CWE-73
High likelihoodExternal Control of File Name or Path
The product allows user input to control or influence paths or file names that are used in filesystem operations.
519 vulnerabilities with CWE-73
CVE-2026-39907
CRITICAL
Unisys WebPerfect Image Suite 3.0 NTLMv2 Hash Leakage via WCF SOAP
CVSS 10.0
CVE-2026-5809
HIGH
wpForo Forum <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Deletion via 'data[body][fileurl]' Parameter
CVSS 7.1
CVE-2026-5054
HIGH
NoMachine External Control of File Path Local Privilege Escalation Vulnerability
CVSS 7.8
CVE-2026-5053
HIGH
NoMachine External Control of File Path Arbitrary File Deletion Vulnerability
CVSS 7.1
CVE-2026-31939
HIGH
Path Traversal (Arbitrary File Delete) in Chamilo LMS
CVSS 8.3
CVE-2026-40086
MEDIUM
Rembg <2.0.75 Custom Model Loading - Path Traversal
CVSS 5.3
CVE-2026-35174
CRITICAL
Chyrp Lite <2026.01 Uploads Path - Remote Code Execution
CVSS 9.1
CVE-2026-34783
HIGH
Ferret <2.0.0-alpha.4 IO::FS::WRITE - Arbitrary File Write
CVSS 8.1
CVE-2026-34522
HIGH
SillyTavern: Path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
CVSS 8.1
CVE-2026-33949
HIGH
@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files
CVSS 8.1
CVE-2026-30292
HIGH
Docudepot PDF Reader 1.0.34 - File Overwrite
CVSS 8.4
CVE-2026-30291
HIGH
Ora Tools PDF Reader 4.3.5 - File Overwrite
CVSS 8.4
CVE-2026-30289
HIGH
Tinybeans Private Family Album App 5.9.5-prod - Arbitrary File Overwrite
CVSS 8.4
CVE-2026-30287
HIGH
ACE Scanner PDF Scanner 1.4.5 - File Overwrite
CVSS 8.4
CVE-2026-23898
HIGH
Joomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdate
CVSS 7.2
CVE-2026-5210
HIGH
SourceCodester Leave Application System file inclusion
CVSS 7.3
CVE-2026-30282
CRITICAL
Cast to TV Screen Mirroring 2.2.77 - File Overwrite
CVSS 9.0
CVE-2026-30284
HIGH
UXGROUP Voice Recorder 10.0 - File Overwrite
CVSS 8.6
CVE-2026-30281
CRITICAL
MaruNuri LLC v2.0.23 - Arbitrary File Overwrite
CVSS 9.8
CVE-2026-30276
CRITICAL
DeftPDF Document Translator 54.0 - File Overwrite
CVSS 9.8
CVE-2026-30940
HIGH
baserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCE
CVSS 7.2
CVE-2026-33027
MEDIUM
Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directory
CVSS 6.5
CVE-2026-33989
HIGH
@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools
CVSS 8.1
CVE-2026-33645
HIGH
Fireshare has Path Traversal Arbitrary File Write in `/api/uploadChunked`
CVSS 7.1
CVE-2026-0965
LOW
Libssh: libssh: denial of service via improper configuration file handling
CVSS 3.3
Details
Vulnerabilities
519
Exploit Likelihood
High