CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
594 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 8 of 12
- CVE-2026-14551HIGHCVSS 8.8EG 8.82026-07-22
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), runnin…
- CVE-2026-15307HIGHCVSS 8.8EG 8.82026-08-04
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value…
- CVE-2026-15382MEDIUMCVSS 6.5EG 6.52026-07-30
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete al…
- CVE-2026-15540MEDIUMCVSS 4.3EG 4.32026-07-13
A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page…
- CVE-2026-15724HIGHCVSS 8.7EG 8.72026-07-21
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary…
- CVE-2026-15736HIGHCVSS 8.3EG 8.32026-07-14
Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could allow SQL injection through attacker-controlled input keys. …
- CVE-2026-15921LOWCVSS 3.1EG 3.12026-07-15
Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.1 through 0.40.5, `nvm ls-remote` (and other commands that refresh remote LTS aliases, such as `nvm install --lts`) par…
- CVE-2026-16054CRITICALCVSS 9.1EG 9.12026-08-06
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attacker…
- CVE-2026-16137HIGHCVSS 7.2EG 7.22026-08-17
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writ…
- CVE-2026-16139HIGHCVSS 7.2EG 7.22026-08-17
In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside …
- CVE-2026-1669HIGHCVSS 7.5EG 7.52026-02-11
Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras mo…
- CVE-2026-16898HIGHCVSS 7.8EG 7.82026-08-13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
- CVE-2026-16926CRITICALCVSS 9.1EG 9.12026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.
- CVE-2026-16987HIGHCVSS 7.8EG 8.82026-08-13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.
- CVE-2026-17014MEDIUMCVSS 5.3EG 5.32026-08-09
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it store…
- CVE-2026-17184CRITICALCVSS 9.8EG 9.82026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
- CVE-2026-17431MEDIUMCVSS 6.1EG 6.12026-08-12
PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for. to_pdf reads the generated PDF back from its path argument, and _style_tag_for…
- CVE-2026-17482CRITICALCVSS 9.8EG 9.82026-08-13
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
- CVE-2026-18048HIGHCVSS 7.5EG 7.52026-08-12
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public endpoint actions, and performs no authorisation check on it, allowing unauthenticated att…
- CVE-2026-18127HIGHCVSS 7.7EG 7.72026-08-11
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
- CVE-2026-18751MEDIUMCVSS 5.2EG 5.22026-08-18
External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.
- CVE-2026-18806HIGHCVSS 7.1EG 7.12026-08-04
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 0.9.0.
- CVE-2026-19009HIGHCVSS 7.3EG 7.32026-08-06
A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core/src/response.ts of the component Message API Endpoint. This manipulation causes file inclusion. The attack can be init…
- CVE-2026-19011MEDIUMCVSS 5.3EG 5.32026-08-06
A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packages/server/src/routes/agents.ts. Performing a manipulation results in file inclusion. The attack may be initiated remot…
- CVE-2026-19353MEDIUMCVSS 5.0EG 5.02026-08-09
A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be…
- CVE-2026-20175MEDIUMCVSS 6.1EG 6.12026-06-03
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerabil…
- CVE-2026-20358CRITICALCVSS 10.0EG 10.02026-08-19
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address…
- CVE-2026-20872MEDIUMCVSS 6.5EG 6.52026-01-13
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-20925MEDIUMCVSS 6.5EG 6.52026-01-13
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-20931HIGHCVSS 8.0EG 8.02026-01-13
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
- CVE-2026-21249LOWCVSS 3.3EG 3.32026-02-10
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
- CVE-2026-22783HIGHCVSS 8.1EG 8.12026-01-12
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system has a vulnerability where mass assignment of the file_local_…
- CVE-2026-2351MEDIUMCVSS 6.5EG 6.52026-03-21
The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 via the callback_get_text_from_url() function. This makes it possible for authenticated attackers, with Subscriber-level…
- CVE-2026-23521MEDIUMCVSS 6.5EG 6.52026-02-23
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or edit devices can set a device `uniqueId` to an absolute path. When uploading a device image,…
- CVE-2026-23529HIGHCVSS 7.7EG 7.72026-01-16
Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to 2.11.0, there is an arbitrary file read in Google BigQuery Sink connector. Aiven's Google BigQuery Kafka Connect Sink …
- CVE-2026-23835MEDIUMCVSS 5.7EG 5.72026-01-30
LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in `Knowledge Base > File Upload` does not validate the integrity of the upload request, allowing users to intercept and modify the req…
- CVE-2026-23898HIGHCVSS 7.2EG 7.22026-04-01
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
- CVE-2026-24287HIGHCVSS 7.8EG 7.82026-03-10
External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-24708HIGHCVSS 8.2EG 8.22026-02-18
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to …
- CVE-2026-25573HIGHCVSS 7.8EG 7.82026-03-10
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially re…
- CVE-2026-25605HIGHCVSS 7.1EG 7.12026-03-10
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affecte…
- CVE-2026-25628HIGHCVSS 8.8EG 8.82026-02-06
Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_disk.log_file path. Minimal privileges are requi…
- CVE-2026-25636HIGHCVSS 7.8EG 7.82026-02-06
calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion, Calibre re…
- CVE-2026-25964MEDIUMCVSS 4.9EG 4.92026-02-13
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, a Path Traversal vulnerability in the RecipeImport workflow of Tandoor Recipes allows authenticated users with import perm…
- CVE-2026-2604MEDIUMCVSS 5.6EG 5.62026-06-17
A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored w…
- CVE-2026-26157HIGHCVSS 7.0EG 7.02026-02-11
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended direct…
- CVE-2026-26158HIGHCVSS 7.0EG 7.02026-02-11
A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is e…
- CVE-2026-26202HIGHCVSS 7.5EG 7.52026-02-19
Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from the server by supplying a local file path (e.g. `/etc/passwd`) as a font data chunk in the…
- CVE-2026-26228MEDIUMCVSS 4.9EG 4.92026-02-26
VideoLAN VLC for Android prior to version 3.7.0 contains a path traversal vulnerability in the Remote Access Server routing for the authenticated endpoint GET /download. The file query parameter is concatenated into a filesystem path under…
- CVE-2026-26359HIGHCVSS 8.8EG 8.82026-02-19
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the ability to overwrite…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →