VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (674)

page 31 of 34
  • CVE-2023-0092MedJan 31, 2025
    risk 0.25cvss 4.9epss 0.01

    An authenticated user who has read access to the juju controller model, may construct a remote request to download an arbitrary file from the controller's filesystem.

  • CVE-2024-12875MedDec 21, 2024
    risk 0.25cvss 4.9epss 0.01

    The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.2 via the file download functionality. This makes it possible for authenticated attackers, with…

  • CVE-2026-49836MedSep 10, 2026
    risk 0.23cvss —epss 0.00

    psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled and unsanitised, a tool that extracts…

  • CVE-2025-49760LowJul 8, 2025
    risk 0.23cvss 3.5epss 0.01

    External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-63225MedSep 16, 2026
    risk 0.22cvss 4.4epss 0.00

    Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSamples lang values without verifying that the…

  • CVE-2026-21249LowFeb 10, 2026
    risk 0.22cvss 3.3epss 0.11

    External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

  • CVE-2025-27137MedFeb 24, 2025
    risk 0.22cvss 4.4epss 0.00

    Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track allows users with the `SYSTEM_CONFIGURATION` permission to customize notification templates. Templates are evaluated using the…

  • CVE-2024-39303MedJul 1, 2024
    risk 0.22cvss 4.4epss 0.00

    Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ZIP file. This issue has been addressed in Weblate…

  • CVE-2026-86995MedSep 8, 2026
    risk 0.21cvss 4.3epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration without validating it. A later fetch or pull…

  • CVE-2026-0965LowMar 26, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by…

  • CVE-2025-65799MedDec 8, 2025
    risk 0.21cvss 4.3epss 0.00

    A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.

  • CVE-2025-8998LowNov 11, 2025
    risk 0.20cvss 3.1epss 0.00

    It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account.

  • CVE-2025-12654LowDec 21, 2025
    risk 0.18cvss 2.7epss 0.00

    The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up to, and including, 0.9.120. This is due to the check_filesystem_permissions() function not properly restricting the directories…

  • CVE-2025-1911LowMar 26, 2025
    risk 0.18cvss 2.7epss 0.00

    The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.5.0. This makes it…

  • CVE-2025-1972LowMar 22, 2025
    risk 0.18cvss 2.7epss 0.00

    The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with…

  • CVE-2024-13922LowMar 20, 2025
    risk 0.18cvss 2.7epss 0.00

    The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.0. This makes it possible for authenticated…

  • CVE-2024-10672LowNov 12, 2024
    risk 0.18cvss 2.7epss 0.01

    The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the mpg_upsert_project_source_block() function in all versions up to, and including, 4.0.2. This makes it possible for…

  • CVE-2024-6937LowJul 21, 2024
    risk 0.18cvss 2.7epss 0.00

    A vulnerability, which was classified as problematic, was found in formtools.org Form Tools 3.1.1. Affected is the function curl_exec of the file /admin/forms/option_lists/edit.php of the component Import Option List. The manipulation of the argument url leads to file inclusion.…

  • CVE-2026-93987LowSep 19, 2026
    risk 0.15cvss 3.4epss 0.00

    rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name) from the attacker-supplied `name` field of a Docker…

  • CVE-2020-5297LowJun 3, 2020
    risk 0.15cvss 3.4epss 0.01

    In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to upload jpg, jpeg, bmp, png, webp, gif, ico, css, js, woff, woff2, svg, ttf, eot, json, md, less, sass, scss, xml files to any directory of an…