Path Traversal (CWE-22)
CWE-22 happens when a product uses outside input to build a pathname meant to stay under a restricted directory but fails to neutralize elements that resolve outside it. Parent-directory sequences give relative path traversal, and full pathnames give absolute path traversal. MITRE prefers the term path traversal over directory traversal.
About CWE-22
Attackers may read files outside the intended directory, overwrite or create files such as programs and libraries, or corrupt critical files. That can expose sensitive data, bypass security mechanisms, crash the product or lead to code execution.
Mitigations
- +Validate filenames with a strict allowlist of characters, allow at most one dot, and exclude directory separators.
- +Decode and canonicalize input to the application's internal form before validating it, and avoid decoding the same input twice.
- +Do not rely on filters that strip dangerous characters, since a filtered result can still form a traversal sequence.
- +Repeat client-side checks on the server.
- +Use a list of permitted file extensions to reduce related upload risks.
Detection
Automated static analysis is rated highly effective, though tuning may be needed to deprioritize paths only an administrator controls. Manual code review is also effective when file operations can be assessed in reasonable time.
CWE-22 Vulnerabilities
33 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-104286 | Fortinet FortiMail Path Traversal Vulnerability | Fortinet | 9.8 | 2.2% | KEV | 2026-10-01 |
| CVE-2026-93616 | Directory Traversal and File upload allows execution of arbitrary script on the Management Server | checkpoint | 9.8 | 19.7% | KEV | 2026-09-22 |
| CVE-2026-85706 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab | GitLab | 10.0 | 93.0% | KEV | 2026-09-12 |
| CVE-2026-66384 | Authenticated users may write data outside the intended Docker cache path | jfrog | 5.3 | 0.7% | KEV | 2026-08-12 |
| CVE-2026-59310 | vCenter directory-traversal vulnerability | VMware | 9.8 | 2.6% | KEV | 2026-07-30 |
| CVE-2026-48282 | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) | Adobe | 10.0 | 42.4% | KEV | 2026-06-30 |
| CVE-2026-34909 | Ubiquiti UniFi OS Path Traversal Vulnerability | Ubiquiti Inc | 10.0 | 1.8% | KEV | 2026-05-22 |
| CVE-2024-1708 | Improper limitation of a pathname to a restricted directory (“path traversal”) | ConnectWise | 8.4 | 95.4% | KEV | 2024-02-21 |
| CVE-2024-7399 | Samsung MagicINFO 9 Server Path Traversal Vulnerability | Samsung Electronics | 8.8 | 91.9% | KEV | 2024-08-09 |
| CVE-2025-2749 | Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE | Kentico | 7.2 | 4.1% | KEV | 2025-03-24 |
| CVE-2025-8110 | File overwrite in file update API in Gogs | Gogs | 8.7 | 85.2% | KEV | 2025-12-10 |
| CVE-2025-6218 | RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability | RARLAB | 7.8 | 90.5% | KEV | 2025-06-21 |
| CVE-2021-43798 | Grafana path traversal | grafana | 7.5 | 88.5% | KEV | 2021-12-07 |
| CVE-2019-5418 | Rails Ruby on Rails Path Traversal Vulnerability | Rails | 7.5 | 98.5% | KEV | 2019-03-27 |
| CVE-2024-0769 | D-Link DIR-859 HTTP POST Request hedwig.cgi path traversal | D-Link | 5.3 | 82.7% | KEV | 2024-01-21 |
| CVE-2025-4632 | Samsung MagicINFO 9 Server Path Traversal Vulnerability | Samsung Electronics | 9.8 | 24.3% | KEV | 2025-05-13 |
| CVE-2025-34028 | Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal | Commvault | 9.3 | 97.6% | KEV | 2025-04-22 |
| CVE-2024-4885 | WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability | Progress Software Corporation | 9.8 | 99.3% | KEV | 2024-06-25 |
| CVE-2024-11667 | Zyxel Multiple Firewalls Path Traversal Vulnerability | Zyxel | 7.5 | 2.9% | KEV | 2024-11-27 |
| CVE-2024-8963 | Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability | Ivanti | 9.4 | 98.6% | KEV | 2024-09-19 |
| CVE-2024-7262 | Arbitrary Code Execution in WPS Office | Kingsoft | 9.3 | 2.9% | KEV | 2024-08-15 |
| CVE-2024-32113 | Apache OFBiz: Path traversal leading to RCE | Apache Software Foundation | 9.1 | 99.9% | KEV | 2024-05-08 |
| CVE-2024-28995 | SolarWinds Serv-U L Directory Transversal Vulnerability | SolarWinds | 8.6 | 99.6% | KEV | 2024-06-06 |
| CVE-2023-32315 | Openfire administration console authentication bypass | igniterealtime | 8.6 | 100.0% | KEV | 2023-05-26 |
| CVE-2022-41328 | Fortinet FortiOS Path Traversal Vulnerability | Fortinet | 6.5 | 10.7% | KEV | 2023-03-07 |
| CVE-2014-0780 | InduSoft Web Studio Path Traversal | InduSoft | 9.8 | 74.7% | KEV | 2014-04-25 |
| CVE-2019-7483 | SonicWall SMA100 Directory Traversal Vulnerability | SonicWall | 7.5 | 4.0% | KEV | 2019-12-19 |
| CVE-2020-1631 | Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services | Juniper Networks | 8.8 | 4.8% | KEV | 2020-05-04 |
| CVE-2021-41773 | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 | Apache Software Foundation | 7.5 | 100.0% | KEV | 2021-10-05 |
| CVE-2021-42013 | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) | Apache Software Foundation | 9.8 | 100.0% | KEV | 2021-10-07 |
| CVE-2021-20023 | SonicWall Email Security Path Traversal Vulnerability | SonicWall | 4.9 | 51.7% | KEV | 2021-04-20 |
| CVE-2026-1056 | Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal | inc2734 | 9.8 | 13.5% | 2026-01-28 | |
| CVE-2026-22218 | Chainlit < 2.9.4 Arbitrary File Read via /project/element | Chainlit | 7.1 | 9.5% | 2026-01-19 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-22?→
CWE-22 is MITRE's entry for path traversal. Outside input builds a file path that escapes the directory it was supposed to stay within.
Which child entries should be considered instead of CWE-22?→
MITRE suggests CWE-23 for relative path traversal and CWE-36 for absolute path traversal when the details are known.
How many exploited vulnerabilities are classified as CWE-22?→
This database lists 33 CVE records mapped to CWE-22 by their CVE Numbering Authority. 31 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 6 to known ransomware campaigns. Examples include CVE-2026-104286, CVE-2026-93616, CVE-2026-85706.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.