Weaknesses of type CWE-22

5,866 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2025-2743MEDIUMzhijiantianya ruoyi-vue-pro Material Upload Interface upload-temporary path traversalEPSS 0.9%CVE-2026-65688CRITICALBold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Font ProcessingEPSS 0.9%CVE-2024-57451HIGHChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to EPSS 0.9%CVE-2026-65689CRITICALBold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Database DownloadEPSS 0.9%CVE-2024-48071MEDIUME-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server directory, causing the serEPSS 0.9%CVE-2024-5456HIGHPanda Video <= 1.4.0 - Authenticated (Contributor+) Local File InclusionEPSS 0.9%CVE-2023-24379MEDIUMWordPress Landing Page Builder – Free Landing Page Templates plugin <= 3.1.9.9 - Local File Inclusion vulnerabilityEPSS 0.9%CVE-2025-48370LOWauth-js Vulnerable to Insecure Path Routing from Malformed User InputEPSS 0.9%CVE-2023-3385MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabEPSS 0.9%CVE-2023-4748MEDIUMYongyou UFIDA-NC PrintTemplateFileServlet.java path traversalEPSS 0.9%CVE-2025-0461MEDIUMShanghai Lingdang Information Technology Lingdang CRM index.php path traversalEPSS 0.9%CVE-2025-55988HIGHAn issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via EPSS 0.9%CVE-2026-71476HIGHNx: Zip-Slip in the self-hosted remote cacheEPSS 0.9%CVE-2023-6026CRITICALImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in PHPMemcachedAdminEPSS 0.9%CVE-2023-39525MEDIUMPrestaShop vulnerable to path traversalEPSS 0.9%CVE-2022-44280MEDIUMAutomotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.EPSS 0.9%CVE-2024-37464MEDIUMWordPress Beaver Builder Addons by WPZOOM plugin <= 1.3.5 - Local File Inclusion vulnerabilityEPSS 0.9%CVE-2021-39369MEDIUMIn Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to aEPSS 0.9%CVE-2022-45829HIGHWordPress Easy WP SMTP Plugin <= 1.5.1 is vulnerable to Arbitrary File DeletionEPSS 0.9%CVE-2026-47731CRITICALNASA AMMOS Instrument Toolkit: Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)EPSS 0.9%