Weaknesses of type CWE-22

5,913 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2024-32024MEDIUMKohya_ss vulenrable to path injection in `common_gui.py` `add_pre_postfix` function (`GHSL-2024-023`)EPSS 0.7%CVE-2024-41704CRITICALLibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.EPSS 0.7%CVE-2024-24311HIGHPath Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for PrestaShop before versEPSS 0.7%CVE-2025-41035HIGHPath Traversal vulnerability in appRain CMFEPSS 0.7%CVE-2026-66384MEDIUMAuthenticated users may write data outside the intended Docker cache pathEPSS 0.7%KEVCVE-2024-3934MEDIUMMercado Pago payments for WooCommerce 7.3.0 - 7.6.1 - Authenticated (Subscriber+) Arbitrary File DownloadEPSS 0.7%CVE-2025-10307MEDIUMBackuply – Backup, Restore, Migrate and Clone <= 1.4.8 - Authenticated (Admin+) Arbitrary File DeletionEPSS 0.7%CVE-2025-70231CRITICALD-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verification codes in /goform/EPSS 0.7%CVE-2021-46902HIGHAn issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. PathEPSS 0.7%CVE-2026-7474HIGHNomad vulnerable to path traversal in dynamic host volume which may lead to code executionEPSS 0.7%CVE-2026-50003CRITICALOFFIS DCMTK Toolkit Path TraversalEPSS 0.7%CVE-2026-54414CRITICALFileRise shared-folder upload path traversal allows arbitrary file write and admin takeoverEPSS 0.7%CVE-2026-15160MEDIUMNinja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated (Subscriber+) XLS Write via Path TraversalEPSS 0.7%CVE-2023-49960HIGHIn Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmware allows remote attEPSS 0.7%CVE-2023-45197CRITICALAdminer and AdminerEvo vulnerable to directory traversal and file uploadEPSS 0.7%CVE-2023-3697HIGHA Command injection vulnerability was found on Printer service of ADMEPSS 0.7%CVE-2025-67030HIGHDirectory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2dEPSS 0.7%CVE-2024-40051HIGHIP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter.EPSS 0.7%CVE-2024-52883HIGHAn issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive daEPSS 0.7%CVE-2026-43637HIGHCornac < 2.6.0 Path Traversal via _extract_archive() in download.pyEPSS 0.7%