CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

396 vulnerabilities with CWE-73
CVE-2026-5210 HIGH
SourceCodester Leave Application System file inclusion
CVSS 7.3
CVE-2026-30282 CRITICAL
Cast to TV Screen Mirroring 2.2.77 - File Overwrite
CVSS 9.0
CVE-2026-30284 HIGH
UXGROUP Voice Recorder 10.0 - File Overwrite
CVSS 8.6
CVE-2026-30281 CRITICAL
MaruNuri LLC v2.0.23 - Arbitrary File Overwrite
CVSS 9.8
CVE-2026-30276 CRITICAL
DeftPDF Document Translator 54.0 - File Overwrite
CVSS 9.8
CVE-2026-30940 HIGH
baserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCE
CVSS 7.2
CVE-2026-33027 MEDIUM
Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directory
CVSS 6.5
CVE-2026-33989 HIGH
@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools
CVSS 8.1
CVE-2026-33645 HIGH
Fireshare has Path Traversal Arbitrary File Write in `/api/uploadChunked`
CVSS 7.1
CVE-2026-0965 LOW
Libssh: libssh: denial of service via improper configuration file handling
CVSS 3.3
CVE-2026-33329 HIGH
FileRise: Path Traversal in `resumableIdentifier` Leading to Arbitrary File Write, Recursive Directory Deletion, and Limited Existence Oracle
CVSS 8.1
CVE-2026-33309 CRITICAL
Langflow has an Arbitrary File Write (RCE) via v2 API
CVSS 9.9
CVE-2026-33354 HIGH
AVideo has an authenticated arbitrary local file read via `chunkFile` path injection in `aVideoEncoder.json.php`
CVSS 7.6
CVE-2026-2351 MEDIUM
Task Manager <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Read
CVSS 6.5
CVE-2026-33476 HIGH
SiYuan has an Unauthenticated Arbitrary File Read via Path Traversal
CVSS 7.5
CVE-2026-32949 HIGH
SQLBot: SSRF to Arbitrary File Read (AFR) via Rogue MySQL
CVE-2026-32749 HIGH
SiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write
CVSS 7.6
CVE-2026-30903 CRITICAL
Zoom Workplace <6.6.0 - Privilege Escalation
CVSS 9.6
CVE-2026-27825 CRITICAL
MCP Atlassian <0.17.0 - Path Traversal
CVSS 9.0
CVE-2026-25605 MEDIUM
SICAM SIAPP SDK <V2.1.7 - Path Traversal
CVSS 6.7
CVE-2026-25573 HIGH
SICAM SIAPP SDK <V2.1.7 - Command Injection
CVSS 7.4
CVE-2026-24287 HIGH
Windows Kernel - Privilege Escalation
CVSS 7.8
CVE-2026-30240 CRITICAL
Budibase <=3.31.5 - Path Traversal
CVSS 9.6
CVE-2026-29611 HIGH
OpenClaw <2026.2.14 - Path Traversal
CVSS 7.5
CVE-2026-28459 HIGH
OpenClaw <2026.2.12 - Path Traversal
CVSS 7.1
Details
Vulnerabilities 396
Exploit Likelihood High