CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
714 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 11 of 15
- CVE-2026-76217MEDIUMCVSS 6.5EG 6.52026-08-19
GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary …
- CVE-2026-76210MEDIUMCVSS 6.5EG 6.52026-08-19
phpMyFAQ before 4.1.6 does not adequately sanitize HTML in FAQ answers before generating PDFs via TCPDF. An attacker with permission to create or edit FAQ content can embed an <img> tag whose src references a local file under the web root'…
- CVE-2026-73619MEDIUMCVSS 6.5EG 6.52026-08-13
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to read arbitrary files from the fil…
- CVE-2026-64816MEDIUMCVSS 6.5EG 6.52026-07-30
RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking t…
- CVE-2026-15382MEDIUMCVSS 6.5EG 6.52026-07-30
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete al…
- CVE-2026-54108MEDIUMCVSS 6.5EG 6.52026-07-14
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-55699MEDIUMCVSS 6.5EG 6.52026-06-25
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a malicious package was installed globally, later global remove, update, or add-replacement flows…
- CVE-2026-8118MEDIUMCVSS 6.5EG 6.52026-06-19
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in versio…
- CVE-2026-46397MEDIUMCVSS 6.5EG 6.52026-06-05
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local File Inclusion (LFI) vulnerability in the HAXCMS saveOutline endpoint allows a low-privileged user to read arbitrary files…
- CVE-2025-0898MEDIUMCVSS 6.5EG 6.52026-05-27
The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 1.4.7 via the Draw SVG widget. This makes it possible for authenticated attackers, with Contributor-level ac…
- CVE-2026-45139MEDIUMCVSS 6.5EG 6.52026-05-18
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on content-write operations (`saveFile`, `c…
- CVE-2026-45008MEDIUMCVSS 6.5EG 6.52026-05-15
phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INSTANCE_DELETE permission to delete arbitrary directories. Attackers can submit traversal sequences like https://../../../…
- CVE-2026-7633MEDIUMCVSS 6.5EG 6.52026-05-02
A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument FileName leads to file inclusion. The attack may be perfo…
- CVE-2026-39378MEDIUMCVSS 6.5EG 6.52026-04-21
The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versions 6.5 through 7.17.0, when `HTMLExporter.embed_images=True`, nbconvert's markdown renderer allows arbitrary file read…
- CVE-2026-39377MEDIUMCVSS 6.5EG 6.52026-04-21
The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions 6.5 through 7.17.0 allow arbitrary file writes to locations outside the intended output directory when processing note…
- CVE-2026-33027MEDIUMCVSS 6.5EG 6.52026-03-30
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the b…
- CVE-2026-33989MEDIUMCVSS 6.5EG 6.52026-03-27
Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_screenshot` and `mobile_start_screen_recording` to…
- CVE-2026-2351MEDIUMCVSS 6.5EG 6.52026-03-21
The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 via the callback_get_text_from_url() function. This makes it possible for authenticated attackers, with Subscriber-level…
- CVE-2026-23521MEDIUMCVSS 6.5EG 6.52026-02-23
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or edit devices can set a device `uniqueId` to an absolute path. When uploading a device image,…
- CVE-2026-26361MEDIUMCVSS 6.5EG 6.52026-02-19
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
- CVE-2026-20925MEDIUMCVSS 6.5EG 6.52026-01-13
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-20872MEDIUMCVSS 6.5EG 6.52026-01-13
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-14059MEDIUMCVSS 6.5EG 6.52026-01-07
The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.6.1. This is due to missing path validation in the create_template REST API endpoint where user-controlled in…
- CVE-2021-4472MEDIUMCVSS 6.5EG 6.52025-11-26
The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content.
- CVE-2025-13380MEDIUMCVSS 6.5EG 6.52025-11-25
The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1. This is due to insufficient validation of user-supplied file paths in the 'l…
- CVE-2025-8050MEDIUMCVSS 6.5EG 6.52025-10-21
External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could allow a user to access files hosted on the server. This issue affects Flipper: 3.1.2.
- CVE-2025-8048MEDIUMCVSS 6.5EG 6.52025-10-20
External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could allow a user to submit a stored local file path and then download the specified file from the system by requesting the s…
- CVE-2025-59483MEDIUMCVSS 6.5EG 6.52025-10-15
A validation vulnerability exists in an undisclosed URL in the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2025-59244MEDIUMCVSS 6.5EG 6.52025-10-14
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-59185MEDIUMCVSS 6.5EG 6.52025-10-14
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-20269MEDIUMCVSS 6.5EG 6.52025-08-20
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker to retrieve arbitrary files from the un…
- CVE-2025-36506MEDIUMCVSS 6.5EG 6.52025-06-13
External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data.
- CVE-2025-49138MEDIUMCVSS 6.5EG 6.52025-06-09
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticated Local File Inclusion (LFI) vulnerability in the HAXCMS saveOutline endpoint allows a low-privileged user to read arbi…
- CVE-2024-51553MEDIUMCVSS 6.5EG 6.52025-05-22
Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Ser…
- CVE-2025-24996MEDIUMCVSS 6.5EG 6.52025-03-11
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-1730MEDIUMCVSS 6.5EG 6.52025-03-01
The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.0 via the 'simple_download_counter_download_handler'. This makes it possible for authenticated attackers, with Au…
- CVE-2025-25478MEDIUMCVSS 6.5EG 6.52025-02-28
The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the da…
- CVE-2024-47265MEDIUMCVSS 6.5EG 6.52025-02-13
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authen…
- CVE-2025-21377MEDIUMCVSS 6.5EG 6.52025-02-11
NTLM Hash Disclosure Spoofing Vulnerability
- CVE-2025-0630MEDIUMCVSS 6.5EG 6.52025-02-04
Multiple Western Telematic (WTI) products contain a web interface that is vulnerable to a local file inclusion attack (LFI), where any authenticated user has privileged access to files on the device's filesystem.
- CVE-2024-12861MEDIUMCVSS 6.5EG 6.52025-01-30
The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.2.1 via the 'viw2s_view_log' AJAX action. This makes it possible for authenticated attackers, with…
- CVE-2024-7744MEDIUMCVSS 6.5EG 6.52024-08-28
In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Probe System Files, User-Controlled Filena…
- CVE-2024-38165MEDIUMCVSS 6.5EG 6.52024-08-13
Windows Compressed Folder Tampering Vulnerability
- CVE-2024-25975MEDIUMCVSS 6.5EG 6.52024-05-29
The application implements an up- and downvote function which alters a value within a JSON file. The POST parameters are not filtered properly and therefore an arbitrary file can be overwritten. The file can be controlled by an authenticat…
- CVE-2024-0100MEDIUMCVSS 6.5EG 6.52024-05-14
NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user can corrupt system files. A successful exploit of this vulnerability might lead to denial of service and data tampering.
- CVE-2024-33860MEDIUMCVSS 6.5EG 6.52024-05-07
An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within the File System Collector. The content of the file specified can be viewed in the incoming logs.
- CVE-2024-26185MEDIUMCVSS 6.5EG 6.52024-03-12
Windows Compressed Folder Tampering Vulnerability
- CVE-2023-49864MEDIUMCVSS 6.5EG 6.52024-01-10
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerab…
- CVE-2023-49863MEDIUMCVSS 6.5EG 6.52024-01-10
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerab…
- CVE-2023-49862MEDIUMCVSS 6.5EG 6.52024-01-10
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerab…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →