EG 3.32025-10-01
auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import endpoint in applications built with the SDK does not validate the file-path wrapper or value. Without proper validatio…
- CVE-2025-5880MEDIUMCVSS 4.3EG 4.32025-06-09
A vulnerability has been found in Whistle 2.9.98 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/sessions/get-temp-file. The manipulation of the argument filename leads to path traversal. The exp…
- CVE-2025-58959HIGHCVSS 7.7EG 7.72025-10-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Taskbot taskbot allows Path Traversal.This issue affects Taskbot: from n/a through <= 6.4.
- CVE-2025-59002HIGHCVSS 7.7EG 7.72025-09-26
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Builder bm-builder allows Path Traversal.This issue affects BM Content Builder: from n/a through < 3.16.3.3.
- CVE-2025-59049HIGHCVSS 7.5EG 7.52025-09-10
Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file serving follows the same approach presented in the documentation page, where the server filename is generated via templating…
- CVE-2025-59056HIGHCVSS 7.5EG 7.52025-09-15
FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web interface can cause the uninstall function to be triggered for certain modules. This func…
- CVE-2025-59171HIGHCVSS 7.5EG 7.52025-11-06
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.
- CVE-2025-59304CRITICALCVSS 9.8EG 9.82025-09-17
A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote Code Execution via a crafted HTTP request.
- CVE-2025-59336MEDIUMCVSS 6.9EG 6.92025-09-16
Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of service by overwriting Phoenix runtime files. Package names like ../../package are not properly filtered and pass the va…
- CVE-2025-59343HIGHCVSS 8.7EG 8.72025-09-24
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in …
- CVE-2025-59352CRITICALCVSS 9.8EG 9.82025-09-17
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send requests that force the recipient peer to create files in arbitrary file system locations…
- CVE-2025-59366CRITICALCVSS 9.2EG 9.22025-11-25
An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality, potentially leading to allow execution of specific functions without proper authorizatio…
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →