CWE-73
External Control of File Name or Path
Description
The product allows user input to control or influence paths or file names that are used in filesystem operations.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80
CVEs mapped to this weakness (674)
page 18 of 34| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-12513 | Med | 0.44 | 6.8 | 0.00 | Aug 28, 2026 | The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that… | ||
| CVE-2026-49360 | Hig | 0.44 | — | 0.01 | Aug 21, 2026 | Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server deployments that expose the server to an untrusted network without authentication are vulnerable to unauthenticated SQL execution through the query run API. When… | ||
| CVE-2026-65939 | Med | 0.44 | 6.8 | 0.00 | Aug 12, 2026 | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root. | ||
| CVE-2026-25605 | Med | 0.44 | 6.7 | 0.00 | Mar 10, 2026 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affected process has permission to remove,… | ||
| CVE-2026-20925 | Med | 0.44 | 6.5 | 0.18 | Jan 13, 2026 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-20872 | Med | 0.44 | 6.5 | 0.20 | Jan 13, 2026 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-20614 | Med | 0.44 | 6.7 | 0.00 | Nov 11, 2025 | External control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable… | ||
| CVE-2025-26684 | Med | 0.44 | 6.7 | 0.00 | May 13, 2025 | External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-21377 | Med | 0.44 | 6.5 | 0.24 | Feb 11, 2025 | NTLM Hash Disclosure Spoofing Vulnerability | ||
| CVE-2024-12058 | Med | 0.44 | 6.8 | 0.01 | Feb 11, 2025 | External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files. | ||
| CVE-2024-38173 | Med | 0.44 | 6.7 | 0.01 | Aug 13, 2024 | Microsoft Outlook Remote Code Execution Vulnerability | ||
| CVE-2026-50158 | Hig | 0.43 | 7.7 | 0.00 | Sep 17, 2026 | yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/caption/download.go and passes it to Caption.Download() in pkg/caption/caption.go, where os.Create()… | ||
| CVE-2026-73496 | Hig | 0.43 | 7.7 | 0.00 | Sep 14, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlassian/confluence/attachments.py… | ||
| CVE-2026-42845 | Hig | 0.43 | — | 0.01 | May 11, 2026 | The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-content overwrite via file upload (GHSA-w4rc-p66m-x6qq). Public form uploads now strip path components from the POST-supplied filename and hard-block page-content… | ||
| CVE-2025-54780 | Hig | 0.43 | 7.7 | 0.00 | Aug 5, 2025 | The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user can use the /ajax/screenshot.php endpoint to leak files from the system or use PHP wrappers. This is fixed in version 2.0.2. | ||
| CVE-2024-38049 | Med | 0.43 | 6.6 | 0.02 | Jul 9, 2024 | Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability | ||
| CVE-2024-0265 | Med | 0.43 | 6.3 | 0.21 | Jan 7, 2024 | A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component GET Parameter Handler. The manipulation of the argument page leads to file inclusion. The… | ||
| CVE-2026-76553 | Med | 0.42 | 6.5 | 0.00 | Sep 16, 2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, allowing users to whom an administrator has delegated a WP Import Export Lite WordPress plugin before… | ||
| CVE-2026-54629 | Hig | 0.42 | 7.5 | 0.01 | Sep 14, 2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, authorization, or directory restrictions. A… | ||
| CVE-2026-85603 | Med | 0.42 | 6.5 | 0.00 | Sep 4, 2026 | Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply directory traversal sequences in the lang POST… |
- risk 0.44cvss 6.8epss 0.00
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that…
- risk 0.44cvss —epss 0.01
Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server deployments that expose the server to an untrusted network without authentication are vulnerable to unauthenticated SQL execution through the query run API. When…
- risk 0.44cvss 6.8epss 0.00
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
- risk 0.44cvss 6.7epss 0.00
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affected process has permission to remove,…
- risk 0.44cvss 6.5epss 0.18
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- risk 0.44cvss 6.5epss 0.20
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- risk 0.44cvss 6.7epss 0.00
External control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable…
- risk 0.44cvss 6.7epss 0.00
External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.5epss 0.24
NTLM Hash Disclosure Spoofing Vulnerability
- risk 0.44cvss 6.8epss 0.01
External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.
- risk 0.44cvss 6.7epss 0.01
Microsoft Outlook Remote Code Execution Vulnerability
- risk 0.43cvss 7.7epss 0.00
yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/caption/download.go and passes it to Caption.Download() in pkg/caption/caption.go, where os.Create()…
- risk 0.43cvss 7.7epss 0.00
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlassian/confluence/attachments.py…
- risk 0.43cvss —epss 0.01
The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0 , there is an unauthenticated page-content overwrite via file upload (GHSA-w4rc-p66m-x6qq). Public form uploads now strip path components from the POST-supplied filename and hard-block page-content…
- risk 0.43cvss 7.7epss 0.00
The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user can use the /ajax/screenshot.php endpoint to leak files from the system or use PHP wrappers. This is fixed in version 2.0.2.
- risk 0.43cvss 6.6epss 0.02
Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability
- risk 0.43cvss 6.3epss 0.21
A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component GET Parameter Handler. The manipulation of the argument page leads to file inclusion. The…
- risk 0.42cvss 6.5epss 0.00
The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, allowing users to whom an administrator has delegated a WP Import Export Lite WordPress plugin before…
- risk 0.42cvss 7.5epss 0.01
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, authorization, or directory restrictions. A…
- risk 0.42cvss 6.5epss 0.00
Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply directory traversal sequences in the lang POST…