CWE-552— Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.— MITRE CWE catalog
535 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-552page 4 of 11
- CVE-2020-5250HIGHCVSS 7.6EG 7.62020-03-05
In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone else's address. It is the same with CustomerForm, you are able to change the id_customer a…
- CVE-2026-105750HIGHCVSS 7.5EG 7.52026-10-05
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.82.0 until 2.118.1, HTMLBackendOptions(render_page=True) permits file URLs because HTMLDocumentBackend._g…
- CVE-2026-88623HIGHCVSS 7.5EG 7.52026-09-18
NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and fopen() is used to open the URL in binary read-only mode. The content is then written to t…
- CVE-2026-75413HIGHCVSS 7.5EG 7.52026-08-26
DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any file via the parameter targetPath.
- CVE-2026-63490HIGHCVSS 7.5EG 7.52026-08-20
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader wit…
- CVE-2026-54629HIGHCVSS 7.5EG 7.52026-07-14
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, aut…
- CVE-2026-59703HIGHCVSS 7.5EG 7.52026-07-08
repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to read arbitrary local git repositories. The isValidRemoteValue function in src/core/git/gitRemoteParse.ts fails to bloc…
- CVE-2025-66389HIGHCVSS 7.5EG 7.52026-06-22
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.
- CVE-2026-45088HIGHCVSS 7.5EG 7.52026-05-27
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the custom-payload-file field in model.Options is JSON-tagged and deserialized directly from the a…
- CVE-2026-39871HIGHCVSS 7.5EG 7.52026-05-11
A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to observe unprotected user data.
- CVE-2025-69428HIGHCVSS 7.5EG 7.52026-04-27
An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories.
- CVE-2026-34392HIGHCVSS 7.5EG 7.52026-04-08
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, a bug in the static file router can all…
- CVE-2026-34785HIGHCVSS 7.5EG 7.52026-04-02
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes suc…
- CVE-2026-4532HIGHCVSS 7.5EG 7.52026-03-22
A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /food/sql/food.sql of the component Database Backup Handler. The mani…
- CVE-2018-25164HIGHCVSS 7.5EG 7.52026-03-06
EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive files by requesting them directly from the files directory. Attackers can send GET requests to the files directory to …
- CVE-2026-25231HIGHCVSS 7.5EG 7.52026-02-09
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerability due to the lack of access control on the /uploads directory. Files uploaded to this di…
- CVE-2019-25239HIGHCVSS 7.5EG 7.52025-12-24
V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by se…
- CVE-2025-14896HIGHCVSS 7.5EG 7.52025-12-18
due to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker can craft a malicious Vega diagram specification that will allow them to send requests to any URL, …
- CVE-2025-11965HIGHCVSS 7.5EG 7.52025-10-22
In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to hidden files fails to restrict access to hidden directories, allowing unauthorized users to retrieve files within them (…
- CVE-2025-31996HIGHCVSS 7.5EG 7.52025-10-13
HCL Unica Platform is affected by unprotected files due to improper access controls. These files may contain sensitive information such as private or system information that can be exploited by attackers to compromise the application, i…
- CVE-2025-61734HIGHCVSS 7.5EG 7.52025-10-02
Files or Directories Accessible to External Parties vulnerability in Apache Kylin. You are fine as long as the Kylin's system and project admin access is well protected. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users a…
- CVE-2025-58753HIGHCVSS 7.5EG 7.52025-09-09
Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the `shr` global-option). When a share was created for just one file inside a folder, it was possible to access t…
- CVE-2025-25759HIGHCVSS 7.5EG 7.52025-02-27
An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitrary file deletion via a crafted GET request.
- CVE-2024-57452HIGHCVSS 7.5EG 7.52025-02-03
ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file and folder.
- CVE-2024-43660HIGHCVSS 7.5EG 7.52025-01-09
The CGI script <redacted>.sh can be used to download any file on the filesystem. This issue affects Iocharger firmware for AC model chargers beforeversion 24120701. Likelihood: High, but credentials required. Impact: Critical – The sc…
- CVE-2024-52047HIGHCVSS 7.5EG 7.52024-12-31
A widget local file inclusion vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code…
- CVE-2024-10403HIGHCVSS 7.5EG 7.52024-11-21
Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core …
- CVE-2024-49359HIGHCVSS 7.5EG 7.52024-10-24
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in ZimaOS is vulnerable to a directory traver…
- CVE-2024-45276HIGHCVSS 7.5EG 7.52024-10-15
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.
- CVE-2024-7107HIGHCVSS 7.5EG 7.52024-09-26
Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath allows Collect Data from Common Resource Locations. This issue affects CyberMath: before CYBM.240816253.
- CVE-2023-49198HIGHCVSS 7.5EG 7.52024-08-21
Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allowLoadLocalInfile=true&allowUrlInLocalInfile=true&allowLoadLocalInfileInPath=/&maxAllowedPac…
- CVE-2024-7729HIGHCVSS 7.5EG 7.52024-08-14
The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CGI files.
- CVE-2024-38429HIGHCVSS 7.5EG 7.52024-07-30
Matrix Tafnit v8 - CWE-552: Files or Directories Accessible to External Parties
- CVE-2024-6911HIGHCVSS 7.5EG 7.52024-07-22
Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in PerkinElmer ProcessPlus.This issue affects ProcessPlus: through 1.11.6507.0.
- CVE-2024-6421HIGHCVSS 7.5EG 7.52024-07-10
An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service.
- CVE-2024-4836HIGHCVSS 7.5EG 7.52024-07-02
Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by an unauthenticated user. The issue in versions 3.5 - 3.25 was removed in r…
- CVE-2024-2759HIGHCVSS 7.5EG 7.52024-04-04
Improper access control vulnerability in Apaczka plugin for PrestaShop allows information gathering from saved templates without authentication.This issue affects Apaczka plugin for PrestaShop from v1 through v4.
- CVE-2024-2052HIGHCVSS 7.5EG 7.52024-03-18
CWE-552: Files or Directories Accessible to External Parties vulnerability exists that could allow unauthenticated files and logs exfiltration and download of files when an attacker modifies the URL to download to a different location.
- CVE-2024-24161HIGHCVSS 7.5EG 7.52024-02-02
MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.
- CVE-2023-4550HIGHCVSS 7.5EG 7.52024-01-29
Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An unauthenticated or authenticated user can abuse a page of AppBuilder to re…
- CVE-2023-6266HIGHCVSS 7.5EG 7.52024-01-11
The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file validation on the BMI_BACKUP case of the handle_downloading function in all versions up to, and including, 1.3.6. This…
- CVE-2023-6114HIGHCVSS 7.5EG 7.52023-12-26
The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily s…
- CVE-2023-6375HIGHCVSS 7.5EG 7.52023-11-30
Tyler Technologies Court Case Management Plus may store backups in a location that can be accessed by a remote, unauthenticated attacker. Backups may contain sensitive information such as database credentials.
- CVE-2023-26580HIGHCVSS 7.5EG 7.52023-10-25
Unauthenticated arbitrary file read in the IDAttend’s IDWeb application 3.1.013 allows the retrieval of any file present on the web server by unauthenticated attackers.
- CVE-2023-33517HIGHCVSS 7.5EG 7.52023-10-23
carRental 1.0 is vulnerable to Incorrect Access Control (Arbitrary File Read on the Back-end System).
- CVE-2023-5297HIGHCVSS 7.5EG 7.52023-09-29
A vulnerability was found in Xinhu RockOA 2.3.2. It has been classified as problematic. This affects the function start of the file task.php?m=sys|runt&a=beifen. The manipulation leads to exposure of backup file to an unauthorized control …
- CVE-2023-43856HIGHCVSS 7.5EG 7.52023-09-27
Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateController.java.
- CVE-2023-38952HIGHCVSS 7.5EG 7.52023-08-03
Insecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that session ids are not validated for the type of user accessing the application by default. Privilege res…
- CVE-2023-34645HIGHCVSS 7.5EG 7.52023-06-16
jfinal CMS 5.1.0 has an arbitrary file read vulnerability.
- CVE-2023-33568HIGHCVSS 7.5EG 7.52023-06-13
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
Map vulnerabilities like CWE-552 to your infrastructure
EchelonGraph correlates every CVE — across CWE-552 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →