Tiny File Manager
Prasathmani · 16 CVEs
Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Du…
Feb 3, 2026
prasathmani TinyFileManager tinyfilemanager.php path traversal
Dec 28, 2025
A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allow…
May 23, 2025
Tiny File Manager v2.4.7 and below is vulnerable to session fixation.
Feb 6, 2025
Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerabi…
Feb 6, 2025
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just return…
Nov 25, 2022
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. T…
Nov 25, 2022
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actio…
Nov 25, 2022
Path Traversal in prasathmani/tinyfilemanager
Mar 17, 2022
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.…
Mar 15, 2022
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to…
Sep 15, 2021
A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that…
Sep 15, 2021
A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is…
Sep 15, 2021
In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticat…
Apr 28, 2020
In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionali…
Apr 28, 2020
Remote Code Execution in Tiny File Manager
Dec 30, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-46651 | Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-sup… | MEDIUM | 0.28% | Feb 3, 2026 |
| CVE-2025-15138 | prasathmani TinyFileManager tinyfilemanager.php path traversal | MEDIUM | 0.66% | Dec 28, 2025 |
| CVE-2025-44998 | A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScr… | MEDIUM | 0.27% | May 23, 2025 |
| CVE-2022-40916 | Tiny File Manager v2.4.7 and below is vulnerable to session fixation. | CRITICAL | 0.82% | Feb 6, 2025 |
| CVE-2022-40490 | Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitra… | MEDIUM | 0.40% | Feb 6, 2025 |
| CVE-2022-45476 | Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible… | CRITICAL | 1.05% | Nov 25, 2022 |
| CVE-2022-45475 | Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application… | MEDIUM | 0.89% | Nov 25, 2022 |
| CVE-2022-23044 | Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. This is possi… | HIGH | 0.44% | Nov 25, 2022 |
| CVE-2022-1000 | Path Traversal in prasathmani/tinyfilemanager | CRITICAL | 1.89% | Mar 17, 2022 |
| CVE-2021-45010 | A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid us… | HIGH | 70.08% | Mar 15, 2022 |
| CVE-2021-40964 | A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials o… | MEDIUM | 8.24% | Sep 15, 2021 |
| CVE-2021-40965 | A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run… | HIGH | 0.60% | Sep 15, 2021 |
| CVE-2021-40966 | A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and jav… | MEDIUM | 0.54% | Sep 15, 2021 |
| CVE-2020-12103 | In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticated users to create backup copies of file… | HIGH | 1.46% | Apr 28, 2020 |
| CVE-2020-12102 | In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. This allows authenticated users to e… | HIGH | 1.83% | Apr 28, 2020 |
| CVE-2019-16790 | Remote Code Execution in Tiny File Manager | HIGH | 1.24% | Dec 30, 2019 |
Showing 1 to 16 of 16 CVEs