Weaknesses of type CWE-22

5,970 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-65698MEDIUMVoid 1.3.4 Path Traversal via AI Agent File-Reading ToolsEPSS 0.5%CVE-2026-59542HIGHWordPress Kali Forms plugin <= 2.4.18 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-54193HIGHWordPress Fusion Builder plugin <= 3.15.4 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-56054HIGHWordPress JS Help Desk plugin <= 3.1.1 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-11416HIGHMoviePilot Path Traversal via Cloud Storage Download HandlersEPSS 0.5%CVE-2024-37423HIGHWordPress Newspack Blocks plugin <= 3.0.8 - Contributor+ Arbitrary Directory Deletion vulnerabilityEPSS 0.5%CVE-2026-73752HIGHUnauthenticated Arbitrary File Write Vulnerability Leads to Remote Code Execution in AOS-CXEPSS 0.5%CVE-2026-72814MEDIUMactix-web before 0.6.10 Information Disclosure via FilesEPSS 0.5%CVE-2025-4530MEDIUMfeng_ha_ha/megagao ssm-erp/production_ssm File FileController.java handleFileDownload path traversalEPSS 0.5%CVE-2026-32750MEDIUMSiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notesEPSS 0.5%CVE-2023-33747HIGHCloudPanel v2.2.2 allows attackers to execute a path traversal.EPSS 0.5%CVE-2026-45565HIGHRoxy-WI: EscapedString validator skips its '..' block when stripping (root cause for several path-traversal/RCE vectors)EPSS 0.5%CVE-2026-44973HIGHBilly: Path traversal vulnerabilitiesEPSS 0.5%CVE-2026-81564HIGHJoomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0EPSS 0.5%CVE-2026-66493MEDIUMJoomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.3EPSS 0.5%CVE-2026-48338MEDIUMColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.5%CVE-2025-62449MEDIUMMicrosoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2026-53757MEDIUMEmlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCEEPSS 0.5%CVE-2026-46724MEDIUMPath Traversal in extension "Faceted Search" (ke_search)EPSS 0.5%CVE-2026-75115HIGHJoomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40EPSS 0.5%