Weaknesses of type CWE-22

5,967 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-19725CRITICALWPvivid Backup & Migration < 0.9.131 - Unauthenticated Path Traversal via send_to_site_connectEPSS 0.5%CVE-2025-22205HIGHExtension - admiror-design-studio.com - Path traversal in the Admiror Gallery 4.x component for JoomlaEPSS 0.5%CVE-2026-47669CRITICALDbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCEEPSS 0.5%CVE-2026-1549MEDIUMjishenghua jshERP PluginController uploadPluginConfigFile path traversalEPSS 0.5%CVE-2025-47512HIGHWordPress Tainacan plugin <= 0.21.14 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2024-33870MEDIUMAn issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary fileEPSS 0.5%CVE-2026-81028MEDIUMZLMediaKit downloadFile Root-Directory Confinement Bypass via Prefix CollisionEPSS 0.5%CVE-2026-43982HIGHAlgernon: Path traversal file write via savein()EPSS 0.5%CVE-2026-46486MEDIUMMobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS Backup processingEPSS 0.5%CVE-2026-63179MEDIUMWinter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assetsEPSS 0.5%CVE-2026-45532HIGHDataEase has a Path Traversal VulnerabilityEPSS 0.5%CVE-2026-32747MEDIUMSiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secretsEPSS 0.5%CVE-2026-41363MEDIUMOpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image ParameterEPSS 0.5%CVE-2024-34552HIGHWordPress Stockholm theme <= 9.6 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2024-11219MEDIUMOtter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image ViewEPSS 0.5%CVE-2024-34554HIGHWordPress Stockholm Core plugin <= 2.4.1 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2024-37501HIGHWordPress Advanced Classifieds & Directory Pro plugin <= 3.1.3 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-41589CRITICALWish has SCP Path Traversal that allows arbitrary file read/writeEPSS 0.5%CVE-2026-33344HIGHDagu has an incomplete fix for CVE-2026-27598: path traversal via %2F-encoded slashes in locateDAGEPSS 0.5%CVE-2026-30828HIGHWallos: SSRF via url parameter leading to File TraversalEPSS 0.5%