Weaknesses of type CWE-22

5,950 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2024-41792CRITICALA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices contains a patEPSS 0.6%CVE-2024-31232HIGHWordPress Rehub theme <= 19.6.1 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2025-24569HIGHWordPress PDF Generator Addon for Elementor Page Builder plugin <= 1.7.5 - Arbitrary File Read vulnerabilityEPSS 0.6%CVE-2025-21095MEDIUMKeysight Ixia Vision Product Family Path TraversalEPSS 0.6%CVE-2024-44013HIGHWordPress VR Calendar plugin <= 2.4.0 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2025-3317MEDIUMfumiao opencms dataPage.jsp path traversalEPSS 0.6%CVE-2025-27101HIGHBroken Access Control in Opal filesystem's copy functionality exposes all user dataEPSS 0.6%CVE-2025-4175MEDIUMAlanBinu007 Spring-Boot-Advanced-Projects Upload Profile API Endpoint UserProfileController.java uploadUserProfileImage path traversalEPSS 0.6%CVE-2026-34522HIGHSillyTavern: Path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directoryEPSS 0.6%CVE-2026-33293HIGHAVideo Affected by Arbitrary File Deletion via Path Traversal in CloneSite deleteDump ParameterEPSS 0.6%CVE-2024-43165MEDIUMWordPress WPSection plugin <= 1.3.8 - Contributor+ Limited Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-54083HIGHWazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletionEPSS 0.6%CVE-2024-49780MEDIUMIBM OpenPages path traversalEPSS 0.6%CVE-2024-55597MEDIUMA improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows atEPSS 0.6%CVE-2026-33686HIGHSharp is Vulnerable to Path Traversal via Unsanitized Extension in FileUtilEPSS 0.6%CVE-2024-42474MEDIUMStreamlit Path Traversal Security Vulnerability on WindowsEPSS 0.6%CVE-2026-72773MEDIUMn8n before 2.32.1 Path Traversal via computer-use search_filesEPSS 0.6%CVE-2023-5588LOWkphrx pleroma pack.ex Pleroma.Emoji.Pack path traversalEPSS 0.6%CVE-2026-53825HIGHOpenClaw < 2026.4.7 - Arbitrary Local File Read via memory-wiki Ingest with operator.write ScopeEPSS 0.6%CVE-2024-43957MEDIUMWordPress Animated Number Counters plugin <= 1.9 - Editor+ Limited Local File Inclusion vulnerabilityEPSS 0.6%