CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
714 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 6 of 15
- CVE-2026-77176HIGHCVSS 8.1EG 8.12026-08-20
A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows …
- CVE-2026-61873HIGHCVSS 8.1EG 8.12026-07-15
Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but never re-validated after rendering. Attackers can s…
- CVE-2026-58293HIGHCVSS 8.1EG 8.12026-07-03
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2026-5821HIGHCVSS 8.1EG 8.12026-07-02
The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in p…
- CVE-2026-8095HIGHCVSS 8.1EG 8.12026-06-27
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wp…
- CVE-2026-44019HIGHCVSS 8.1EG 8.12026-06-03
Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.1, docling-core could allow local file:// image references and accepted inline data: conte…
- CVE-2026-35080HIGHCVSS 8.1EG 8.12026-06-03
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
- CVE-2026-35079HIGHCVSS 8.1EG 8.12026-06-03
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
- CVE-2026-35078HIGHCVSS 8.1EG 8.12026-06-03
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
- CVE-2026-35077HIGHCVSS 8.1EG 8.12026-06-03
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
- CVE-2026-35076HIGHCVSS 8.1EG 8.12026-06-03
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
- CVE-2026-46402HIGHCVSS 8.1EG 8.12026-05-27
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing session log paths. An authenticated client…
- CVE-2026-3892HIGHCVSS 8.1EG 8.12026-05-14
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer l…
- CVE-2026-35032HIGHCVSS 8.1EG 8.12026-04-14
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts), where the tuner URL is not validated, allowing local file read via non…
- CVE-2026-34783HIGHCVSS 8.1EG 8.12026-04-06
Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferret's IO::FS::WRITE standard library function allows a malicious website to write arbitrary files to the filesystem of t…
- CVE-2026-34522HIGHCVSS 8.1EG 8.12026-04-02
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path traversal vulnerability …
- CVE-2026-33949HIGHCVSS 8.1EG 8.12026-04-01
Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manip…
- CVE-2026-33645HIGHCVSS 8.1EG 8.12026-03-26
Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerability in Fireshare’s chunked upload endpoint allows an attacker to write arbitrary files outside the intended upload dire…
- CVE-2026-33329HIGHCVSS 8.1EG 8.12026-03-24
FileRise is a self-hosted web file manager / WebDAV server. From version 1.0.1 to before version 3.10.0, the resumableIdentifier parameter in the Resumable.js chunked upload handler (UploadModel::handleUpload()) is concatenated directly in…
- CVE-2026-30240HIGHCVSS 8.1EG 8.12026-03-09
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path traversal vulnerability in the PWA (Progressive Web App) ZIP processing endpoint (POST /api/pwa/process-zip) allows an …
- CVE-2026-28459HIGHCVSS 8.1EG 8.12026-03-05
OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway clients to write transcript data to arbitrary locations on the host filesystem. Attackers can supply a sessionFile path ou…
- CVE-2026-26360HIGHCVSS 8.1EG 8.12026-02-19
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to delete arbitrary files.
- CVE-2025-69621HIGHCVSS 8.1EG 8.12026-02-04
An arbitrary file overwrite vulnerability in the file import process of Comic Book Reader v1.0.95 allows attackers to overwrite critical internal files, potentially leading to arbitrary code execution or exposure of sensitive information.
- CVE-2025-66292HIGHCVSS 8.1EG 8.12026-01-15
DPanel is an open source server management panel written in Go. Prior to 1.9.2, DPanel has an arbitrary file deletion vulnerability in the /api/common/attach/delete interface. Authenticated users can delete arbitrary files on the server vi…
- CVE-2026-22783HIGHCVSS 8.1EG 8.12026-01-12
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system has a vulnerability where mass assignment of the file_local_…
- CVE-2025-13322HIGHCVSS 8.1EG 8.12025-11-21
The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.0. This is due to the `wpag_uploadaudio_callback()` AJAX handler not proper…
- CVE-2025-10494HIGHCVSS 8.1EG 8.12025-10-08
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation when deleting profile pictures in all versions up to, and including, 1.4.89. …
- CVE-2025-10058HIGHCVSS 8.1EG 8.12025-09-17
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_function() function in all versions up to, and including, 7.27. …
- CVE-2025-9048HIGHCVSS 8.1EG 8.12025-08-23
The Wptobe-memberships plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the del_img_ajax_call() function in all versions up to, and including, 3.4.2. This makes it possible for authe…
- CVE-2025-6691HIGHCVSS 8.1EG 8.12025-07-09
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.…
- CVE-2025-3812HIGHCVSS 8.1EG 8.12025-05-17
The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the qcld_openai_delete_training_file() function in all versions up to, and including, 13.6.2. This ma…
- CVE-2025-46762HIGHCVSS 8.1EG 8.12025-05-06
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code. While 1.15.1 introduced a fix to restrict untrusted packages, the default setting of trusted packages st…
- CVE-2024-7626HIGHCVSS 8.1EG 8.12024-09-11
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file movement and reading due to insufficient file path validation in the save_edit_profile_details() functio…
- CVE-2024-20652HIGHCVSS 8.1EG 8.12024-01-09
Windows HTML Platforms Security Feature Bypass Vulnerability
- CVE-2023-1105HIGHCVSS 8.1EG 8.12023-03-01
External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.
- CVE-2026-27825HIGHCVSS 8.0EG 8.02026-03-10
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachment` MCP tool accepts a `download_path` parameter that is written to without any …
- CVE-2026-20931HIGHCVSS 8.0EG 8.02026-01-13
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
- CVE-2025-26646HIGHCVSS 8.0EG 8.02025-05-13
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
- CVE-2020-15264HIGHCVSS 8.0EG 8.02020-10-20
The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH environment variable. However, this directory is writable by normal, unprivileged users. To exploit the vulnerability, place …
- CVE-2021-21343HIGHCVSS 7.5EG 8.02021-03-23
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written ob…
- CVE-2026-91797HIGHCVSS 7.8EG 7.82026-09-23
Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened.
- CVE-2026-62804HIGHCVSS 7.8EG 7.82026-09-08
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-80119HIGHCVSS 7.8EG 7.82026-09-04
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dum…
- CVE-2026-16898HIGHCVSS 7.8EG 7.82026-08-13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
- CVE-2026-50462HIGHCVSS 7.8EG 7.82026-07-14
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-49360HIGHCVSS 7.8EG 7.82026-07-02
Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server deployments that expose the server to an untrusted network without authentication are vulnerable to unauthenticated SQL ex…
- CVE-2026-30905HIGHCVSS 7.8EG 7.82026-05-13
External Control of File Name or Path in the Zoom Workplace VDI Plugin Windows Universal Installer before version 6.6.11 may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2026-41088HIGHCVSS 7.8EG 7.82026-05-12
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-32204HIGHCVSS 7.8EG 7.82026-05-12
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
- CVE-2026-5054HIGHCVSS 7.8EG 7.82026-04-11
NoMachine External Control of File Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →