CWE-73— External Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.— MITRE CWE catalog
662 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-73page 8 of 14
- CVE-2026-14480CRITICALCVSS 9.9EG 9.92026-07-10
OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly into the Programs.File database …
- CVE-2026-14551HIGHCVSS 8.8EG 8.82026-07-22
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), runnin…
- CVE-2026-15307HIGHCVSS 8.8EG 8.82026-08-04
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value…
- CVE-2026-15382MEDIUMCVSS 6.5EG 6.52026-07-30
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete al…
- CVE-2026-15540MEDIUMCVSS 4.3EG 4.32026-07-13
A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page…
- CVE-2026-15724HIGHCVSS 8.7EG 8.72026-07-21
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary…
- CVE-2026-15736HIGHCVSS 8.3EG 8.32026-07-14
Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could allow SQL injection through attacker-controlled input keys. …
- CVE-2026-15921LOWCVSS 3.1EG 3.12026-07-15
Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.1 through 0.40.5, `nvm ls-remote` (and other commands that refresh remote LTS aliases, such as `nvm install --lts`) par…
- CVE-2026-16054CRITICALCVSS 9.1EG 9.12026-08-06
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attacker…
- CVE-2026-16137HIGHCVSS 7.2EG 7.22026-08-17
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writ…
- CVE-2026-16139HIGHCVSS 7.2EG 7.22026-08-17
In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside …
- CVE-2026-16338CRITICALCVSS 9.9EG 9.92026-09-14
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.
- CVE-2026-16444HIGHCVSS 7.5EG 7.52026-08-26
Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or…
- CVE-2026-1669HIGHCVSS 7.5EG 7.52026-02-11
Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras mo…
- CVE-2026-16898HIGHCVSS 7.8EG 7.82026-08-13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.
- CVE-2026-16926CRITICALCVSS 9.1EG 9.12026-08-20
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special elements in input.
- CVE-2026-16987HIGHCVSS 7.8EG 8.82026-08-13
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.
- CVE-2026-17014MEDIUMCVSS 5.3EG 5.32026-08-09
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it store…
- CVE-2026-17184CRITICALCVSS 9.8EG 9.82026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
- CVE-2026-17431MEDIUMCVSS 6.1EG 6.12026-08-12
PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for. to_pdf reads the generated PDF back from its path argument, and _style_tag_for…
- CVE-2026-17482CRITICALCVSS 9.8EG 9.82026-08-13
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
- CVE-2026-18048HIGHCVSS 7.5EG 7.52026-08-12
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public endpoint actions, and performs no authorisation check on it, allowing unauthenticated att…
- CVE-2026-18127HIGHCVSS 7.7EG 7.72026-08-11
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
- CVE-2026-18751MEDIUMCVSS 5.2EG 5.22026-08-18
External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.
- CVE-2026-18806HIGHCVSS 7.1EG 7.12026-08-04
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 0.9.0.
- CVE-2026-19009HIGHCVSS 7.3EG 7.32026-08-06
A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core/src/response.ts of the component Message API Endpoint. This manipulation causes file inclusion. The attack can be init…
- CVE-2026-19011MEDIUMCVSS 5.3EG 5.32026-08-06
A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packages/server/src/routes/agents.ts. Performing a manipulation results in file inclusion. The attack may be initiated remot…
- CVE-2026-19084HIGHCVSS 7.5EG 7.52026-08-28
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a publi…
- CVE-2026-19353MEDIUMCVSS 5.0EG 5.02026-08-09
A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be…
- CVE-2026-19860MEDIUMCVSS 5.5EG 5.52026-09-19
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion func…
- CVE-2026-19913HIGHCVSS 7.5EG 7.52026-08-25
The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and acce…
- CVE-2026-20175MEDIUMCVSS 6.1EG 6.12026-06-03
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerabil…
- CVE-2026-20358CRITICALCVSS 10.0EG 10.02026-08-19
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address…
- CVE-2026-20872MEDIUMCVSS 6.5EG 6.52026-01-13
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-20925MEDIUMCVSS 6.5EG 6.52026-01-13
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- CVE-2026-20931HIGHCVSS 8.0EG 8.02026-01-13
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
- CVE-2026-21249LOWCVSS 3.3EG 3.32026-02-10
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
- CVE-2026-22783HIGHCVSS 8.1EG 8.12026-01-12
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system has a vulnerability where mass assignment of the file_local_…
- CVE-2026-2351MEDIUMCVSS 6.5EG 6.52026-03-21
The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 via the callback_get_text_from_url() function. This makes it possible for authenticated attackers, with Subscriber-level…
- CVE-2026-23521MEDIUMCVSS 6.5EG 6.52026-02-23
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or edit devices can set a device `uniqueId` to an absolute path. When uploading a device image,…
- CVE-2026-23529HIGHCVSS 7.7EG 7.72026-01-16
Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to 2.11.0, there is an arbitrary file read in Google BigQuery Sink connector. Aiven's Google BigQuery Kafka Connect Sink …
- CVE-2026-23835MEDIUMCVSS 5.7EG 5.72026-01-30
LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in `Knowledge Base > File Upload` does not validate the integrity of the upload request, allowing users to intercept and modify the req…
- CVE-2026-23898HIGHCVSS 7.2EG 7.22026-04-01
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
- CVE-2026-24287HIGHCVSS 7.8EG 7.82026-03-10
External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-24708HIGHCVSS 8.2EG 8.22026-02-18
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to …
- CVE-2026-25573HIGHCVSS 7.8EG 7.82026-03-10
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially re…
- CVE-2026-25605HIGHCVSS 7.1EG 7.12026-03-10
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affecte…
- CVE-2026-25628HIGHCVSS 8.8EG 8.82026-02-06
Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_disk.log_file path. Minimal privileges are requi…
- CVE-2026-25636HIGHCVSS 7.8EG 7.82026-02-06
calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion, Calibre re…
- CVE-2026-25964MEDIUMCVSS 4.9EG 4.92026-02-13
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, a Path Traversal vulnerability in the RecipeImport workflow of Tandoor Recipes allows authenticated users with import perm…
Map vulnerabilities like CWE-73 to your infrastructure
EchelonGraph correlates every CVE — across CWE-73 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →