VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (561)

page 1 of 29
  • CVE-2025-33053HigKEVJun 10, 2025
    risk 0.79cvss 8.8epss 0.85

    External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

  • CVE-2022-39952CriFeb 16, 2023
    risk 0.75cvss 9.8epss 1.00

    A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or…

  • CVE-2024-8517CriSep 6, 2024
    risk 0.74cvss 9.8epss 0.95

    SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.

  • CVE-2023-4634CriSep 6, 2023
    risk 0.73cvss 9.8epss 0.83

    The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the…

  • CVE-2020-1631HigKEVMay 4, 2020
    risk 0.70cvss 8.8epss 0.05

    A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform local file inclusion (LFI) or path traversal.…

  • CVE-2018-17246CriDec 20, 2018
    risk 0.70cvss 9.8epss 0.82

    Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing…

  • CVE-2024-46909CriDec 2, 2024
    risk 0.68cvss 9.8epss 0.49

    In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.

  • CVE-2026-39907CriApr 14, 2026
    risk 0.65cvss 10.0epss 0.01

    Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter, allowing remote attackers to trigger SMB connections and leak…

  • CVE-2024-13984CriAug 27, 2025
    risk 0.65cvss epss 0.01

    QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the rptsvr component that allows unauthenticated attackers to upload files to arbitrary locations on the server. The /rptsvr/upload endpoint fails to sanitize the…

  • CVE-2026-52680CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.01

    Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi…

  • CVE-2026-14480CriJul 10, 2026
    risk 0.64cvss 9.9epss 0.00

    OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly into the Programs.File database field and later uses this value as the …

  • CVE-2026-39006CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.

  • CVE-2026-45556CriJun 10, 2026
    risk 0.64cvss 9.9epss 0.00

    Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf//<server_ip>/rule/<rule_id>/save accepts a config_file_name form field that is passed straight through to…

  • CVE-2026-47643CriJun 9, 2026
    risk 0.64cvss 9.8epss 0.01

    External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.

  • CVE-2026-9559CriMay 29, 2026
    risk 0.64cvss 9.9epss 0.01

    A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw in the validation logic allows file paths to escape the intended temporary directories. An authenticated user with campaign import…

  • CVE-2026-30281CriMar 31, 2026
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

  • CVE-2026-30276CriMar 31, 2026
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

  • CVE-2020-37080CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.00

    webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delete arbitrary files. Attackers can exploit the vulnerability by manipulating the 'atttmp1' parameter to specify and delete files on…

  • CVE-2025-54945CriAug 30, 2025
    risk 0.64cvss 9.8epss 0.01

    An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via a malicious file by controlling the destination file path.

  • CVE-2025-43951CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.00

    LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the environment via the objectname request parameter.