Weaknesses of type CWE-22

5,905 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-86775HIGHknowns before 0.30.0 Path Traversal via Document APIEPSS 0.7%CVE-2023-27055HIGHAver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request.EPSS 0.7%CVE-2023-31131HIGHArbitrary File Write when Extracting Tarballs in greenplum-dbEPSS 0.7%CVE-2005-10002MEDIUMalmosteffortless secure-files Plugin secure-files.php sf_downloads path traversalEPSS 0.7%CVE-2024-52292HIGHCraft Allows Attackers to Read Arbitrary System FilesEPSS 0.7%CVE-2024-52054MEDIUMApplication Creation Path Traversal in Wowza Streaming EngineEPSS 0.7%CVE-2022-4885MEDIUMsviehb jefferson path traversalEPSS 0.7%CVE-2026-2419LOWWP-DownloadManager <= 1.69 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'download_path' ParameterEPSS 0.7%CVE-2024-13920MEDIUMOrder Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file FunctionEPSS 0.7%CVE-2023-0290MEDIUMRapid7 Velociraptor directory traversal in client ID parameter EPSS 0.7%CVE-2024-54259MEDIUMWordPress DELUCKS SEO plugin <= 2.7.0 - Arbitrary File Download vulnerabilityEPSS 0.7%CVE-2025-57644CRITICALAccela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative useEPSS 0.7%CVE-2026-72602HIGHAsyncFuncAI deepwiki-open - Path TraversalEPSS 0.7%CVE-2026-16137HIGHPath traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones ControllerEPSS 0.7%CVE-2021-47849HIGHMini Mouse 9.3.0 - Local File inclusion / Path TraversalEPSS 0.7%CVE-2024-36059CRITICALDirectory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitraEPSS 0.7%CVE-2022-45852MEDIUMWordPress WP-FormAssembly plugin <= 2.0.5 - Auth. Arbitrary File Read vulnerabilityEPSS 0.7%CVE-2023-3406HIGHPath traversal issue in M-Files Classic WebEPSS 0.7%CVE-2024-55657HIGHSiYuan has an arbitrary file read via /api/template/renderEPSS 0.7%CVE-2024-10799MEDIUMEventer <= 3.9.7 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.7%