CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
714 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 13 of 15
- CVE-2025-4602MEDIUMCVSS 5.9EG 5.92025-05-24
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions up to, and including, 1.2.5 via the get_file() function. This makes it possible for unauthenticated attackers to read th…
- CVE-2023-47147MEDIUMCVSS 5.9EG 5.92024-03-15
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow an attacker to overwrite a log message under specific conditions. IBM X-Force ID: 270598.
- CVE-2020-8553MEDIUMCVSS 5.9EG 5.92020-07-29
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes…
- CVE-2026-78620MEDIUMCVSS 4.9EG 5.92026-09-08
The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file contents. The path from the event payload is used directly as the write destination, resulting in files bei…
- CVE-2026-104853MEDIUMCVSS 5.8EG 5.82026-10-02
Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx migration planning reads the nx-migrations.migrations value from a target package manifest without validating that it is a contained…
- CVE-2026-41389MEDIUMCVSS 5.8EG 5.82026-04-20
OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side fi…
- CVE-2025-64714MEDIUMCVSS 5.8EG 5.82025-11-13
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, an unauthenticated Local File Inclusion exists in the template-switching feature. If `templateselect…
- CVE-2020-2504MEDIUMCVSS 5.8EG 5.82020-12-24
If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
- CVE-2026-40605MEDIUMCVSS 5.7EG 5.72026-06-04
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configu…
- CVE-2026-42424MEDIUMCVSS 5.7EG 5.72026-04-28
OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channel local file exfiltration. Attackers can exploit this by crafting malicious shared reply MEDIA references to cause anot…
- CVE-2026-23835MEDIUMCVSS 5.7EG 5.72026-01-30
LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in `Knowledge Base > File Upload` does not validate the integrity of the upload request, allowing users to intercept and modify the req…
- CVE-2026-71453MEDIUMCVSS 5.6EG 5.62026-10-01
- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63.
- CVE-2026-81830MEDIUMCVSS 5.6EG 5.62026-09-07
The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation
- CVE-2026-2604MEDIUMCVSS 5.6EG 5.62026-06-17
A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored w…
- CVE-2019-14905MEDIUMCVSS 5.6EG 5.62020-03-31
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malic…
- CVE-2026-19860MEDIUMCVSS 5.5EG 5.52026-09-19
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion func…
- CVE-2026-82194MEDIUMCVSS 5.5EG 5.52026-09-04
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files…
- CVE-2026-12979MEDIUMCVSS 5.5EG 5.52026-07-16
The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the inte…
- CVE-2026-55628MEDIUMCVSS 5.5EG 5.52026-07-01
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to pat…
- CVE-2026-12480MEDIUMCVSS 5.5EG 5.52026-07-01
Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides in the `H5IOStore._verify_dataset()` and `file_editor.py` methods, which fail to …
- CVE-2026-3602MEDIUMCVSS 5.5EG 5.52026-06-30
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accident…
- CVE-2026-53632MEDIUMCVSS 5.5EG 5.52026-06-15
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attemp…
- CVE-2026-46383MEDIUMCVSS 5.5EG 5.52026-05-15
Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by apm install <bundle> on s…
- CVE-2026-41177MEDIUMCVSS 5.5EG 5.52026-04-22
Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerable to Blind Server-Side Request Forgery (SSRF). The application fails to validate the URI …
- CVE-2025-67461MEDIUMCVSS 5.5EG 5.52025-12-10
External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of information via local access.
- CVE-2025-64738MEDIUMCVSS 5.5EG 5.52025-11-13
External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of information via local access.
- CVE-2025-53769MEDIUMCVSS 5.5EG 5.52025-08-12
External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
- CVE-2025-47956MEDIUMCVSS 5.5EG 5.52025-06-10
External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
- CVE-2025-0202MEDIUMCVSS 5.5EG 5.52025-01-04
A vulnerability was found in TCS BaNCS 10. It has been classified as problematic. This affects an unknown part of the file /REPORTS/REPORTS_SHOW_FILE.jsp. The manipulation of the argument FilePath leads to file inclusion. The real existenc…
- CVE-2023-34982MEDIUMCVSS 5.5EG 5.52023-11-15
This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.…
- CVE-2022-34765MEDIUMCVSS 5.5EG 5.52022-07-13
A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (…
- CVE-2026-34967MEDIUMCVSS 5.4EG 5.42026-08-25
Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to…
- CVE-2025-36398MEDIUMCVSS 5.4EG 5.42026-08-19
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.
- CVE-2026-53956MEDIUMCVSS 5.4EG 5.42026-07-09
Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling package …
- CVE-2025-48067MEDIUMCVSS 5.4EG 5.42025-06-10
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows an attacker with the FILE_UPLOAD permission to exfiltrate files from the host tha…
- CVE-2024-2917MEDIUMCVSS 5.4EG 5.42024-03-26
A vulnerability was found in Campcodes House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to f…
- CVE-2026-54584MEDIUMCVSS 5.3EG 5.32026-09-21
mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport in…
- CVE-2026-82637MEDIUMCVSS 5.3EG 5.32026-08-30
browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_path,…
- CVE-2026-17014MEDIUMCVSS 5.3EG 5.32026-08-09
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it store…
- CVE-2026-19011MEDIUMCVSS 5.3EG 5.32026-08-06
A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packages/server/src/routes/agents.ts. Performing a manipulation results in file inclusion. The attack may be initiated remot…
- CVE-2026-42593MEDIUMCVSS 5.3EG 5.32026-05-14
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoffice/convert, chromium/convert/url, chromium/convert/html, and chromium/convert/markdown accept stampSource=pdf + stampE…
- CVE-2026-40086MEDIUMCVSS 5.3EG 5.32026-04-10
Rembg is a tool to remove images background. Prior to 2.0.75, a path traversal vulnerability in the rembg HTTP server allows unauthenticated remote attackers to read arbitrary files from the server's filesystem. By sending a crafted reques…
- CVE-2025-11738MEDIUMCVSS 5.3EG 5.32025-10-18
The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents …
- CVE-2024-22341MEDIUMCVSS 5.3EG 5.32025-02-22
IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7.4, and 4.8.0 through 4.8.7 could allow unauthorized data access from a remote data source object due to improper privil…
- CVE-2024-12267MEDIUMCVSS 5.3EG 5.32025-01-31
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, a…
- CVE-2024-36473MEDIUMCVSS 5.3EG 5.32024-06-10
Trend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack but is limited to local Denial of Service (DoS) and under specific conditions can lead to elevation of privileges.
- CVE-2024-4818MEDIUMCVSS 5.3EG 5.32024-05-14
A vulnerability was found in Campcodes Online Laundry Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php. The manipulation of the argument page leads to file inclusion. Th…
- CVE-2024-2150MEDIUMCVSS 5.3EG 5.32024-03-03
A vulnerability, which was classified as critical, has been found in SourceCodester Insurance Management System 1.0. This issue affects some unknown processing. The manipulation of the argument page leads to file inclusion. The attack may …
- CVE-2023-2152MEDIUMCVSS 5.3EG 5.32023-04-18
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument…
- CVE-2022-2400MEDIUMCVSS 5.3EG 5.32022-07-18
External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →