CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

519 vulnerabilities with CWE-73
CVE-2026-35078 HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - ugw-logstop Arbitrary File Deletion
CVSS 8.1
CVE-2026-35077 HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - ugw-delete-file Arbitrary File Deletion
CVSS 8.1
CVE-2026-35076 HIGH
MBS Gateway Devices V1_0_0_0-V6_0_0_7 - bac-scanresult Arbitrary File Deletion
CVSS 8.1
CVE-2026-10694 HIGH
SourceCodester Online Food Ordering System index.php include file inclusion
CVSS 7.3
CVE-2026-41412 MEDIUM
alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension Script
CVSS 4.9
CVE-2026-10559 MEDIUM
SourceCodester Pizzafy Ecommerce System index.php file inclusion
CVSS 6.3
CVE-2026-10558 MEDIUM
SourceCodester Pizzafy Ecommerce System index.php file inclusion
CVSS 6.3
CVE-2026-9559 CRITICAL
Mautic 7 - Authenticated Path Traversal and Remote Code Execution via Campaign Import ZIP Extraction
CVSS 9.9
CVE-2026-46402 HIGH
Microsoft UFO uses untrusted task_name in log paths, allowing authenticated path traversal and log file creation outside the logs directory
CVSS 8.1
CVE-2026-45089 HIGH
Dalfox: Unauthenticated Arbitrary File Create/Append via `output` Option in Dalfox Server Mode
CVSS 8.2
CVE-2026-45088 HIGH
Dalfox: Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file` in Dalfox Server Mode
CVSS 7.5
CVE-2026-48920 HIGH
Jenkins Email Extension Plugin < 1933.v45cec755423f - External Control of File Name or Path
CVSS 8.8
CVE-2026-8450 CRITICAL
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()
CVSS 9.1
CVE-2026-35593 MEDIUM
Trilium Notes has Local File Inclusion via upload modified file API endpoint
CVSS 6.8
CVE-2026-47358 HIGH
Tenable Terrascan < 1.18.3 - Externally Controlled Reference to a Resource in Another Sphere
CVSS 7.5
CVE-2026-47357 HIGH
Tenable Terrascan < 1.18.3 - Externally Controlled Reference to a Resource in Another Sphere
CVSS 7.5
CVE-2026-29962 HIGH
HSC MailInspector 5.3.3-7 - Path Traversal
CVSS 7.5
CVE-2026-45008 MEDIUM
phpMyFAQ - Path Traversal in Client::deleteClientFolder via URL Parameter
CVSS 6.5
CVE-2026-46383 MEDIUM
Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
CVSS 5.5
CVE-2026-44641 HIGH
Microsoft APM: plugin.json component paths escape plugin root and copy arbitrary host files during install
CVSS 7.1
CVE-2026-42597 MEDIUM
Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// scheme
CVSS 5.9
CVE-2026-42593 MEDIUM
Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes
CVSS 5.3
CVE-2026-40893 HIGH
Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move
CVSS 8.2
CVE-2026-42881 HIGH
STIGQter: Arbitrary File Write leading to Local Code Execution via Export HTML
CVE-2026-3892 HIGH
Motors – Car Dealer, Classifieds & Listing <= 1.4.107 - Authenticated (Subscriber+) Arbitrary File Deletion via 'stm_dealer_logo_path' Parameter
CVSS 8.1
Details
Vulnerabilities 519
Exploit Likelihood High