Weaknesses of type CWE-22

5,950 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2024-35778MEDIUMWordPress Slideshow SE plugin <= 2.5.17 - Auth. Limited Local File Inclusion vulnerabilityEPSS 0.6%CVE-2024-43129MEDIUMWordPress BetterDocs plugin <= 3.5.8 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2024-43957MEDIUMWordPress Animated Number Counters plugin <= 1.9 - Editor+ Limited Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-30942HIGHFlare has a Path Traversal in /api/avatars/[filename]EPSS 0.6%CVE-2026-49984HIGHKestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary server files via the execution file-download API (`\..\` bypasses the `..` guard)EPSS 0.6%CVE-2026-26202HIGHPenpot has Arbitrary File Read via create-font-variant RPC endpointEPSS 0.6%CVE-2023-47178HIGHWordPress The Plus Addons for Elementor Pro plugin <= 5.2.8 - Unauthenticated Local File Inclusion vulnerabilityEPSS 0.6%CVE-2022-4572MEDIUMUBI Reader UBIFS File output.py ubireader_extract_files path traversalEPSS 0.6%CVE-2024-34384MEDIUMWordPress Sina Extension for Elementor plugin <= 3.5.1 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2025-1281HIGHBM Content Builder < 3.17.1 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.6%CVE-2025-31493MEDIUMPath traversal of collection names during file system lookupEPSS 0.6%CVE-2025-2215MEDIUMDoufox s=doudou path traversalEPSS 0.6%CVE-2026-7872HIGHPath Traversal Vulnerability in File Component Leading to Arbitrary File Read and Authentication BypassEPSS 0.6%CVE-2026-100682HIGHBudibase Server before 3.45.0 Arbitrary File Write via ZIP SymlinkEPSS 0.6%CVE-2018-25393HIGHNavigate CMS 2.8.5 Path Traversal via navigate_download.phpEPSS 0.6%CVE-2024-8165MEDIUMChengdu Everbrite Network Technology BeikeShop export exportZip path traversalEPSS 0.6%CVE-2026-22249HIGHDocmost affected by an Arbitrary File Write via Zip Import Feature (ZipSlip)EPSS 0.6%CVE-2026-5331MEDIUMOpenCart Extension Installer installer.php path traversalEPSS 0.6%CVE-2026-33292HIGHAVideo has Authorization Bypass via Path Traversal in HLS Endpoint Allows Streaming Private/Paid VideosEPSS 0.6%CVE-2025-30207LOWKirby vulnerable to path traversal in the router for PHP's built-in serverEPSS 0.6%