VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (674)

page 27 of 34
  • CVE-2022-23536MedDec 19, 2022
    risk 0.35cvss 6.5epss 0.01

    Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a result of parsing maliciously crafted Alertmanager…

  • CVE-2021-24966MedMar 14, 2022
    risk 0.35cvss 4.9epss 0.05

    The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder

  • CVE-2026-18751MedAug 18, 2026
    risk 0.34cvss —epss 0.00

    External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.

  • CVE-2026-17014MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.

  • CVE-2026-19011MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packages/server/src/routes/agents.ts. Performing a manipulation results in file inclusion. The attack may be initiated remotely. The exploit is now public and may…

  • CVE-2025-11738MedOct 18, 2025
    risk 0.34cvss 5.3epss 0.00

    The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and including, 3.29 via the mla-stream-image.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary ai/eps/pdf/ps files on the…

  • CVE-2024-22341MedFeb 22, 2025
    risk 0.34cvss 5.3epss 0.00

    IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7.4, and 4.8.0 through 4.8.7 could allow unauthorized data access from a remote data source object due to improper privilege management.

  • CVE-2024-12267MedJan 31, 2025
    risk 0.34cvss 5.3epss 0.00

    The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.8.5. This makes it…

  • CVE-2024-36473MedJun 10, 2024
    risk 0.34cvss 5.3epss 0.00

    Trend Micro VPN Proxy One Pro, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite or create attack but is limited to local Denial of Service (DoS) and under specific conditions can lead to elevation of privileges.

  • CVE-2024-2150MedMar 3, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Insurance Management System 1.0. This issue affects some unknown processing. The manipulation of the argument page leads to file inclusion. The attack may be initiated remotely. The exploit has…

  • CVE-2023-43074MedOct 23, 2023
    risk 0.34cvss 5.2epss 0.00

    Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server.

  • CVE-2014-125044MedJan 5, 2023
    risk 0.34cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in soshtolsus wing-tight. This affects an unknown part of the file index.php. The manipulation of the argument p leads to file inclusion. It is possible to initiate the attack remotely. Upgrading to version 1.0.0 is…

  • CVE-2026-19353MedAug 9, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed remotely. This attack is…

  • CVE-2026-48520MedJun 23, 2026
    risk 0.33cvss 6.1epss 0.00

    Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code) contains a potential arbitrary file-read vulnerability, depending on the exact flow configuration used. By making a flow public,…

  • CVE-2025-67461MedDec 10, 2025
    risk 0.33cvss 5.0epss 0.00

    External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of information via local access.

  • CVE-2025-64738MedNov 13, 2025
    risk 0.33cvss 5.0epss 0.00

    External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user to conduct a disclosure of information via local access.

  • CVE-2020-5296MedJun 3, 2020
    risk 0.33cvss 6.2epss 0.01

    In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to delete arbitrary local files of an October CMS server. The vulnerability is only exploitable by an authenticated backend user with the…

  • CVE-2026-54582MedSep 17, 2026
    risk 0.32cvss —epss 0.01

    mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/install_primative.c, and…

  • CVE-2026-53508MedAug 31, 2026
    risk 0.32cvss —epss 0.00

    oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRefsAllowed = false) when loading a spec from…

  • CVE-2026-79653MedAug 27, 2026
    risk 0.32cvss —epss 0.00

    In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage with config key enable.attachment.store.to.file.system, the attacker can manipulate the filename upon upload and can essentially cause arbitrary file path…