CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
714 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 12 of 15
- CVE-2023-47171MEDIUMCVSS 6.5EG 6.52024-01-10
An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.
- CVE-2023-20114MEDIUMCVSS 6.5EG 6.52023-11-01
A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability is due to a lack of inpu…
- CVE-2023-32615MEDIUMCVSS 6.5EG 6.52023-09-05
A file write vulnerability exists in the OAS Engine configuration functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attac…
- CVE-2023-35384MEDIUMCVSS 6.5EG 6.52023-08-08
Windows HTML Platforms Security Feature Bypass Vulnerability
- CVE-2023-35308MEDIUMCVSS 6.5EG 6.52023-07-11
Windows MSHTML Platform Security Feature Bypass Vulnerability
- CVE-2023-29324MEDIUMCVSS 6.5EG 6.52023-05-09
Windows MSHTML Platform Security Feature Bypass Vulnerability
- CVE-2023-30943MEDIUMCVSS 6.5EG 6.52023-05-02
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the sy…
- CVE-2021-4332MEDIUMCVSS 6.5EG 6.52023-03-07
The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info B…
- CVE-2023-0003MEDIUMCVSS 6.5EG 6.52023-02-08
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
- CVE-2022-23536MEDIUMCVSS 6.5EG 6.52022-12-19
Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a result of parsing malici…
- CVE-2022-2638MEDIUMCVSS 6.5EG 6.52022-08-29
The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file from the server
- CVE-2022-32761MEDIUMCVSS 6.5EG 6.52022-08-22
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTT…
- CVE-2022-28710MEDIUMCVSS 6.5EG 6.52022-08-22
An information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to tri…
- CVE-2022-0593MEDIUMCVSS 6.5EG 6.52022-03-14
The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or authorization checks placed in the plugin directory, allowing unauthenticated user to remotely delete the plugin files l…
- CVE-2020-26078MEDIUMCVSS 6.5EG 6.52020-11-18
A vulnerability in the file system of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to overwrite files on an affected system. The vulnerability is due to insufficient file system protections. An attac…
- CVE-2020-2003MEDIUMCVSS 6.5EG 6.52020-05-13
An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system files affecting the integrity of the system or causing denial of service to all PAN-OS servi…
- CVE-2022-20789MEDIUMCVSS 4.9EG 6.52022-04-21
A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to writ…
- CVE-2025-12915MEDIUMCVSS 6.4EG 6.42025-11-08
A vulnerability was found in 70mai X200 up to 20251019. This issue affects some unknown processing of the component Init Script Handler. The manipulation results in file inclusion. The attack requires a local approach. A high complexity le…
- CVE-2025-35053MEDIUMCVSS 6.4EG 6.42025-10-09
Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an authenticated user to read and delete arbitrary files with 'NT AUTHORITY\NetworkService' priv…
- CVE-2026-106559MEDIUMCVSS 6.3EG 6.32026-10-07
Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper input validation in confluence to markdown scaffolder mo…
- CVE-2026-56390MEDIUMCVSS 6.3EG 6.32026-07-29
GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing…
- CVE-2026-13748MEDIUMCVSS 6.3EG 6.32026-06-29
Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file content to be read and transmitted to Snowflake services. An attacker could exploit this by supplying crafted repository or p…
- CVE-2026-10559MEDIUMCVSS 6.3EG 6.32026-06-02
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the file /index.php. Executing a manipulation of the argument page can lead to file inclusion. The attack may be performed…
- CVE-2026-10558MEDIUMCVSS 6.3EG 6.32026-06-02
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument page results in file inclusion. The attack is possible to …
- CVE-2025-2982MEDIUMCVSS 6.3EG 6.32025-03-31
A vulnerability, which was classified as critical, was found in Legrand SMS PowerView 1.x. Affected is an unknown function. The manipulation of the argument redirect leads to file inclusion. It is possible to launch the attack remotely. Th…
- CVE-2025-0211MEDIUMCVSS 6.3EG 6.32025-01-04
A vulnerability was found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/index.php. The manipulation of the argument page leads to file …
- CVE-2024-9275MEDIUMCVSS 6.3EG 6.32024-09-27
A vulnerability was found in jeanmarc77 123solar up to 1.8.4.5. It has been rated as critical. This issue affects some unknown processing of the file /admin/admin_invt2.php. The manipulation of the argument PROTOCOLx leads to file inclusio…
- CVE-2024-7911MEDIUMCVSS 6.3EG 6.32024-08-18
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This affects an unknown part of the file /simple-online-bidding-system/bidding/index.php. The manipulation of the argument pa…
- CVE-2024-7497MEDIUMCVSS 6.3EG 6.32024-08-06
A vulnerability was found in itsourcecode Airline Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument page leads to file inclusion. Th…
- CVE-2024-7496MEDIUMCVSS 6.3EG 6.32024-08-06
A vulnerability has been found in itsourcecode Airline Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument page leads to file inclusion. The at…
- CVE-2024-23317MEDIUMCVSS 6.3EG 6.32024-07-11
External Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local access to the Controller to perform arbitrary code execution. This issue affects: 9.10 prior to vCR9.10.240520a (dis…
- CVE-2019-25618MEDIUMCVSS 6.2EG 6.22026-03-22
AdminExpress 1.2.5 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the System Compare feature. Attackers can paste a large buffer of characters into the …
- CVE-2025-29819MEDIUMCVSS 6.2EG 6.22025-04-08
External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.
- CVE-2020-5296MEDIUMCVSS 6.2EG 6.22020-06-03
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to delete arbitrary local files of an October CMS server. The vulnerability is only exploitable by an aut…
- CVE-2026-17431MEDIUMCVSS 6.1EG 6.12026-08-12
PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for. to_pdf reads the generated PDF back from its path argument, and _style_tag_for…
- CVE-2026-48520MEDIUMCVSS 6.1EG 6.12026-06-16
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code) contains a potential arbitrary file-read vulnerability, depending on the exact flow conf…
- CVE-2026-20175MEDIUMCVSS 6.1EG 6.12026-06-03
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerabil…
- CVE-2025-32802MEDIUMCVSS 6.1EG 6.12025-05-28
Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control so…
- CVE-2025-1056MEDIUMCVSS 6.1EG 6.12025-04-23
Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin user can modify this file to either create files or change the content of files in an admi…
- CVE-2024-25965MEDIUMCVSS 6.1EG 6.12024-05-14
Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to denial of service.
- CVE-2026-54582MEDIUMCVSS 6.0EG 6.02026-09-17
mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/inst…
- CVE-2026-79653MEDIUMCVSS 6.0EG 6.02026-08-27
In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage with config key enable.attachment.store.to.file.system, the attacker can manipulate the filename upon upload and can e…
- CVE-2026-77139MEDIUMCVSS 6.0EG 6.02026-08-25
The extension fails to validate a client-supplied template element key before using it to build file paths for saving and deleting Mask template files. An authenticated backend user with access to the Mask module can supply a key containin…
- CVE-2026-53449MEDIUMCVSS 6.0EG 6.02026-07-10
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI command in coturn takes a filename argument and directly passes it to fopen with no path validation. An authenticated adm…
- CVE-2026-53508MEDIUMCVSS 6.0EG 6.02026-07-07
oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRefsA…
- CVE-2024-23634MEDIUMCVSS 6.0EG 6.02024-03-20
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file renaming vulnerability exists in versions prior to 2.23.5 and 2.24.2 that enables an authenticated administr…
- CVE-2021-34761MEDIUMCVSS 6.0EG 6.02021-10-27
A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credenti…
- CVE-2026-92595MEDIUMCVSS 5.9EG 5.92026-09-16
Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` usin…
- CVE-2026-81347MEDIUMCVSS 5.9EG 5.92026-09-04
The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outs…
- CVE-2026-42597MEDIUMCVSS 5.9EG 5.92026-05-14
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/... from anonymous callers. The default Chromium deny-list intenti…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →