CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
714 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 14 of 15
- CVE-2026-18751MEDIUMCVSS 5.2EG 5.22026-08-18
External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.
- CVE-2026-103511MEDIUMCVSS 5.1EG 5.12026-10-05
Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension installation feature. An attacker with super-user or service-token privileges can write files with arbitrary content to the P4 Search installatio…
- CVE-2026-53648MEDIUMCVSS 5.1EG 5.12026-07-06
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a deterministic filename-derived path. When an administrator uploads a file for a downloadable pro…
- CVE-2026-19353MEDIUMCVSS 5.0EG 5.02026-08-09
A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be…
- CVE-2026-105676MEDIUMCVSS 4.9EG 4.92026-10-05
Ghost is a Node.js content management system. From 1.20.0 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to read JSON files outside of the active theme's directory, potential…
- CVE-2026-59819MEDIUMCVSS 4.9EG 4.92026-07-08
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, all…
- CVE-2026-41412MEDIUMCVSS 4.9EG 4.92026-06-02
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, the alf.io extension sandbox injects a fully-functional HTTP client (`simpleHttpClient`) into every exte…
- CVE-2026-26228MEDIUMCVSS 4.9EG 4.92026-02-26
VideoLAN VLC for Android prior to version 3.7.0 contains a path traversal vulnerability in the Remote Access Server routing for the authenticated endpoint GET /download. The file query parameter is concatenated into a filesystem path under…
- CVE-2026-25964MEDIUMCVSS 4.9EG 4.92026-02-13
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, a Path Traversal vulnerability in the RecipeImport workflow of Tandoor Recipes allows authenticated users with import perm…
- CVE-2025-54162MEDIUMCVSS 4.9EG 4.92026-02-11
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have alrea…
- CVE-2025-11973MEDIUMCVSS 4.9EG 4.92025-11-21
The 简数采集器 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.6.3 via the __kds_flag functionality that imports featured images. This makes it possible for authenticated attackers, wi…
- CVE-2025-12137MEDIUMCVSS 4.9EG 4.92025-11-01
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.14.16. This is due to the plugin's REST API endpoint accepting arbitrary a…
- CVE-2024-12875MEDIUMCVSS 4.9EG 4.92024-12-21
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.2 via the file download functionality. This makes it possible…
- CVE-2023-5816MEDIUMCVSS 4.9EG 4.92024-10-30
The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and including, 1.4.5. This is due to the fact that the plugin does not restrict accessing files to those outside of the WordPres…
- CVE-2024-22178MEDIUMCVSS 4.9EG 4.92024-04-03
A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to arbitrary file creation or overw…
- CVE-2024-21870MEDIUMCVSS 4.9EG 4.92024-04-03
A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An …
- CVE-2023-46851MEDIUMCVSS 4.9EG 4.92023-11-07
Allura Discussion and Allura Forum importing does not restrict URL values specified in attachments. Project administrators can run these imports, which could cause Allura to read local files and expose them. Exposing internal files then …
- CVE-2022-0246MEDIUMCVSS 4.9EG 4.92022-04-11
The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings of the plugin by uploading a zip file. After the uploading…
- CVE-2021-24966MEDIUMCVSS 4.9EG 4.92022-03-14
The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder
- CVE-2025-53363MEDIUMCVSS 4.8EG 4.82025-08-22
dpanel is an open source server management panel written in Go. In versions 1.2.0 through 1.7.2, dpanel allows authenticated users to read arbitrary files from the server via the /api/app/compose/get-from-uri API endpoint. The vulnerabilit…
- CVE-2024-0728MEDIUMCVSS 4.7EG 4.72024-01-19
A vulnerability classified as problematic was found in ForU CMS up to 2020-06-23. Affected by this vulnerability is an unknown functionality of the file channel.php. The manipulation of the argument c_cmodel leads to file inclusion. The at…
- CVE-2026-57916MEDIUMCVSS 4.6EG 4.62026-07-27
proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it t…
- CVE-2026-49836MEDIUMCVSS 4.6EG 4.62026-07-09
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled an…
- CVE-2026-108591MEDIUMCVSS 4.4EG 4.42026-10-10
InnoShop 0.9.2 contains a local file disclosure vulnerability that allows authenticated administrators with files_create permission to read server files by abusing the AI Core MCP file_upload tool's source argument. Attackers can supply fi…
- CVE-2026-106494MEDIUMCVSS 4.4EG 4.42026-10-06
Backstage is an open framework for building developer portals. Prior to 0.17.8, the @backstage/backend-defaults package is affected by improper input validation in cloud storage url readers. An attacker with write access to a cloud storage…
- CVE-2026-91072MEDIUMCVSS 4.4EG 4.42026-09-30
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing Web…
- CVE-2026-63225MEDIUMCVSS 4.4EG 4.42026-09-16
Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSamples …
- CVE-2025-27137MEDIUMCVSS 4.4EG 4.42025-02-24
Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track allows users with the `SYSTEM_CONFIGURATION` permission to customize notification templa…
- CVE-2024-39303MEDIUMCVSS 4.4EG 4.42024-07-01
Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ZIP file. Th…
- CVE-2024-27175MEDIUMCVSS 4.4EG 4.42024-06-14
Remote Command program allows an attacker to read any file using a Local File Inclusion vulnerability. An attacker can read any file on the printer. As for the affected products/models/versions, see the reference URL.
