CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

449 vulnerabilities with CWE-73
CVE-2026-7633 MEDIUM
Totolink N300RH cstecgi.cgi setUploadSetting file inclusion
CVSS 6.5
CVE-2026-30893 CRITICAL
Wazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peer
CVSS 9.0
CVE-2026-42424 MEDIUM
OpenClaw < 2026.4.8 - Local File Exfiltration via Shared Reply MEDIA Paths
CVSS 5.7
CVE-2026-41177 MEDIUM
Squidex has Blind SSRF via file:// Protocol in Restore API leading to Local File Interaction
CVSS 5.5
CVE-2026-4132 HIGH
HTTP Headers <= 1.19.2 - Authenticated Remote Code Execution via htpasswd Path Manipulation
CVSS 7.2
CVE-2026-39378 MEDIUM
nbconvert 6.5-7.17.0 HTMLExporter Image Embedding - Arbitrary File Read
CVSS 6.5
CVE-2026-39377 MEDIUM
nbconvert 6.5-7.17.0 Cell Attachments - Arbitrary File Write
CVSS 6.5
CVE-2026-41389 MEDIUM
OpenClaw 2026.4.7 < 2026.4.15 - Arbitrary File Read via Unvalidated Tool-Result Media Paths
CVSS 5.8
CVE-2026-35465 HIGH
SecureDrop Client has path injection in read_gzip_header_filename()
CVSS 7.5
CVE-2026-40342 CRITICAL
Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution
CVSS 9.9
CVE-2026-35032 HIGH
Jellyfin: Potential SSRF + Arbitrary file read via LiveTV M3U tuner
CVSS 8.1
CVE-2026-39907 CRITICAL
Unisys WebPerfect Image Suite 3.0 NTLMv2 Hash Leakage via WCF SOAP
CVSS 10.0
CVE-2026-5809 HIGH
wpForo Forum <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion via 'data[body][fileurl]' Parameter
CVSS 7.1
CVE-2026-5054 HIGH
NoMachine External Control of File Path Local Privilege Escalation Vulnerability
CVSS 7.8
CVE-2026-5053 HIGH
NoMachine External Control of File Path Arbitrary File Deletion Vulnerability
CVSS 7.1
CVE-2026-31939 HIGH
Path Traversal (Arbitrary File Delete) in Chamilo LMS
CVSS 8.3
CVE-2026-40086 MEDIUM
Rembg <2.0.75 Custom Model Loading - Path Traversal
CVSS 5.3
CVE-2026-35174 CRITICAL
Chyrp Lite <2026.01 Uploads Path - Remote Code Execution
CVSS 9.1
CVE-2026-34783 HIGH
Ferret <2.0.0-alpha.4 IO::FS::WRITE - Arbitrary File Write
CVSS 8.1
CVE-2026-34522 HIGH
SillyTavern: Path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
CVSS 8.1
CVE-2026-33949 HIGH
@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files
CVSS 8.1
CVE-2026-30292 HIGH
Docudepot PDF Reader 1.0.34 - File Overwrite
CVSS 8.4
CVE-2026-30291 HIGH
Ora Tools PDF Reader 4.3.5 - File Overwrite
CVSS 8.4
CVE-2026-30289 HIGH
Tinybeans Private Family Album App 5.9.5-prod - Arbitrary File Overwrite
CVSS 8.4
CVE-2026-30287 HIGH
ACE Scanner PDF Scanner 1.4.5 - File Overwrite
CVSS 8.4
Details
Vulnerabilities 449
Exploit Likelihood High