Weaknesses of type CWE-22

5,968 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-41589CRITICALWish has SCP Path Traversal that allows arbitrary file read/writeEPSS 0.5%CVE-2024-37501HIGHWordPress Advanced Classifieds & Directory Pro plugin <= 3.1.3 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-42574HIGHapko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build rootEPSS 0.5%CVE-2024-25614MEDIUMThere is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the aEPSS 0.5%CVE-2026-40180HIGHZip Slip Path Traversal in quarkus-openapi-generator ApicurioCodegenWrapper classEPSS 0.5%CVE-2025-25155HIGHWordPress Music Sheet Viewer plugin <= 4.1 - Arbitrary File Read vulnerabilityEPSS 0.5%CVE-2023-3330—Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2,EPSS 0.5%CVE-2024-35781MEDIUMWordPress Word Balloon plugin <= 4.21.1 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-93013MEDIUMRAGFlow through 0.27.2 Tenant Import Endpoints Path TraversalEPSS 0.5%CVE-2026-32026HIGHOpenClaw < 2026.2.24 - Arbitrary File Read via Improper Temporary Path Validation in SandboxEPSS 0.5%CVE-2026-15138MEDIUMtumf mcp-text-editor text_editor.py _validate_file_path path traversalEPSS 0.5%CVE-2025-49138MEDIUMHAX CMS vulnerable to Local File Inclusion via saveOutline API Location ParameterEPSS 0.5%CVE-2024-38704MEDIUMWordPress Team Manager plugin <= 2.1.12 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-32030HIGHOpenClaw < 2026.2.19 - Sensitive File Disclosure via stageSandboxMedia Path TraversalEPSS 0.5%CVE-2025-2032MEDIUMChestnutCMS rename renameFile path traversalEPSS 0.5%CVE-2026-59510HIGHAuthenticated Path Traversal in AIL Framework PDF Object Handling Enables Potential Arbitrary File ReadEPSS 0.5%CVE-2026-32567MEDIUMWordPress YML for Yandex Market plugin < 5.3.0 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-39369HIGHWWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLsEPSS 0.5%CVE-2026-56138MEDIUMAuthenticated Path Traversal in AIL framework /objects/item/diff Allows Reading Gzip-Compressed FilesEPSS 0.5%CVE-2025-46486MEDIUMWordPress Nomupay Payment Processing Gateway plugin <= 7.1.7 - Arbitrary File Download VulnerabilityEPSS 0.5%