Weaknesses of type CWE-22

5,931 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-59555CRITICALWordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2026-27969CRITICALVitess users with backup storage access can write to arbitrary file paths on restoreEPSS 0.6%CVE-2024-35743HIGHWordPress SC filechecker plugin <= 0.6 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2026-65431CRITICALJoomla Extension - regularlabs.com - Zipslip in GeoIP extensionEPSS 0.6%CVE-2026-47884CRITICALSpring Framework Improper Path Limitation in XsltViewEPSS 0.6%CVE-2024-35744HIGHWordPress Upunzipper plugin <= 1.0.0 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2024-37419HIGHWordPress Cowidgets – Elementor Addons plugin <= 1.1.1 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2024-8941HIGHPath Traversal vulnerability on ScriptcaseEPSS 0.6%CVE-2026-42520HIGHJenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing aEPSS 0.6%CVE-2024-43955CRITICALWordPress Droip plugin <= 1.1.1 - Unauthenticated Arbitrary File Download/Deletion vulnerabilityEPSS 0.6%CVE-2025-25371HIGHNASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the EPSS 0.6%CVE-2025-5993CRITICALPath Traversal in ITCube CRMEPSS 0.6%CVE-2026-33656CRITICALEspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin userEPSS 0.6%CVE-2026-74044HIGHWazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster HelloEPSS 0.6%CVE-2024-8262CRITICALPath Traversal in Proliz Software's OBSEPSS 0.6%CVE-2026-6282HIGHA potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remoteEPSS 0.6%CVE-2025-51480HIGHPath Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files byEPSS 0.6%CVE-2026-40547MEDIUMPath Traversal in SOPlanningEPSS 0.6%CVE-2024-45593CRITICALNix affected by unsafe NAR unpackingEPSS 0.6%CVE-2025-9435MEDIUMPath TraversalEPSS 0.6%