VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (674)

page 33 of 34
  • CVE-2026-13014CriJul 13, 2026
    risk 0.00cvss —epss 0.01

    A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable application files—including Python modules, configuration files, cron inputs, and runtime…

  • CVE-2026-15540MedJul 13, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename…

  • CVE-2026-59793HigJul 10, 2026
    risk 0.00cvss 8.8epss 0.00

    In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration

  • CVE-2026-59807MedJul 8, 2026
    risk 0.00cvss 6.8epss 0.00

    Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check in the readFileFromDisk function within tool-file-uploads.ts. Attackers can…

  • CVE-2026-49145HigJul 8, 2026
    risk 0.00cvss 7.5epss 0.00

    App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up the directory hierarchy from the current directory for a project .ackrc and loads its options. The project-source option blocklist in App::Ack::ConfigLoader does…

  • CVE-2026-6101HigJul 7, 2026
    risk 0.00cvss 7.5epss 0.01

    The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() function combined with inadequate cleanup that fails to…

  • CVE-2026-53648MedJul 7, 2026
    risk 0.00cvss —epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a deterministic filename-derived path. When an administrator uploads a file for a downloadable product, FOSSBilling stores the file as…

  • CVE-2026-59196HigJul 6, 2026
    risk 0.00cvss 7.1epss 0.00

    pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm could overwrite pnpm-owned layout. This…

  • CVE-2026-58293HigJul 3, 2026
    risk 0.00cvss 8.1epss 0.01

    External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-5821HigJul 2, 2026
    risk 0.00cvss 8.1epss 0.01

    The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in post meta are used directly in file…

  • CVE-2026-6070CriJul 1, 2026
    risk 0.00cvss 9.1epss 0.01

    The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryControllerUpload class. The…

  • CVE-2026-3602MedJun 30, 2026
    risk 0.00cvss 4.7epss 0.00

    IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be…

  • CVE-2026-10816HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.01

    Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled

  • CVE-2026-13748MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.00

    Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file content to be read and transmitted to Snowflake services. An attacker could exploit this by supplying crafted repository or project content that referenced files…

  • CVE-2026-8095HigJun 28, 2026
    risk 0.00cvss 8.1epss 0.01

    The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where…

  • CVE-2025-71333CriJun 25, 2026
    risk 0.00cvss 9.8epss 0.01

    Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary…

  • CVE-2026-27211CriFeb 21, 2026
    risk 0.00cvss 10.0epss 0.01

    Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary host file exfiltration (constrained by process privileges) when using virtio-block devices backed by raw images. A malicious guest can overwrite its disk…

  • CVE-2026-27115HigFeb 20, 2026
    risk 0.00cvss 7.1epss 0.00

    ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument that allows any user to trigger recursive deletion of arbitrary directories on the Windows filesystem. ADB Explorer accepts an optional path argument to set a…

  • CVE-2026-26975HigFeb 20, 2026
    risk 0.00cvss 8.8epss 0.02

    Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthenticated network-adjacent attackers to execute arbitrary code on affected installations. The music/playlists/update API…

  • CVE-2026-26202HigFeb 19, 2026
    risk 0.00cvss 7.5epss 0.00

    Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from the server by supplying a local file path (e.g. `/etc/passwd`) as a font data chunk in the `create-font-variant` RPC endpoint,…