VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (674)

page 25 of 34
  • CVE-2026-42866MedMay 11, 2026
    risk 0.37cvss —epss 0.00

    Tookie is a advanced OSINT information gathering tool. Prior to 4.1fix, modules/modules.py's write_txt, write_csv, write_json, and (commented-but-shipping) scan_file helpers open their output as open(f"{user}."), where user comes unsanitized from the -u CLI flag or any line…

  • CVE-2026-27008MedFeb 20, 2026
    risk 0.37cvss 6.7epss 0.00

    OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a bug in `download` skill installation allowed `targetDir` values from skill frontmatter to resolve outside the per-skill tools directory if not strictly validated. In the admin-only `skills.install` flow, this…

  • CVE-2025-13320MedDec 12, 2025
    risk 0.37cvss 6.8epss 0.01

    The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs…

  • CVE-2025-1686MedFeb 27, 2025
    risk 0.37cvss 6.8epss 0.01

    Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Name or Path via the include tag. A high privileged attacker can access sensitive local files by crafting malicious notification templates that leverage this tag…

  • CVE-2024-25117MedFeb 21, 2024
    risk 0.37cvss 6.8epss 0.01

    php-svg-lib is a scalable vector graphics (SVG) file parsing/rendering library. Prior to version 0.5.2, php-svg-lib fails to validate that font-family doesn't contain a PHAR url, which might leads to RCE on PHP < 8.0, and doesn't validate if external references are allowed. This…

  • CVE-2026-19860MedSep 19, 2026
    risk 0.36cvss 5.5epss 0.00

    The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage…

  • CVE-2026-81830MedSep 7, 2026
    risk 0.36cvss —epss 0.00

    The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

  • CVE-2026-82194MedSep 4, 2026
    risk 0.36cvss 5.5epss 0.00

    The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root.

  • CVE-2026-2604MedJun 17, 2026
    risk 0.36cvss 5.6epss 0.00

    A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact…

  • CVE-2025-53769MedAug 12, 2025
    risk 0.36cvss 5.5epss 0.00

    External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.

  • CVE-2025-47956MedJun 10, 2025
    risk 0.36cvss 5.5epss 0.01

    External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.

  • CVE-2025-0202MedJan 4, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in TCS BaNCS 10. It has been classified as problematic. This affects an unknown part of the file /REPORTS/REPORTS_SHOW_FILE.jsp. The manipulation of the argument FilePath leads to file inclusion. The real existence of this vulnerability is still doubted…

  • CVE-2023-6618MedDec 8, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The exploit has…

  • CVE-2023-34982MedNov 15, 2023
    risk 0.36cvss 5.5epss 0.00

    This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.

  • CVE-2023-30943MedMay 2, 2023
    risk 0.36cvss 6.5epss 0.07

    The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.

  • CVE-2022-34765MedJul 13, 2022
    risk 0.36cvss 5.5epss 0.01

    A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA…

  • CVE-2019-14905MedMar 31, 2020
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename…

  • CVE-2026-75602MedSep 3, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before…

  • CVE-2026-78679MedAug 25, 2026
    risk 0.35cvss 6.5epss 0.00

    GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file= to read arbitrary files, with contents returned in…

  • CVE-2025-36398MedAug 19, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modify another user's command history due to an externally controlled filename.