Weaknesses of type CWE-22

5,967 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2024-39624HIGHWordPress ListingPro theme <= 2.9.4 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-12198MEDIUMMicroweber API Endpoint thumbnail_img userfiles_path path traversalEPSS 0.5%CVE-2026-81481HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('EPSS 0.5%CVE-2026-12339MEDIUMAuthenticated Arbitrary File Write Vulnerability in multiple devicesEPSS 0.5%CVE-2024-37092HIGHWordPress Consulting Elementor Widgets plugin <= 1.3.0 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-82286HIGHgpt-crawler Arbitrary File Write via outputFileName ParameterEPSS 0.5%CVE-2026-15724HIGHPath traversal in Progress ShareFile Storage Zones Controller (SZC)EPSS 0.5%CVE-2024-47645HIGHWordPress WPOptin plugin <= 2.0.1 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-62947MEDIUMOpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-downloadEPSS 0.5%CVE-2024-36427HIGHThe file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authenticated attackers to EPSS 0.5%CVE-2023-24804MEDIUMownCloud Android app vulnerable to Path TraversalEPSS 0.5%CVE-2025-58423HIGHAdvantech DeviceOn/iEdge Path TraversalEPSS 0.5%CVE-2025-2519MEDIUMStreamit <= 4.0.1 - Authenticated (Subscriber+) Arbitrary File DownloadEPSS 0.5%CVE-2025-52913CRITICALA vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allow an unauthenticatedEPSS 0.5%CVE-2025-24960HIGHMissing Input validation for filename in backups endpoint in JellystatEPSS 0.5%CVE-2025-70950HIGHAn issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.EPSS 0.5%CVE-2026-96651HIGHPlex Media Server path traversalEPSS 0.5%CVE-2024-33568HIGHWordPress Element Pack Pro plugin < 7.19.3 - Arbitrary File Read and Phar Deserialization vulnerabilityEPSS 0.5%CVE-2024-55970HIGHFile Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aEPSS 0.5%CVE-2025-39568HIGHWordPress StoreContrl Woocommerce plugin <= 4.1.3 - Arbitrary File Download VulnerabilityEPSS 0.5%