← Back
CWE-73

628 CVEs • Abstraction: Base • Likelihood of Exploit: High

External Control of File Name or Path

The product allows user input to control or influence paths or file names that are used in filesystem operations.

JSON object

Loading...

CVEs (628)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Carel
1Boss Mini Firmware
Jun 17, 2026
Jul 12, 2023
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion....Show more
A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This affects an unknown part of the file boss/servlet/document. The manipulation of the argument path leads to file inclusion. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233889 was assigned to this vulnerability.Show less
1Microsoft
11Windows 10 1507
Windows 10 1607Windows 10 1809+8 more
Jun 17, 2026
Jul 11, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Windows MSHTML Platform Security Feature Bypass Vulnerability
1Advantech
1R Seenet
Jun 17, 2026
Jun 22, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.
1Zoom
1Virtual Desktop Infrastructure
Jun 17, 2026
Jun 13, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A malicious user may potentially delete local files without proper permissions.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
May 10, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to export local files from the firewall through a race condition.
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Jun 17, 2026
May 9, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Windows MSHTML Platform Security Feature Bypass Vulnerability
1Bumsys Project
1Bumsys
Jun 17, 2026
May 5, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.
2Fedoraproject
Moodle
3Extra Packages For Enterprise Linux
FedoraMoodle
Jun 17, 2026
May 2, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrar...Show more
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.Show less
1Oretnom23
1Student Study Center Desk Management System
Jun 17, 2026
Apr 18, 2023
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulat...Show more
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226273 was assigned to this vulnerability.Show less
1Posimyth
1The Plus Addons For Elementor
Jun 17, 2026
Mar 7, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor create...Show more
The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info Box can include an SVG image for the box. Unfortunately, the plugin used file_get_contents with no verification that the file being supplied was an SVG file, so any user with access to the Elementor page builder, such as contributors, could read arbitrary files on the WordPress installation.Show less
1Flatpress
1Flatpress
Jun 17, 2026
Mar 1, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.
1Teampass
1Teampass
Jun 17, 2026
Feb 27, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.
1Fortinet
1Fortinac
Jun 17, 2026
Feb 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow...Show more
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.Show less
1Microsoft
3Visual Studio 2017
Visual Studio 2019Visual Studio 2022
Aug 19, 2026
Feb 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Visual Studio Elevation of Privilege Vulnerability
1Microsoft
1Windows Server 2008
Aug 19, 2026
Feb 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Installer Elevation of Privilege Vulnerability
2Fedoraproject
Paloaltonetworks
2Cortex Xsoar
Fedora
Jun 17, 2026
Feb 8, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
1Siemens
1Automation License Manager
Jun 17, 2026
Jan 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected compone...Show more
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected components allow to rename license files with user chosen input without authentication. This could allow an unauthenticated remote attacker to rename and move files as SYSTEM user.Show less
1Sternenblog Project
1Sternenblog
Nov 21, 2024
Jan 7, 2023
N/A· v4
9.8 CRITICAL· v3
4.6 MEDIUM· v2
A vulnerability, which was classified as problematic, has been found in sternenseemann sternenblog. This issue affects the function blog_index of the file main.c. The manipulation of the argument post_path leads to file...Show more
A vulnerability, which was classified as problematic, has been found in sternenseemann sternenblog. This issue affects the function blog_index of the file main.c. The manipulation of the argument post_path leads to file inclusion. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 0.1.0 is able to address this issue. The identifier of the patch is cf715d911d8ce17969a7926dea651e930c27e71a. It is recommended to upgrade the affected component. The identifier VDB-217613 was assigned to this vulnerability. NOTE: This case is rather theoretical and probably won't happen. Maybe only on obscure Web servers.Show less
1Wing Tight Project
1Wing Tight
Nov 21, 2024
Jan 5, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability, which was classified as critical, was found in soshtolsus wing-tight. This affects an unknown part of the file index.php. The manipulation of the argument p leads to file inclusion. It is possible to ini...Show more
A vulnerability, which was classified as critical, was found in soshtolsus wing-tight. This affects an unknown part of the file index.php. The manipulation of the argument p leads to file inclusion. It is possible to initiate the attack remotely. Upgrading to version 1.0.0 is able to address this issue. The patch is named 567bc33e6ed82b0d0179c9add707ac2b257aeaf2. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217515.Show less
1Perfsonar
1Perfsonar
Jun 17, 2026
Jan 1, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL.