CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
714 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 4 of 15
- CVE-2021-47871HIGHCVSS 8.8EG 8.82026-01-21
Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write files to arbitrary locations using the API index.php endpoint. Attackers can exploit the v-make-tmp-file command to writ…
- CVE-2025-66449HIGHCVSS 8.8EG 8.82025-12-16
ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on the system, overwriting binaries and allowing code execution. The upload function …
- CVE-2025-12529HIGHCVSS 8.8EG 8.82025-12-02
The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteOrdersFiles() function in all versions up to, and including, 3.6.3. This makes it possible for …
- CVE-2025-58158HIGHCVSS 8.8EG 8.82025-08-29
Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Developer Environments, and Artifact Registries. Prior to version 3.3.0, Open Source Harness git LFS server (Gitness) exposes a…
- CVE-2025-29866HIGHCVSS 8.8EG 8.82025-08-07
: External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This issue affects X-Free Uploader: from 1.0.1.0084 before 1.0.1.0085, from 2.0.1.0034 before 2.0.1.0035.
- CVE-2025-6463HIGHCVSS 8.8EG 8.82025-07-02
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'entry_delete_upload_files' function in all versions up…
- CVE-2024-57394HIGHCVSS 8.8EG 8.82025-04-21
The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege esca…
- CVE-2024-12066HIGHCVSS 8.8EG 8.82024-12-21
The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the smsa_delete_label() function in all versions up to, and including, 2.3. This makes it possible for au…
- CVE-2024-6714HIGHCVSS 8.8EG 8.82024-07-23
An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.
- CVE-2024-6467HIGHCVSS 8.8EG 8.82024-07-17
The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to Arbitrary File Read to Arbitrary File Creation in all versions up to, and including, 1.1.5 via the 'bookingpress_sa…
- CVE-2024-39904HIGHCVSS 8.8EG 8.82024-07-11
VNote is a note-taking platform. Prior to 3.18.1, a code execution vulnerability existed in VNote, which allowed an attacker to execute arbitrary programs on the victim's system. A crafted URI can be used in a note to perform this attack u…
- CVE-2024-28826HIGHCVSS 8.8EG 8.82024-05-29
Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local fil…
- CVE-2024-0265HIGHCVSS 8.8EG 8.82024-01-07
A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component GET Parameter Handler. The manipulation of the argumen…
- CVE-2023-6618HIGHCVSS 8.8EG 8.82023-12-08
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page …
- CVE-2023-40194HIGHCVSS 8.8EG 8.82023-11-27
An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace characters. A specially crafted malicious file can create files at arbitrary locations, w…
- CVE-2023-39542HIGHCVSS 8.8EG 8.82023-11-27
A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can create arbitrary files, which can lead to remote code execution. An attacker needs to trick the user in…
- CVE-2023-35985HIGHCVSS 8.8EG 8.82023-11-27
An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to properly validate a dangerous extension. A specially crafted malicious file can create files at arbitra…
- CVE-2023-36764HIGHCVSS 8.8EG 8.82023-09-12
Microsoft SharePoint Server Elevation of Privilege Vulnerability
- CVE-2023-3256HIGHCVSS 8.8EG 8.82023-06-22
Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.
- CVE-2022-34669HIGHCVSS 8.8EG 8.82022-12-30
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modify system files or other files that are critical to the application, which may lead to code executi…
- CVE-2022-31739HIGHCVSS 8.8EG 8.82022-12-22
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>*This bug only affects Fir…
- CVE-2021-3626HIGHCVSS 8.8EG 8.82021-10-01
The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation.
- CVE-2020-25161HIGHCVSS 8.8EG 8.82021-02-23
The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator.
- CVE-2022-2431HIGHCVSS 8.1EG 8.82022-09-06
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/P…
- CVE-2026-16987HIGHCVSS 7.8EG 8.82026-08-13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.
- CVE-2026-19253HIGHCVSS 8.7EG 8.72026-10-01
The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated us…
- CVE-2026-54675HIGHCVSS 8.7EG 8.72026-09-28
FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, a critical vulnerability exists in the sound language upload and conversion functionality that allows an authenticated attacker to perform arbitrary file writes, leadi…
- CVE-2026-87815HIGHCVSS 8.7EG 8.72026-09-09
SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbitra…
- CVE-2026-77693HIGHCVSS 8.7EG 8.72026-08-26
The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file deletion, nor does it restrict which path may be deleted, allowing users with the Shop Manager role and above to delete…
- CVE-2026-62865HIGHCVSS 8.7EG 8.72026-08-25
Typebot is an open-source chatbot builder. In self-hosted versions prior to 3.18.0, the server-side Send Email integration block allows arbitrary reading of local files on the server. The block builds Nodemailer attachments from a typebot …
- CVE-2026-15724HIGHCVSS 8.7EG 8.72026-07-21
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary…
- CVE-2020-36878HIGHCVSS 8.7EG 8.72025-12-05
ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can ex…
- CVE-2025-49588HIGHCVSS 8.7EG 8.72025-07-02
Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In version 2.10.2, the server accepts links of format file:///etc/passwd and doesn't do any validation before sending them t…
- CVE-2023-3643HIGHCVSS 7.3EG 8.72023-07-12
A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to i…
- CVE-2026-73171HIGHCVSS 8.6EG 8.62026-09-16
Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite ar…
- CVE-2026-72742HIGHCVSS 8.6EG 8.62026-08-11
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the url…
- CVE-2026-61462HIGHCVSS 8.6EG 8.62026-07-13
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to esc…
- CVE-2026-11527HIGHCVSS 8.6EG 8.62026-06-14
Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle. Config::IniFiles::_make_filehandle opens a filename argument with Perl's 2-arg …
- CVE-2026-47358HIGHCVSS 8.6EG 8.62026-05-19
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFormation templates, i…
- CVE-2026-47357HIGHCVSS 8.6EG 8.62026-05-19
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unaut…
- CVE-2026-30284HIGHCVSS 8.6EG 8.62026-03-31
An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
- CVE-2025-4674HIGHCVSS 8.6EG 8.62025-07-29
The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. …
- CVE-2025-48385HIGHCVSS 8.6EG 8.62025-07-08
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When cloning a repository Git knows to optionally fetch a bundle adverti…
- CVE-2026-104805HIGHCVSS 8.5EG 8.52026-10-05
DigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup repository to introduce arbitrary files into the system during restoration. The specific …
- CVE-2026-10739HIGHCVSS 8.5EG 8.52026-09-30
Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe.
- CVE-2026-86741HIGHCVSS 8.5EG 8.52026-09-09
Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in checkout confirmation emails. Attackers with low-privilege permissions can inject markdown image syntax or raw HTML img tags pointing to lo…
- CVE-2026-8920HIGHCVSS 8.5EG 8.52026-07-15
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file …
- CVE-2026-8921HIGHCVSS 8.5EG 8.52026-07-03
External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' secti…
- CVE-2026-43989HIGHCVSS 8.5EG 8.52026-05-12
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a filesystem path from the agent and uploaded whatever bytes the path resolved to, with no validation of location, symli…
- CVE-2026-28442HIGHCVSS 8.5EG 8.52026-03-05
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, users are restricted from deleting internal system files or folders through the application interface. However, when int…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →