Falhas do tipo CWE-22

5.979 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-44298MEDIUMKimai: Arbitrary file read in invoice PDF renderer (admin)EPSS 0.4%CVE-2024-57186MEDIUMIn Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-fileEPSS 0.4%CVE-2025-59002HIGHWordPress BM Content Builder Plugin < 3.16.3.3 - Arbitrary File Deletion VulnerabilityEPSS 0.4%CVE-2026-7704MEDIUMAV Stumpfl Pixera Two Media Server Service Port 1338 path traversalEPSS 0.4%CVE-2026-25062MEDIUMOutline Affected an Arbitrary File Read via Path Traversal in JSON ImportEPSS 0.4%CVE-2026-4917MEDIUMIBM Guardium Data Protection is affected by multiple vulnerabilitiesEPSS 0.4%CVE-2026-97163CRITICALJoomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29EPSS 0.4%CVE-2025-6731MEDIUMyzcheng90 X-SpringBoot APK File apk uploadApk path traversalEPSS 0.4%CVE-2026-97161CRITICALJoomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29EPSS 0.4%CVE-2024-53844MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in labsai/eddiEPSS 0.4%CVE-2026-22573MEDIUMAn improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6EPSS 0.4%CVE-2026-6262MEDIUMBetheme <= 28.4 - Authenticated (Contributor+) Arbitrary File Deletion via 'mfn-icon-upload'EPSS 0.4%CVE-2026-54732MEDIUMlibreoffice-convert: path traversal / arbitrary file writeEPSS 0.4%CVE-2026-49991HIGHRustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injectionEPSS 0.4%CVE-2026-27800HIGHZed has Zip Slip Path Traversal in Extension Archive ExtractionEPSS 0.4%CVE-2026-2552MEDIUMZenTao Editor control.php delete path traversalEPSS 0.4%CVE-2026-53554HIGHSQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through Alembic Import ProcessingEPSS 0.4%CVE-2025-54021HIGHWordPress Simple File List plugin <= 6.1.14 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-30973MEDIUMZip Slip arbitrary file write in @appium/support ZIP extractionEPSS 0.4%CVE-2026-94620CRITICALClassroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)EPSS 0.4%