VYPR

CWE-73

External Control of File Name or Path

BaseDraftLikelihood: High

Description

The product allows user input to control or influence paths or file names that are used in filesystem operations.

Hierarchy (View 1000)

Children

Related attack patterns (CAPEC)

CAPEC-13 · CAPEC-267 · CAPEC-64 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-80

CVEs mapped to this weakness (674)

page 6 of 34
  • CVE-2025-64712CriFeb 4, 2026
    risk 0.57cvss 9.8epss 0.01

    The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. Prior to version 0.18.18, a path traversal vulnerability in the partition_msg function allows an attacker to write…

  • CVE-2020-37078HigFeb 3, 2026
    risk 0.57cvss 8.8epss 0.00

    i-doit Open Source CMDB 1.14.1 contains a file deletion vulnerability in the import module that allows authenticated attackers to delete arbitrary files by manipulating the delete_import parameter. Attackers can send a POST request to the import module with a crafted filename to…

  • CVE-2021-47871HigJan 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write files to arbitrary locations using the API index.php endpoint. Attackers can exploit the v-make-tmp-file command to write SSH keys or other content to specific…

  • CVE-2020-36878HigDec 5, 2025
    risk 0.57cvss —epss 0.00

    ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can exploit this to disclose contents of files…

  • CVE-2025-12529HigDec 2, 2025
    risk 0.57cvss 8.8epss 0.01

    The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteOrdersFiles() function in all versions up to, and including, 3.6.3. This makes it possible for unauthenticated attackers to inject…

  • CVE-2025-6237CriSep 18, 2025
    risk 0.57cvss 9.8epss 0.00

    A vulnerability in invokeai version v6.0.0a1 and below allows attackers to perform path traversal and arbitrary file deletion via the GET /api/v1/images/download/{bulk_download_item_name} endpoint. By manipulating the filename arguments, attackers can read and delete any files…

  • CVE-2025-29866HigAug 7, 2025
    risk 0.57cvss —epss 0.00

    : External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This issue affects X-Free Uploader: from 1.0.1.0084 before 1.0.1.0085, from 2.0.1.0034 before 2.0.1.0035.

  • CVE-2025-49588HigJul 2, 2025
    risk 0.57cvss —epss 0.00

    Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In version 2.10.2, the server accepts links of format file:///etc/passwd and doesn't do any validation before sending them to parsers and playwright, this can…

  • CVE-2024-57394HigApr 21, 2025
    risk 0.57cvss 8.8epss 0.01

    The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL…

  • CVE-2024-12066HigDec 21, 2024
    risk 0.57cvss 8.8epss 0.01

    The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the smsa_delete_label() function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with…

  • CVE-2024-28826HigMay 29, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server.

  • CVE-2023-40194HigNov 27, 2023
    risk 0.57cvss 8.8epss 0.02

    An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to mistreatment of whitespace characters. A specially crafted malicious file can create files at arbitrary locations, which can lead to arbitrary code…

  • CVE-2023-39542HigNov 27, 2023
    risk 0.57cvss 8.8epss 0.04

    A code execution vulnerability exists in the Javascript saveAs API of Foxit Reader 12.1.3.15356. A specially crafted malformed file can create arbitrary files, which can lead to remote code execution. An attacker needs to trick the user into opening the malicious file to trigger…

  • CVE-2023-35985HigNov 27, 2023
    risk 0.57cvss 8.8epss 0.03

    An arbitrary file creation vulnerability exists in the Javascript exportDataObject API of Foxit Reader 12.1.3.15356 due to a failure to properly validate a dangerous extension. A specially crafted malicious file can create files at arbitrary locations, which can lead to…

  • CVE-2023-36764HigSep 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

  • CVE-2023-3256HigJun 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.

  • CVE-2022-34669HigDec 30, 2022
    risk 0.57cvss 8.8epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modify system files or other files that are critical to the application, which may lead to code execution, denial of service, escalation of…

  • CVE-2022-31739HigDec 22, 2022
    risk 0.57cvss 8.8epss 0.01

    When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.*This bug only affects Firefox for Windows. Other operating…

  • CVE-2020-25161HigFeb 23, 2021
    risk 0.57cvss 8.8epss 0.02

    The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator.

  • CVE-2026-73171HigSep 16, 2026
    risk 0.56cvss —epss 0.01

    Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite arbitrary files on the device filesystem…