Tiny File Manager

Prasathmani · 16 CVEs

CVE-2025-46651
MEDIUM

Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Du…

Feb 3, 2026

CVE-2025-15138
MEDIUM

prasathmani TinyFileManager tinyfilemanager.php path traversal

Dec 28, 2025

CVE-2025-44998
MEDIUM

A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allow…

May 23, 2025

CVE-2022-40916
CRITICAL

Tiny File Manager v2.4.7 and below is vulnerable to session fixation.

Feb 6, 2025

CVE-2022-40490
MEDIUM

Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerabi…

Feb 6, 2025

CVE-2022-45476
CRITICAL

Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just return…

Nov 25, 2022

CVE-2022-45475
MEDIUM

Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. T…

Nov 25, 2022

CVE-2022-23044
HIGH

Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actio…

Nov 25, 2022

CVE-2022-1000
CRITICAL

Path Traversal in prasathmani/tinyfilemanager

Mar 17, 2022

CVE-2021-45010
HIGH

A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.…

Mar 15, 2022

CVE-2021-40964
MEDIUM

A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to…

Sep 15, 2021

CVE-2021-40965
HIGH

A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that…

Sep 15, 2021

CVE-2021-40966
MEDIUM

A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is…

Sep 15, 2021

CVE-2020-12103
HIGH

In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticat…

Apr 28, 2020

CVE-2020-12102
HIGH

In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionali…

Apr 28, 2020

CVE-2019-16790
HIGH

Remote Code Execution in Tiny File Manager

Dec 30, 2019

Showing 1 to 16 of 16 CVEs