CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
519 vulnerabilities with CWE-73
CVE-2026-15736
HIGH
Multiple SQL/DDL Injection and Arbitrary File Read Vulnerabilities in snowflake-sqlalchemy
CVSS 8.3
CVE-2026-57898
CRITICAL
Eclipse BaSyx - Java Server SDK < 2.0.0-milestone-13 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS 9.0
CVE-2026-61462
HIGH
mcp-gitlab Path Traversal via job_id Parameter
CVSS 8.6
CVE-2026-13014
CRITICAL
Thales CERT Suspicious <= 1.3.4 - Unauthenticated Remote Code Execution
CVE-2026-15540
MEDIUM
SourceCodester Online Book Store System Administrative index.php php file inclusion
CVSS 4.3
CVE-2026-14480
CRITICAL
OpenPLC v3 External Control of File Name or Path
CVSS 9.9
CVE-2026-53449
MEDIUM
Coturn: Arbitrary File Write via CLI psd Command
CVSS 6.0
CVE-2026-59793
HIGH
Jetbrains TeamCity < 2026.1.2 - External Control of File Name or Path
CVSS 8.8
CVE-2026-58192
HIGH
Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-plugin
CVSS 8.6
CVE-2026-59819
MEDIUM
LiteLLM: Local file read via request-supplied OIDC file references
CVSS 4.9
CVE-2026-59807
MEDIUM
Composio SDK < 0.2.32-beta.283 - Sensitive File Upload via tool-file-uploads.ts
CVSS 6.8
CVE-2026-49145
HIGH
App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc
CVSS 7.5
CVE-2026-6101
HIGH
AMP for WP <= 1.1.12 - Authenticated Arbitrary File Write
CVSS 7.5
CVE-2026-53648
MEDIUM
FOSSBilling: Downloadable product files can be overwritten through filename collisions
CVE-2026-59196
HIGH
pnpm: hoisted install imports lockfile alias outside node_modules
CVSS 7.1
CVE-2026-59194
HIGH
pnpm: patch-remove could delete project-selected files outside the patches directory
CVSS 7.1
CVE-2026-58293
HIGH
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVSS 8.1
CVE-2026-8921
HIGH
Asus Business Manager < v3.0.38.0 - External Control of File Name or Path
CVE-2026-5821
HIGH
Image Optimizer <= 1.7.4 - Authenticated (Author+) Arbitrary File Deletion via Post Meta Field Injection
CVSS 8.1
CVE-2026-55628
MEDIUM
ImageMagick: Policy Bypass in concatenate operation due to missing checks
CVSS 5.5
CVE-2026-12480
MEDIUM
Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras
CVSS 5.5
CVE-2026-6070
CRITICAL
WP-BusinessDirectory <= 4.0.1 - Unauthenticated File Deletion via Path Traversal
CVSS 9.1
CVE-2026-3602
MEDIUM
IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection
CVSS 4.7
CVE-2026-10816
HIGH
NetScaler ADC and Gateway Management Interfaces - Unauthenticated File Read
CVSS 7.5
CVE-2026-13748
MEDIUM
Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path Restriction
CVSS 6.3
Details
Vulnerabilities
519
Exploit Likelihood
High