CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
714 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 8 of 15
- CVE-2026-54629HIGHCVSS 7.5EG 7.52026-07-14
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, aut…
- CVE-2026-49145HIGHCVSS 7.5EG 7.52026-07-08
App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The project-source option …
- CVE-2026-6101HIGHCVSS 7.5EG 7.52026-07-07
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() function combined wi…
- CVE-2026-10816HIGHCVSS 7.5EG 7.52026-06-30
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
- CVE-2025-71324HIGHCVSS 7.5EG 7.52026-06-25
Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints. The chatId value is not validated and is passed to streamStora…
- CVE-2026-45088HIGHCVSS 7.5EG 7.52026-05-27
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the custom-payload-file field in model.Options is JSON-tagged and deserialized directly from the a…
- CVE-2026-29962HIGHCVSS 7.5EG 7.52026-05-18
HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controlled parameters that directly affect file …
- CVE-2026-43891HIGHCVSS 7.5EG 7.52026-05-12
changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by trusting attacker-controlled snapshot paths restored from backup files. The vulnerable flow starts in the backup resto…
- CVE-2026-35465HIGHCVSS 7.5EG 7.52026-04-18
SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Server can achieve code execution on the C…
- CVE-2026-33476HIGHCVSS 7.5EG 7.52026-03-20
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under `/appearance/*filepath.` Due to improper path sanitization, attackers can perform directory …
- CVE-2026-32949HIGHCVSS 7.5EG 7.52026-03-20
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to retrieve arbitrary system and application fil…
- CVE-2019-25472HIGHCVSS 7.5EG 7.52026-03-11
IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with…
- CVE-2026-29611HIGHCVSS 7.5EG 7.52026-03-05
OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be installed and enabled) media path handling that allows attackers to read arbitrary files from the local filesystem. The sen…
- CVE-2026-26202HIGHCVSS 7.5EG 7.52026-02-19
Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from the server by supplying a local file path (e.g. `/etc/passwd`) as a font data chunk in the…
- CVE-2026-1669HIGHCVSS 7.5EG 7.52026-02-11
Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras mo…
- CVE-2021-47746HIGHCVSS 7.5EG 7.52026-01-21
NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests…
- CVE-2025-68428HIGHCVSS 7.5EG 7.52026-01-05
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsaniti…
- CVE-2025-68155HIGHCVSS 7.5EG 7.52025-12-16
@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development mode. An a…
- CVE-2025-64739HIGHCVSS 7.5EG 7.52025-11-13
External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access.
- CVE-2025-11451HIGHCVSS 7.5EG 7.52025-11-11
The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads in all versions up to, and including, 5.4.3 via the '/wp-json/wp/v2/aal_ajax_unit_loading' RST API endpoint. This make…
- CVE-2025-8422HIGHCVSS 7.5EG 7.52025-09-11
The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.7.6.7 via the send_email() function. This makes it possible for unauthenticated attackers…
- CVE-2025-59049HIGHCVSS 7.5EG 7.52025-09-10
Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file serving follows the same approach presented in the documentation page, where the server filename is generated via templating…
- CVE-2025-48783HIGHCVSS 7.5EG 7.52025-06-06
An external control of file name or path vulnerability in the delete file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to delete partial files by specifying arbitrary fil…
- CVE-2025-48781HIGHCVSS 7.5EG 7.52025-06-06
An external control of file name or path vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to obtain partial files by specifying arbitrary f…
- CVE-2025-3419HIGHCVSS 7.5EG 7.52025-05-08
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauth…
- CVE-2025-3103HIGHCVSS 7.5EG 7.52025-04-19
The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress is vulnerable to arbitrary file read due to insufficient file path validation in the 'history.php' file in all versions up t…
- CVE-2025-3431HIGHCVSS 7.5EG 7.52025-04-08
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 via the 'dzsap_download' action. This makes it possible for unauthenticated att…
- CVE-2024-8524HIGHCVSS 7.5EG 7.52025-03-20
A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint.
- CVE-2024-12036HIGHCVSS 7.5EG 7.52025-03-07
The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via the get_widget_settings_json() function. This makes it possible for authenticated attackers, with subscriber-level acc…
- CVE-2024-51961HIGHCVSS 7.5EG 7.52025-03-03
There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal files fr…
- CVE-2024-38029HIGHCVSS 7.5EG 7.52024-10-08
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
- CVE-2024-38040HIGHCVSS 7.5EG 7.52024-10-04
There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a URL that could potentially disclose sensitive configuration information by reading internal…
- CVE-2024-5334HIGHCVSS 7.5EG 7.52024-06-27
A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handling of the 'snapshot_path' parameter in the '/api/get-browser-snapshot' endpoint. An attacke…
- CVE-2024-30265HIGHCVSS 7.5EG 7.52024-04-03
Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voilà dashboard se…
- CVE-2024-1603HIGHCVSS 7.5EG 7.52024-03-23
paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file.
- CVE-2023-49738HIGHCVSS 7.5EG 7.52024-01-10
An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.
- CVE-2023-43074HIGHCVSS 7.5EG 7.52023-10-23
Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server.
- CVE-2022-42893HIGHCVSS 7.5EG 7.52022-11-17
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder acc…
- CVE-2022-42891HIGHCVSS 7.5EG 7.52022-11-17
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder acc…
- CVE-2022-42734HIGHCVSS 7.5EG 7.52022-11-17
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder acc…
- CVE-2022-42733HIGHCVSS 7.5EG 7.52022-11-17
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any f…
- CVE-2022-42732HIGHCVSS 7.5EG 7.52022-11-17
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any f…
- CVE-2021-3845HIGHCVSS 7.5EG 7.52022-01-04
ws-scrcpy is vulnerable to External Control of File Name or Path
- CVE-2019-3681HIGHCVSS 7.5EG 7.52020-06-29
A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE Linux Enterprise Software Development Kit 12-SP4; openSUSE L…
- CVE-2018-14820HIGHCVSS 7.5EG 7.52018-10-23
Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, which may allow an arbitrary file deletion when processing.
- CVE-2018-7495HIGHCVSS 7.5EG 7.52018-05-15
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an external con…
- CVE-2026-65802HIGHCVSS 7.4EG 7.42026-08-03
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
- CVE-2026-10303HIGHCVSS 7.4EG 7.42026-06-16
In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated against RFC 8555 before being used in challenge-file handling, allowing a maliciously crafted token to influence local pa…
- CVE-2026-41107HIGHCVSS 7.4EG 7.42026-05-12
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
- CVE-2026-79692HIGHCVSS 7.3EG 7.32026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an External Control of File Name or Path vulnerability. An unauthenticated attacker with remote access could potentiall…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →