Weaknesses of type CWE-22

5,950 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2024-49245HIGHWordPress Ahime Image Printer plugin <= 1.0.0 - Arbitrary File Download vulnerabilityEPSS 0.6%CVE-2024-52378HIGHWordPress DigiPass plugin <= 0.3.0 - Arbitrary File Download vulnerabilityEPSS 0.6%CVE-2026-13048HIGHData::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filenameEPSS 0.6%CVE-2025-66689MEDIUMA path traversal vulnerability exists in Zen MCP Server before 9.8.2 that allows authenticated attackers to read arbitrary files on the systEPSS 0.6%CVE-2025-60969MEDIUMDirectory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers toEPSS 0.6%CVE-2026-90774HIGHrustypaste before 0.18.1 Path Traversal via filename headerEPSS 0.6%CVE-2024-35745HIGHWordPress Strategery Migrations plugin <= 1.0 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2026-71215HIGHart-template - Path Traversal in Sub-Template Resolution via include()/extend()EPSS 0.6%CVE-2024-12362MEDIUMInvoicePlane invoices.php download path traversalEPSS 0.6%CVE-2024-44012HIGHWordPress WP Newsletter Subscription plugin <= 1.1 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2024-44015HIGHWordPress Users Control plugin <= 1.0.16 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-66492MEDIUMJoomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3EPSS 0.6%CVE-2024-44016HIGHWordPress Podiant plugin <= 1.1 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2024-44018HIGHWordPress Instant Chat WP plugin <= 1.0.5 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-15265CRITICALTenable Agent Path Traversal Leading to Remote Code ExecutionEPSS 0.6%CVE-2024-44017HIGHWordPress MH Board plugin <= 1.3.2.1 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-52832MEDIUMNuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard containerEPSS 0.6%CVE-2024-44011HIGHWordPress WP Ticket Ultra plugin <= 1.0.5 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-17602MEDIUMSSL Zen <= 4.7.42 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'file_name' ParameterEPSS 0.6%CVE-2024-44034HIGHWordPress WPSPX plugin <= 1.0.2 - Local File Inclusion vulnerabilityEPSS 0.6%