CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
519 vulnerabilities with CWE-73
CVE-2026-8095
HIGH
Frontend File Manager Plugin <= 23.6 - Authenticated (Subscriber+) Arbitrary File Deletion
CVSS 8.1
CVE-2026-47214
HIGH
Docling: Unsafe URI and Path Handling in HTML Backend
CVSS 7.1
CVE-2026-55700
HIGH
pnpm: stage download writes outside destination via manifest version traversal
CVSS 7.1
CVE-2026-55699
MEDIUM
pnpm: reserved bin name deletes PNPM_HOME during global remove
CVSS 6.5
CVE-2026-55477
HIGH
Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
CVSS 7.2
CVE-2026-48720
HIGH
Warp: SSH remote output can lead to local file overwrite and persistence
CVSS 8.8
CVE-2026-48520
MEDIUM
Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
CVSS 6.1
CVE-2026-53632
MEDIUM
NTLMv2 hash disclosure via UNC path handling on Windows
CVE-2026-49358
LOW
PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles
CVSS 3.0
CVE-2026-53915
HIGH
Jetbrains GoLand < 2026.1.3 - External Control of File Name or Path
CVSS 7.1
CVE-2026-8118
MEDIUM
Royal Addons for Elementor 1.7.1058-1.7.1059 - Contributor+ Arbitrary File Read
CVSS 6.5
CVE-2026-2604
MEDIUM
Evolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri handling
CVSS 5.6
CVE-2026-10303
HIGH
ServerCo getssl ACME shell script path injection
CVSS 7.4
CVE-2026-39006
CRITICAL
SNMP4J-Agent 3.8.3 - Remote Code Execution via snmp4jCfgStoragePath Component
CVSS 9.8
CVE-2026-34030
MEDIUM
Improper branch-code validation in Wertheim SafeController Software allows file path manipulation
CVE-2026-11527
HIGH
Perl Config::IniFiles < 3.001000 - OS Command Injection via -file 2-Arg open()
CVSS 8.6
CVE-2026-11526
CRITICAL
Perl GD < 2.86 - OS Command Injection via 2-Arg open()
CVSS 9.8
CVE-2026-45556
CRITICAL
Roxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream RCE) via WAF rule save `config_file_name`
CVSS 9.9
CVE-2026-47643
CRITICAL
Azure Stack Edge Remote Code Execution Vulnerability
CVSS 9.8
CVE-2026-46397
MEDIUM
haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0
CVSS 6.5
CVE-2026-46399
CRITICAL
haxtheweb haxcms-nodejs - Authenticated Remote Code Execution via File Overwrite
CVE-2026-40605
MEDIUM
Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API
CVE-2026-20175
MEDIUM
Cisco Finesse File Inclusion Vulnerability
CVSS 6.1
CVE-2026-35080
HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - ugw-restoreinfo Arbitrary File Deletion
CVSS 8.1
CVE-2026-35079
HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - ugw-restore Arbitrary File Deletion
CVSS 8.1
Details
Vulnerabilities
519
Exploit Likelihood
High