Weaknesses of type CWE-22

5,950 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2025-8895CRITICALWP Webhooks <= 3.3.5 - Unauthenticated Arbitrary File CopyEPSS 0.6%CVE-2026-75111HIGHEvidently UI Path Traversal via Dataset Materialization FilenameEPSS 0.6%CVE-2024-25620MEDIUMDependency management path traversal in helmEPSS 0.6%CVE-2024-47264MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology ActiEPSS 0.6%CVE-2026-18051CRITICALW3 Total Cache < 2.10.5 - Unauthenticated Arbitrary Directory File Write and .htaccess Overwrite via Path Traversal in the Page Cache KeyEPSS 0.6%CVE-2026-8802MEDIUMopensourcepos Open Source Point of Sale Items.php getPicThumb path traversalEPSS 0.6%CVE-2025-13265MEDIUMlsfusion platform ZipUtils.java unpackFile path traversalEPSS 0.6%CVE-2026-13170HIGHEventin < 4.1.20 - Editor+ Local File Inclusion via speaker_template SettingEPSS 0.6%CVE-2024-12885MEDIUMConnections Business Directory <= 10.4.66 - Authenticated (Admin+) Arbitrary Directory DeletionEPSS 0.6%CVE-2026-30282CRITICALAn arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internalEPSS 0.6%CVE-2026-14818HIGHA path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 throuEPSS 0.6%CVE-2024-47309MEDIUMWordPress Cities Shipping Zones for WooCommerce plugin <= 1.2.7 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-32749HIGHSiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file writeEPSS 0.6%CVE-2026-20297HIGHPath Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk EnterpriseEPSS 0.6%CVE-2024-41792CRITICALA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices contains a patEPSS 0.6%CVE-2026-2551MEDIUMZenTao Backup control.php delete path traversalEPSS 0.6%CVE-2026-46484HIGHHeadplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/userEPSS 0.6%CVE-2024-31232HIGHWordPress Rehub theme <= 19.6.1 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2025-68406LOWQsync CentralEPSS 0.6%CVE-2026-22894LOWFile Station 5EPSS 0.6%