Weaknesses of type CWE-22

5,868 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-4280MEDIUMBreaking News WP <= 1.3 - Missing Authorization to Authenticated (Subscriber+) Local File Inclusion/ReadEPSS 0.8%CVE-2023-40280HIGHAn issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET requesEPSS 0.8%CVE-2026-33466HIGHImproper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File WriteEPSS 0.8%CVE-2026-30285CRITICALAn arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critical internal files viEPSS 0.8%CVE-2025-11031MEDIUMDataTables examples.php path traversalEPSS 0.8%CVE-2022-41920MEDIUMZip slip in LancetEPSS 0.8%CVE-2024-51747CRITICALArbitrary File Read and Delete in kanboardEPSS 0.8%CVE-2020-36629MEDIUMSimbCo httpster server.coffee fs.realpathSync path traversalEPSS 0.8%CVE-2026-27897CRITICALVociferous Unauthenticated Remote Path Traversal (RCE via CSRF)EPSS 0.8%CVE-2026-40342CRITICALFirebird: Path Traversal + Arbitrary File Write Leads to Remote Code ExecutionEPSS 0.8%CVE-2023-44251HIGH** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FoEPSS 0.8%CVE-2026-9197MEDIUMSmart Slider 3 <= 3.5.1.36 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'src'/'srcset' Attribute in HTML ExportEPSS 0.8%CVE-2024-22328HIGHIBM Maximo Application Suite information disclosureEPSS 0.8%CVE-2025-34185HIGHIlevia EVE X1 Server 4.7.18.0.eden Unauthenticated File DisclosureEPSS 0.8%CVE-2022-45374HIGHWordPress Yet Another Related Posts Plugin (YARPP) plugin <= 5.30.4 - Local File InclusionEPSS 0.8%CVE-2026-40050CRITICALCrowdStrike LogScale Unauthenticated Path TraversalEPSS 0.8%CVE-2026-53535MEDIUMActivepieces: Arbitrary file write in git-sync via path traversal and symlinksEPSS 0.8%CVE-2026-84374HIGHLaravel Excel writes exports outside the configured filesystem disk when given a caller-controlled pathEPSS 0.8%CVE-2025-10472MEDIUMharry0703 MoneyPrinterTurbo URL video.py stream_video path traversalEPSS 0.8%CVE-2023-41877HIGHGeoServer log file path traversal vulnerabilityEPSS 0.8%