VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (681)

page 1 of 35
  • CVE-2025-33053HigKEVJun 10, 2025
    risk 0.79cvss 8.8epss 0.87

    External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

  • CVE-2022-39952CriFeb 16, 2023
    risk 0.75cvss 9.8epss 1.00

    A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or…

  • CVE-2024-8517CriSep 6, 2024
    risk 0.74cvss 9.8epss 0.95

    SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.

  • CVE-2023-4634CriSep 6, 2023
    risk 0.73cvss 9.8epss 0.86

    The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the…

  • CVE-2020-1631HigKEVMay 4, 2020
    risk 0.70cvss 8.8epss 0.05

    A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform local file inclusion (LFI) or path traversal.…

  • CVE-2018-17246CriDec 20, 2018
    risk 0.70cvss 9.8epss 0.82

    Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing…

  • CVE-2024-46909CriDec 2, 2024
    risk 0.68cvss 9.8epss 0.49

    In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.

  • CVE-2026-20358CriAug 19, 2026
    risk 0.65cvss 10.0epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…

  • CVE-2025-71338CriJun 25, 2026
    risk 0.65cvss 10.0epss 0.01

    Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application…

  • CVE-2026-39907CriApr 14, 2026
    risk 0.65cvss 10.0epss 0.01

    Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter, allowing remote attackers to trigger SMB connections and leak…

  • CVE-2024-13984CriAug 27, 2025
    risk 0.65cvss —epss 0.01

    QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the rptsvr component that allows unauthenticated attackers to upload files to arbitrary locations on the server. The /rptsvr/upload endpoint fails to sanitize the…

  • CVE-2026-90817CriSep 20, 2026
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey…

  • CVE-2026-16338CriSep 14, 2026
    risk 0.64cvss 9.9epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.

  • CVE-2026-66302CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

  • CVE-2026-86189CriSep 5, 2026
    risk 0.64cvss 9.8epss 0.01

    WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext…

  • CVE-2026-17184CriAug 14, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.

  • CVE-2026-72842CriAug 13, 2026
    risk 0.64cvss 9.9epss 0.01

    luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape…

  • CVE-2026-72841CriAug 13, 2026
    risk 0.64cvss 9.9epss 0.01

    luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code…

  • CVE-2026-17482CriAug 13, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.

  • CVE-2026-52680CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.01

    Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi…