VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (561)

page 26 of 29
  • CVE-2025-58769LowOct 1, 2025
    risk 0.14cvss 3.3epss 0.00

    auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import endpoint in applications built with the SDK does not validate the file-path wrapper or value. Without proper validation, affected applications may accept…

  • CVE-2026-49358LowJun 19, 2026
    risk 0.13cvss 3.0epss 0.00

    PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGenerator::$temporaryFiles` is a public array, and `removeTemporaryFiles()` — invoked from `__destruct()` and from a registered shutdown function — calls…

  • CVE-2024-10492LowNov 25, 2024
    risk 0.11cvss 2.7epss 0.01

    A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order to perform resource creation, for example,…

  • CVE-2023-2554HigMay 5, 2023
    risk 0.02cvss 7.2epss 0.29

    External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.

  • CVE-2022-24900CriApr 29, 2022
    risk 0.01cvss 9.9epss 0.08

    Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe for use with untrusted input. When the `os.path.join` call…

  • CVE-2026-15382MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a…

  • CVE-2026-57916MedJul 27, 2026
    risk 0.00cvss epss 0.00

    proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the…

  • CVE-2026-65896HigJul 23, 2026
    risk 0.00cvss 7.1epss 0.00

    Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), which strips leading periods but does not…

  • CVE-2026-14551HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the…

  • CVE-2026-15724HigJul 21, 2026
    risk 0.00cvss 8.7epss 0.00

    In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether…

  • CVE-2026-9587HigJul 17, 2026
    risk 0.00cvss epss 0.00

    An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sound_path parameter and fails to properly validate file paths before accessing the underlying…

  • CVE-2026-46336HigJul 16, 2026
    risk 0.00cvss 7.1epss 0.00

    Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. From 0.96.0 until 0.140.0, authenticated users can rename uploaded files with path traversal sequences because app/models/model_file.rb uses the…

  • CVE-2026-12979MedJul 16, 2026
    risk 0.00cvss 5.5epss 0.00

    The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the intended directory through path traversal,…

  • CVE-2026-15921LowJul 15, 2026
    risk 0.00cvss 3.1epss 0.00

    Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.1 through 0.40.5, `nvm ls-remote` (and other commands that refresh remote LTS aliases, such as `nvm install --lts`) parse the node.js mirror's `index.tab` and…

  • CVE-2026-50148CriJul 15, 2026
    risk 0.00cvss 10.0epss 0.00

    Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the…

  • CVE-2026-61873HigJul 15, 2026
    risk 0.00cvss 8.1epss 0.00

    Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but never re-validated after rendering. Attackers can submit form data containing path…

  • CVE-2026-8920HigJul 15, 2026
    risk 0.00cvss epss 0.00

    Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path…

  • CVE-2026-50462HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55002HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-54108MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.