CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
8,873 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 151 of 178
- CVE-2025-64757LOWCVSS 3.5EG 3.52025-11-19
Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's development server that allows arbitrary local file read access through the image optimization endpoint. The vulnerability affe…
- CVE-2025-64765MEDIUMCVSS 5.3EG 5.32025-11-19
Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for routing/rendering and how the application’s middleware reads the path for validation checks. Astro internally applies dec…
- CVE-2025-65025CRITICALCVSS 9.8EG 9.82025-11-19
esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, the esm.sh CDN service is vulnerable to path traversal during NPM package tarball extraction. An attacker can craft a malicious NPM package…
- CVE-2025-65074HIGHCVSS 7.2EG 7.22025-12-16
WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to execute arbitrary OS commands on the server using path trave…
- CVE-2025-65075MEDIUMCVSS 6.5EG 6.52025-12-16
WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to read or delete files, with the permissions of dvr user, on t…
- CVE-2025-65076MEDIUMCVSS 6.1EG 6.12025-12-16
WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to read or delete any file on the server using path traversal in…
- CVE-2025-65077HIGHCVSS 8.8EG 8.82026-02-03
A relative path traversal vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.
- CVE-2025-65287MEDIUMCVSS 4.3EG 4.32025-12-09
An unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1 allows a remote attacker to read arbitrary files. The CGI concatenates the user-supplied params directly onto the base path (/var/www/files/user…
- CVE-2025-65345MEDIUMCVSS 6.5EG 6.52025-12-03
alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create archives containing files and directories outside the intended scope due to improper path val…
- CVE-2025-65346CRITICALCVSS 9.1EG 9.12025-12-04
alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive contents to be written to arbitrary locations on the filesystem due to insufficient validatio…
- CVE-2025-65418HIGHCVSS 7.5EG 7.52026-05-11
docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url.
- CVE-2025-65713MEDIUMCVSS 4.0EG 4.02025-12-23
Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.
- CVE-2025-65792CRITICALCVSS 9.1EG 9.12025-12-10
DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.
- CVE-2025-65814MEDIUMCVSS 6.5EG 6.52025-12-10
A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a directory traversal.
- CVE-2025-65815MEDIUMCVSS 6.5EG 6.52025-12-10
A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attackers to execute a directory traversal.
- CVE-2025-65838HIGHCVSS 7.5EG 7.52025-12-01
PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.
- CVE-2025-65878HIGHCVSS 7.5EG 7.52025-12-05
The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImageByPath` does not sanitize user-controlled path parameters. An attacker could exploit directory traversal to read arbitr…
- CVE-2025-65879HIGHCVSS 8.1EG 8.12025-12-05
Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-controlled goodsimg parameter, which is directly concatenated with the server's UPLOAD_PATH and…
- CVE-2025-6589LOWCVSS 2.1EG 2.12026-02-02
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/specials/pagers/BlockListPager.Php. This issue affects MediaWiki: >= 1.42.0.
- CVE-2025-65897HIGHCVSS 8.8EG 8.82025-12-05
zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file upload paths in the application allows an authenticated user to write arbitrary files to the…
- CVE-2025-65952HIGHCVSS 8.7EG 8.72025-11-25
Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a path traversal vulnerability exists where complicated combinations of backslashes and periods can be used to escape the …
- CVE-2025-6597NONECVSS 0.0EG 0.02026-02-02
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/auth/AuthManager.Php. This issue affects MediaWiki: from * before 1.39.13, 1.42.7, 1.43.2, 1.44.0.
- CVE-2025-66051MEDIUMCVSS 6.5EG 6.52026-01-09
Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated attacker to access resources beyond webroot directory using a direct HTTP request. Due to CVE-2025-66050, a password f…
- CVE-2025-66206HIGHCVSS 8.6EG 8.62025-12-01
Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path traversal attacks, wherein some files from the server could be retrieved if the full path was known. Sites hosted on F…
- CVE-2025-66251CRITICALCVSS 9.1EG 9.12025-11-26
Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deletehidden …
- CVE-2025-66262CRITICALCVSS 9.8EG 9.82025-11-26
Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Tar extraction wit…
- CVE-2025-66278MEDIUMCVSS 6.5EG 6.52026-02-11
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed t…
- CVE-2025-66292HIGHCVSS 8.1EG 8.12026-01-15
DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vulnerability in the /api/common/attach/delete interface. Authenticated users can delete arbitrary files on the server vi…
- CVE-2025-66295HIGHCVSS 8.8EG 8.82025-12-01
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and supplies a username containing path traversal sequences (for example ..\Nijat or ../Nijat), …
- CVE-2025-66300HIGHCVSS 8.5EG 8.52025-12-01
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "Frontmatter" form. This includes Grav user account files (/grav/user/accounts/*.yaml), whi…
- CVE-2025-66302MEDIUMCVSS 6.8EG 6.82025-12-01
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated attackers with administrative privileges to read arbitrary files on the underlying server fil…
- CVE-2025-66410CRITICALCVSS 9.1EG 9.12025-12-01
Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' param…
- CVE-2025-66428HIGHCVSS 8.8EG 8.82026-01-22
An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.
- CVE-2025-66429HIGHCVSS 8.8EG 8.82025-12-11
An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitrary file. This can allow for privilege escalation to the root user.
- CVE-2025-66449HIGHCVSS 8.8EG 8.82025-12-16
ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on the system, overwriting binaries and allowing code execution. The upload function …
- CVE-2025-66480CRITICALCVSS 9.8EG 9.82026-02-02
Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component related to the file upload functionality found in com.xiaoleilu.loServer.action.UploadFileAc…
- CVE-2025-66518HIGHCVSS 8.8EG 8.82026-01-05
Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: fr…
- CVE-2025-66645HIGHCVSS 7.5EG 7.52025-12-09
NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server filesystem. This issue…
- CVE-2025-66687HIGHCVSS 7.5EG 7.52026-03-16
Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game files
- CVE-2025-66689MEDIUMCVSS 6.5EG 6.52026-01-12
A path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitrary files on the system. The vulnerability is caused by flawed logic in the is_dangerous_path() validation function that…
- CVE-2025-66744HIGHCVSS 7.5EG 7.52026-01-09
In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system
- CVE-2025-66905HIGHCVSS 7.5EG 7.52025-12-19
The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base d…
- CVE-2025-67004MEDIUMCVSS 6.5EG 6.52026-01-09
** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weapo…
- CVE-2025-67030HIGHCVSS 8.8EG 8.82026-03-25
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
- CVE-2025-67076HIGHCVSS 7.5EG 7.52026-01-15
Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGetFile action. Only files with an extension can be read.
- CVE-2025-67083MEDIUMCVSS 5.3EG 5.32026-01-15
Directory traversal vulnerability in InvoicePlane through 1.6.3 allows unauthenticated attackers to read files from the server. The ability to read files and the file type depends on the web server and its configuration.
- CVE-2025-67160HIGHCVSS 7.5EG 7.52026-01-02
An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory traversal.
- CVE-2025-67171HIGHCVSS 7.5EG 7.52025-12-17
Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.
- CVE-2025-67174HIGHCVSS 7.5EG 7.52025-12-17
A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_language_file and default_page_language_file in the admin.php component
- CVE-2025-67254HIGHCVSS 7.5EG 7.52025-12-29
NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →