Weaknesses of type CWE-22

5,941 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2025-30882HIGHWordPress JS Help Desk plugin <= 2.9.1 - Arbitrary File Download vulnerabilityEPSS 0.6%CVE-2026-7547MEDIUMWoosa <= 2.0.5 - Authenticated (Administrator+) Arbitrary File Read via 'log_file' ParameterEPSS 0.6%CVE-2024-37932HIGHWordPress Woocommerce OpenPos plugin <= 6.4.4 - Unauthenticated Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2024-36079MEDIUMAn issue was discovered in Vaultize 21.07.27. When uploading files, there is no check that the filename parameter is correct. As a result, aEPSS 0.6%CVE-2025-24019HIGHYesWiki vulnerable to authenticated arbitrary file deletionEPSS 0.6%CVE-2024-37928HIGHWordPress Jobmonster theme <= 4.7.0 - Unauthenticated Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2026-32805HIGHRomeo is vulnerable to Archive Slip due to missing checks in sanitizationEPSS 0.6%CVE-2026-3474MEDIUMEmailKit <= 1.6.3 - Authenticated (Administrator+) Path Traversal via 'emailkit-editor-template' REST API ParameterEPSS 0.6%CVE-2026-55469MEDIUMSnipe-IT: Path traversal vulnerability via CSV import `image` fieldEPSS 0.6%CVE-2024-52371HIGHWordPress Global Gateway e4 plugin <= 2.0 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2025-54450HIGHImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allowEPSS 0.6%CVE-2021-45448HIGHPentaho Business Analytics Server - Pentaho Analyzer plugin exposes a service endpoint for templates which allows a user supplied path to access resources that are out of bounds.EPSS 0.6%CVE-2026-78381HIGHRansomLook Arbitrary File Read via Path Traversal in Post screen FieldEPSS 0.6%CVE-2026-5710HIGHDrag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Limited Arbitrary File Read via mfile FieldEPSS 0.6%CVE-2023-45652MEDIUMWordPress Remote Content Shortcode plugin <= 1.5 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2023-31166MEDIUMImproper Limitation of a Pathname to a Restricted DirectoryEPSS 0.6%CVE-2026-7594MEDIUMFlux159 mcp-game-asset-gen MCP index.ts image_to_3d_async path traversalEPSS 0.6%CVE-2026-7213MEDIUMef10007 MLOps_MCP save_file Tool fastmcp_server.py path traversalEPSS 0.6%CVE-2026-7398MEDIUMflorensiawidjaja BioinfoMCP Upload Endpoint app.py upload path traversalEPSS 0.6%CVE-2026-7384MEDIUMezequiroga mcp-bases research_server.py search_papers path traversalEPSS 0.6%