Weaknesses of type CWE-22

5,925 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2025-1785MEDIUMDownload Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File OverwriteEPSS 0.7%CVE-2023-23608NONEspotipy Path traversal vulnerability that may lead to type confusion in URI handling codeEPSS 0.7%CVE-2024-24869HIGHWordPress Total Upkeep plugin <= 1.15.8 - Arbitrary File Download vulnerabilityEPSS 0.7%CVE-2025-34518HIGHIlevia EVE X1 Server 4.7.18.0.eden Relative Path TraversalEPSS 0.7%CVE-2025-34517HIGHIlevia EVE X1 Server 4.7.18.0.eden Absolute Path TraversalEPSS 0.7%CVE-2024-29502MEDIUMAn issue in Secure Lockdown Multi Application Edition v2.00.219 allows attackers to read arbitrary files via using UNC paths.EPSS 0.7%CVE-2022-4778MEDIUMpath traversal in elvexys StreamX using StreamView HTML component with public web server featureEPSS 0.7%CVE-2019-25671HIGHVA MAX 8.3.4 Remote Code Execution via changeip.phpEPSS 0.7%CVE-2023-29962MEDIUMS-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.EPSS 0.7%CVE-2026-82253HIGHgitoxide before 0.82.0 Path Traversal via Submodule Name Validation BypassEPSS 0.7%CVE-2026-16777MEDIUMStore Exporter <= 2.8.0 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read and Arbitrary File Deletion via 'filename' ParameterEPSS 0.7%CVE-2026-2731CRITICALUnauthenticated RCE in Dynamicweb 9 and Dynamicweb 8EPSS 0.7%CVE-2026-28462HIGHOpenClaw < 2026.2.13 - Path Traversal in Trace and Download Output PathsEPSS 0.7%CVE-2024-6648HIGHPath Traversal in AP Page BuilderEPSS 0.7%CVE-2025-2817HIGHPrivilege escalation in Thunderbird UpdaterEPSS 0.7%CVE-2024-57549HIGHCMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.EPSS 0.7%CVE-2025-49559MEDIUMAdobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.7%CVE-2026-17266MEDIUMIBM i is Affected By Multiple Vulnerabilities in Navigator for iEPSS 0.7%CVE-2026-17173MEDIUMIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.7%CVE-2022-4878MEDIUMJATOS ZIP ZipUtil.java ZipUtil path traversalEPSS 0.7%