- CVE-2020-36772MEDIUMCVSS 4.4EG 4.42024-01-22
CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to read and write arbitrary files of certain file formats outside the CageFS environment.
- CVE-2023-20234MEDIUMCVSS 4.4EG 4.42023-08-23
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesystem of an affected device, including system files. The vulnerability occurs because ther…
- CVE-2023-0008MEDIUMCVSS 4.4EG 4.42023-05-10
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.
- CVE-2021-1306MEDIUMCVSS 4.4EG 4.42021-05-22
A vulnerability in the restricted shell of Cisco Evolved Programmable Network (EPN) Manager, Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to identify directories and writ…
- CVE-2026-105748MEDIUMCVSS 4.3EG 4.32026-10-05
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.16.0 until 2.131.0, the InputFormat.JSON_DOCLING backend in docling/backend/json/docling_json_backend.py …
- CVE-2026-86995MEDIUMCVSS 4.3EG 4.32026-09-08
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration withou…
- CVE-2026-15540MEDIUMCVSS 4.3EG 4.32026-07-13
A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page…
- CVE-2026-40421MEDIUMCVSS 4.3EG 4.32026-05-12
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- CVE-2025-65799MEDIUMCVSS 4.3EG 4.32025-12-08
A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.
- CVE-2024-12357MEDIUMCVSS 4.3EG 4.32024-12-09
A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument page leads to …
- CVE-2024-2155MEDIUMCVSS 4.3EG 4.32024-03-04
A vulnerability was found in SourceCodester Best POS Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file index.php. The manipulation of the argument page leads to file inclusion. The …
- CVE-2022-0377MEDIUMCVSS 4.3EG 4.32022-02-28
Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. After this process the user crops and saves the image. Then a "POST" request that contains user supplied name of the ima…
- CVE-2023-26282MEDIUMCVSS 4.2EG 4.22024-03-05
IBM Watson CP4D Data Stores 4.6.0 through 4.6.3 could allow a user with physical access and specific knowledge of the system to modify files or data on the system. IBM X-Force ID: 248415.
- CVE-2026-106109MEDIUMCVSS 4.1EG 4.12026-10-06
Quasar Framework is a framework for building high-performance Vue.js user interfaces. From 1.0.0 until 3.3.0, @quasar/app-vite recursively removed the resolved build.distDir before building without rejecting the project root, user home dir…
- CVE-2026-76796MEDIUMCVSS 4.0EG 4.02026-09-15
The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameter without adequate validation, allowing a crafted path to read arbitrary image files from the host filesystem outside…
- CVE-2025-12656LOWCVSS 3.8EG 3.82026-06-05
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the delete_cancel_staging_site() function in all versions up to, a…
- CVE-2025-10306LOWCVSS 3.8EG 3.82025-10-03
The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up to, and including, 1.4.1 via the process_backup_batch() function. This makes it possible for authenticated attacke…
- CVE-2025-0124LOWCVSS 3.8EG 3.82025-04-11
An authenticated file deletion vulnerability in the Palo Alto Networks PAN-OS® software enables an authenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes …
- CVE-2025-49760LOWCVSS 3.5EG 3.52025-07-08
External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network.
- CVE-2026-93987LOWCVSS 3.4EG 3.42026-09-19
rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name) from the att…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →