We have discovered 3,534,416 live websites that are affected by CWE-22.
| 914,541 websites | |
| 346,180 websites | |
| 219,787 websites | |
| 186,291 websites | |
| 154,027 websites | |
| 134,458 websites | |
| 107,584 websites | |
| 104,732 websites | |
| 104,345 websites | |
| 88,443 websites |
| .com | 1,396,904 websites |
| .de | 193,616 websites |
| .it | 153,378 websites |
| .org | 148,856 websites |
| .ru | 109,057 websites |
| .nl | 91,593 websites |
| .co.uk | 89,574 websites |
| .com.br | 82,298 websites |
| .pl | 80,965 websites |
| .net | 80,200 websites |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Apr, 2026 | CVE-2026-4351 | Perfmatters <= 2.5.9 - Authenticated (Subscriber+) Arbitrary File Overwrite via 'snippets' Parameter | 17,092 |
| Apr, 2026 | CVE-2026-31939 | Path Traversal (Arbitrary File Delete) in Chamilo LMS | 9 |
| Apr, 2026 | CVE-2026-5436 | MW WP Form <= 5.1.1 - Unauthenticated Arbitrary File Move via regenerate_upload_file_keys | 390 |
| Apr, 2026 | CVE-2026-39844 | NiceGUI has a Path Traversal in NiceGUI Upload Filename on Windows via Backslash Bypass of PurePosixPath Sanitization | 18 |
| Apr, 2026 | CVE-2026-39345 | OrangeHRM Affected by Arbitrary File Read via Path Traversal in Email Template Loader | 9 |
| Apr, 2026 | CVE-2026-39365 | Vite has a Path Traversal in Optimized Deps `.map` Handling | 3 |
| Apr, 2026 | CVE-2026-4350 | Perfmatters <= 2.5.9.1 - Authenticated (Subscriber+) Arbitrary File Deletion via 'delete' Parameter | 17,092 |
| Apr, 2026 | CVE-2026-4347 | MW WP Form <= 5.1.0 - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir | 387 |
| Apr, 2026 | CVE-2026-34728 | phpMyFAQ: Path Traversal - Arbitrary File Deletion in MediaBrowserController | 195 |
| Mar, 2026 | CVE-2025-15433 | Shared Files < 1.7.58 - Contributor+ Arbitrary File Download | 578 |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Aug, 2025 | CVE-2025-9217 | Slider Revolution <= 6.7.36 - Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images' | 1,174,043 |
| Aug, 2025 | CVE-2025-8081 | Elementor <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import | 992,311 |
| Aug, 2024 | CVE-2024-5709 | WPBakery <= 7.7 - Authenticated (Author+) Local File Inclusion | 843,102 |
| May, 2023 | CVE-2023-2745 | WordPress Core < 6.2.1 - Directory Traversal | 703,872 |
| Jun, 2024 | CVE-2024-32111 | WordPress core < 6.5.5 - Auth. Arbitrary .html File Read (Windows Only) vulnerability | 569,182 |
| May, 2024 | CVE-2024-24934 | WordPress Elementor plugin <= 3.19.0 - Arbitrary File Deletion and Phar Deserialization vulnerability | 449,984 |
| Mar, 2026 | CVE-2026-2448 | Page Builder by SiteOrigin <= 2.33.5 - Authenticated (Contributor+) Local File Inclusion | 110,196 |
| Mar, 2026 | CVE-2026-3585 | The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import | 83,734 |
| May, 2024 | CVE-2023-46205 | WordPress Ultimate Addons for WPBakery Page Builder plugin <= 3.19.14 - Local File Inclusion vulnerability | 66,899 |
| Apr, 2022 | CVE-2022-24785 | Path Traversal in Moment.js | 63,038 |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.io | *** | ||
| *****.net | *** | ||
| **************.de | *** | ||
| ***.********.com | *** | ||
| ***************.org | *** | ||
| **********.com | *** | ||
| ******.com | *** | ||
| ****.com | *** | ||
| ****************.de | *** | ||
| **********.com | *** |