Weaknesses of type CWE-22

5,949 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2018-25178HIGHEasyndexer 1.0 Arbitrary File Download via showtif.phpEPSS 0.6%CVE-2022-44653HIGHA security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalatEPSS 0.6%CVE-2021-25367LOWPath Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without permission.EPSS 0.6%CVE-2024-32830HIGHWordPress buddyforms plugin <= 2.8.8- Arbitrary File Read and SSRF vulnerabilityEPSS 0.6%CVE-2023-45383HIGHIn the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personalEPSS 0.6%CVE-2026-46337MEDIUMWWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`EPSS 0.6%CVE-2024-56286HIGHWordPress Classic Addons – WPBakery Page Builder plugin <= 3.0 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-33747HIGHBuildKit vulnerable to malicious frontend causing file escape outside of storage rootEPSS 0.6%CVE-2023-6032MEDIUM A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file systeEPSS 0.6%CVE-2024-43140HIGHWordPress Ultimate Bootstrap Elements for Elementor plugin <= 1.4.4 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2024-37231HIGHWordPress Salon booking system plugin <= 9.9 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2026-64825CRITICALHome Assistant Core < 2026.6.0 Path Traversal File Write via Backup UploadEPSS 0.6%CVE-2024-38292CRITICALIn Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege EPSS 0.6%CVE-2026-65702HIGHVanna 2.0.2 Path Traversal via FileSystemConversationStoreEPSS 0.6%CVE-2026-71268CRITICALOpenPLC Runtime v3 Path Traversal in Structured Text FILE Directive Leading to Arbitrary File WriteEPSS 0.6%CVE-2026-16908HIGHIBM i is Affected By Multiple SQL Vulnerabilities [, ]EPSS 0.6%CVE-2026-78886MEDIUMliketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversalEPSS 0.6%CVE-2026-3666HIGHwpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post BodyEPSS 0.6%CVE-2025-54293HIGHPath Traversal in LXD Instance Log File RetrievalEPSS 0.6%CVE-2026-43624HIGHF5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project()EPSS 0.6%