CWE-73

High likelihood

External Control of File Name or Path

Parent: CWE-642 - External Control of Critical State Data

The product allows user input to control or influence paths or file names that are used in filesystem operations.

449 vulnerabilities with CWE-73
CVE-2025-35053 MEDIUM
Newforma Project Center < 2024.3 - Authenticated Path Traversal and Arbitrary File Deletion via MarkupServices.ashx
CVSS 6.4
CVE-2025-10494 HIGH
Motors - Car Dealership & Classified Listings Plugin <1.4.89 - Priv...
CVSS 8.1
CVE-2025-10306 LOW
Backup Bolt <1.4.1 - Path Traversal
CVSS 3.8
CVE-2025-58769 LOW
auth0-php 3.3.0-8.16.0 - Path Traversal via Bulk User Import Endpoint
CVSS 3.3
CVE-2025-6237 CRITICAL
invokeai < 6.7.0 - Path Traversal and Arbitrary File Deletion via Image Download Endpoint
CVSS 9.8
CVE-2025-10058 HIGH
WP Import - Ultimate CSV XML Importer <7.27 - Privilege Escalation
CVSS 8.1
CVE-2025-8422 HIGH
Propovoice: All-in-One Client Management System <=1.7.6.7 - Arbitrary File Read
CVSS 7.5
CVE-2025-59049 HIGH
Mockoon < 9.2.0 - Path Traversal and Local File Inclusion via Static File Serving Configuration
CVSS 7.5
CVE-2025-58762 CRITICAL
Tautulli < 2.16.0 - Authenticated Path Traversal and Remote Code Execution via pms_image_proxy Endpoint
CVSS 9.1
CVE-2025-55316 HIGH
Azure Connected Machine Agent < 1.56 - Authenticated Privilege Escalation via External Control of File Name or Path
CVSS 7.8
CVE-2025-10134 CRITICAL
Goza - Nonprofit Charity WordPress Theme <3.2.2 - Privilege Escalation
CVSS 9.1
CVE-2025-9920 MEDIUM
Campcodes Recruitment Management System 1.0 - File Inclusion
CVSS 4.7
CVE-2025-54945 CRITICAL
SUNNET Corporate Training Management System <10.11 - Path-Controlled File Command Execution
CVSS 9.8
CVE-2025-58158 HIGH
Harness Open Source <3.3.0 - Command Injection
CVSS 8.8
CVE-2025-9529 HIGH
Campcodes Payroll Management System 1.0 - File Inclusion
CVSS 7.3
CVE-2025-9048 HIGH
Wptobe-memberships <3.4.2 - Privilege Escalation
CVSS 8.1
CVE-2025-53363 MEDIUM
dpanel 1.2.0-1.7.2 - Authenticated Path Traversal via /api/app/compose/get-from-uri Endpoint
CVE-2025-55746 CRITICAL
Directus 10.8.0-11.9.2 - Unauthenticated Arbitrary File Upload via File Update Mechanism
CVSS 9.3
CVE-2025-20269 MEDIUM
Cisco EPNM/Prime Infrastructure - Info Disclosure
CVSS 6.5
CVE-2025-53769 MEDIUM
Windows Security App - Path Traversal
CVSS 5.5
CVE-2025-29866 HIGH
TAGFREE X-Free Uploader <1.0.1.0085 - Path Traversal
CVE-2025-54780 HIGH
GLPI glpi-screenshot-plugin <2.0.2 - Info Disclosure
CVSS 7.7
CVE-2025-4674 HIGH
Go - Code Injection
CVSS 8.6
CVE-2025-5393 CRITICAL
Alone - Charity Multipurpose Non-profit WordPress Theme <7.8.3 - Pa...
CVSS 9.1
CVE-2025-6691 HIGH
SureForms <= 1.7.3 - Unauthenticated Arbitrary File Deletion
CVSS 8.1
Details
Vulnerabilities 449
Exploit Likelihood High