CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

449 vulnerabilities with CWE-73
CVE-2026-34030 MEDIUM
Improper branch-code validation in Wertheim SafeController Software allows file path manipulation
CVE-2026-11527 HIGH
Perl Config::IniFiles < 3.001000 - OS Command Injection via -file 2-Arg open()
CVSS 8.6
CVE-2026-11526 CRITICAL
Perl GD < 2.86 - OS Command Injection via 2-Arg open()
CVSS 9.8
CVE-2026-45556 CRITICAL
Roxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream RCE) via WAF rule save `config_file_name`
CVSS 9.9
CVE-2026-47643 CRITICAL
Azure Stack Edge Remote Code Execution Vulnerability
CVSS 9.8
CVE-2026-46397 MEDIUM
haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0
CVSS 6.5
CVE-2026-46399 CRITICAL
haxtheweb haxcms-nodejs - Authenticated Remote Code Execution via File Overwrite
CVE-2026-40605 MEDIUM
Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API
CVE-2026-20175 MEDIUM
Cisco Finesse File Inclusion Vulnerability
CVSS 6.1
CVE-2026-35080 HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - ugw-restoreinfo Arbitrary File Deletion
CVSS 8.1
CVE-2026-35079 HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - ugw-restore Arbitrary File Deletion
CVSS 8.1
CVE-2026-35078 HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - ugw-logstop Arbitrary File Deletion
CVSS 8.1
CVE-2026-35077 HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - ugw-delete-file Arbitrary File Deletion
CVSS 8.1
CVE-2026-35076 HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - bac-scanresult Arbitrary File Deletion
CVSS 8.1
CVE-2026-10694 HIGH
SourceCodester Online Food Ordering System index.php include file inclusion
CVSS 7.3
CVE-2026-41412 MEDIUM
alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension Script
CVSS 4.9
CVE-2026-10559 MEDIUM
SourceCodester Pizzafy Ecommerce System index.php file inclusion
CVSS 6.3
CVE-2026-10558 MEDIUM
SourceCodester Pizzafy Ecommerce System index.php file inclusion
CVSS 6.3
CVE-2026-9559 CRITICAL
Mautic 7 - Authenticated Path Traversal and Remote Code Execution via Campaign Import ZIP Extraction
CVSS 9.9
CVE-2026-46402 HIGH
Microsoft UFO uses untrusted task_name in log paths, allowing authenticated path traversal and log file creation outside the logs directory
CVSS 8.1
CVE-2026-45089 HIGH
Dalfox: Unauthenticated Arbitrary File Create/Append via `output` Option in Dalfox Server Mode
CVSS 8.2
CVE-2026-45088 HIGH
Dalfox: Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file` in Dalfox Server Mode
CVSS 7.5
CVE-2026-48920 HIGH
Jenkins Email Extension Plugin < 1933.v45cec755423f - External Control of File Name or Path
CVSS 8.8
CVE-2026-8450 CRITICAL
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()
CVSS 9.1
CVE-2026-35593 MEDIUM
Trilium Notes has Local File Inclusion via upload modified file API endpoint
CVSS 6.8
Details
Vulnerabilities 449
Exploit Likelihood High