Fallos del tipo CWE-22

5972 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-14500MEDIUMBulk Order Update for WooCommerce <= 1.6 - Unauthenticated Arbitrary File Read via 'csv_url' ParameterEPSS 0.5%CVE-2025-5385MEDIUMJeeWMS cgformTemplateController.do doAdd path traversalEPSS 0.5%CVE-2025-54819HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:EPSS 0.5%CVE-2025-50178MEDIUMGitForge.jl lacks validation for user provided fieldsEPSS 0.5%CVE-2020-1735MEDIUMA flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then chEPSS 0.5%CVE-2025-47788CRITICALMissing Path Validation Enables Path Traversal in Controller.phpEPSS 0.5%CVE-2023-51366HIGHQTS, QuTS heroEPSS 0.5%CVE-2026-41140LOWPoetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4EPSS 0.5%CVE-2025-49879HIGHWordPress Litho theme <= 3.0 - Arbitrary File Deletion VulnerabilityEPSS 0.5%CVE-2025-66428HIGHAn issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.EPSS 0.5%CVE-2024-57777MEDIUMDirectory Traversal vulnerability in Ianproxy v.0.1 and before allows a remote attacker to obtain sensitive informationEPSS 0.5%CVE-2025-48267HIGHWordPress WP Pipes plugin <= 1.4.2 - Arbitrary File Deletion VulnerabilityEPSS 0.5%CVE-2025-1357MEDIUMSeventh D-Guard HTTP GET Request path traversalEPSS 0.5%CVE-2024-7634MEDIUMNGINX Agent VulnerabilityEPSS 0.5%CVE-2025-24765HIGHWordPress Image Shadow plugin <= 1.1.0 - Arbitrary File Deletion VulnerabilityEPSS 0.5%CVE-2026-56054HIGHWordPress JS Help Desk plugin <= 3.1.1 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-54193HIGHWordPress Fusion Builder plugin <= 3.15.4 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-40727HIGHWordPress Groundhogg plugin <= 4.4 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-95525MEDIUMWordPress WP User Frontend plugin <= 4.3.11 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-59542HIGHWordPress Kali Forms plugin <= 2.4.18 - Arbitrary File Deletion vulnerabilityEPSS 0.5%