CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
449 vulnerabilities with CWE-73
CVE-2026-34030
MEDIUM
Improper branch-code validation in Wertheim SafeController Software allows file path manipulation
CVE-2026-11527
HIGH
Perl Config::IniFiles < 3.001000 - OS Command Injection via -file 2-Arg open()
CVSS 8.6
CVE-2026-11526
CRITICAL
Perl GD < 2.86 - OS Command Injection via 2-Arg open()
CVSS 9.8
CVE-2026-45556
CRITICAL
Roxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream RCE) via WAF rule save `config_file_name`
CVSS 9.9
CVE-2026-47643
CRITICAL
Azure Stack Edge Remote Code Execution Vulnerability
CVSS 9.8
CVE-2026-46397
MEDIUM
haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0
CVSS 6.5
CVE-2026-46399
CRITICAL
haxtheweb haxcms-nodejs - Authenticated Remote Code Execution via File Overwrite
CVE-2026-40605
MEDIUM
Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API
CVE-2026-20175
MEDIUM
Cisco Finesse File Inclusion Vulnerability
CVSS 6.1
CVE-2026-35080
HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - ugw-restoreinfo Arbitrary File Deletion
CVSS 8.1
CVE-2026-35079
HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - ugw-restore Arbitrary File Deletion
CVSS 8.1
CVE-2026-35078
HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - ugw-logstop Arbitrary File Deletion
CVSS 8.1
CVE-2026-35077
HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - ugw-delete-file Arbitrary File Deletion
CVSS 8.1
CVE-2026-35076
HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - bac-scanresult Arbitrary File Deletion
CVSS 8.1
CVE-2026-10694
HIGH
SourceCodester Online Food Ordering System index.php include file inclusion
CVSS 7.3
CVE-2026-41412
MEDIUM
alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension Script
CVSS 4.9
CVE-2026-10559
MEDIUM
SourceCodester Pizzafy Ecommerce System index.php file inclusion
CVSS 6.3
CVE-2026-10558
MEDIUM
SourceCodester Pizzafy Ecommerce System index.php file inclusion
CVSS 6.3
CVE-2026-9559
CRITICAL
Mautic 7 - Authenticated Path Traversal and Remote Code Execution via Campaign Import ZIP Extraction
CVSS 9.9
CVE-2026-46402
HIGH
Microsoft UFO uses untrusted task_name in log paths, allowing authenticated path traversal and log file creation outside the logs directory
CVSS 8.1
CVE-2026-45089
HIGH
Dalfox: Unauthenticated Arbitrary File Create/Append via `output` Option in Dalfox Server Mode
CVSS 8.2
CVE-2026-45088
HIGH
Dalfox: Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file` in Dalfox Server Mode
CVSS 7.5
CVE-2026-48920
HIGH
Jenkins Email Extension Plugin < 1933.v45cec755423f - External Control of File Name or Path
CVSS 8.8
CVE-2026-8450
CRITICAL
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()
CVSS 9.1
CVE-2026-35593
MEDIUM
Trilium Notes has Local File Inclusion via upload modified file API endpoint
CVSS 6.8
Details
Vulnerabilities
449
Exploit Likelihood
High