VendorsPrasathmanitiny_file_managerall versions
Vulnerabilities

Prasathmani Tiny File Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2022-1000
Path Traversal in prasathmani/tinyfilemanager
Published 2022-03-17 · Modified
9.8EPSS 0.019
CVE-2022-45476
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the application is vulnerable to insecure file upload.
Published 2022-11-25 · Modified
9.8EPSS 0.010
CVE-2022-40916
Tiny File Manager v2.4.7 and below is vulnerable to session fixation.
Published 2025-02-06 · Analyzed
9.8EPSS 0.008
CVE-2021-40965
A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run OS commands by inducing the Administrator user to browse a URL controlled by an attacker.
Published 2021-09-15 · Modified
9.3EPSS 0.006
CVE-2021-45010
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.
Published 2022-03-15 · Modified
8.81 PoCEPSS 0.701
CVE-2019-16790
Remote Code Execution in Tiny File Manager
Published 2019-12-30 · Modified
8.8EPSS 0.012
CVE-2022-23044
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. This is possible because the application is vulnerable to CSRF.
Published 2022-11-25 · Modified
8.8EPSS 0.004
CVE-2020-12102
In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. This allows authenticated users to enumerate directories and files on the filesystem (outside of the application scope).
Published 2020-04-28 · Modified
7.7EPSS 0.018
CVE-2020-12103
In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticated users to create backup copies of files (with .bak extension) outside the scope in the same directory in which they are stored.
Published 2020-04-28 · Modified
7.7EPSS 0.015
CVE-2025-15138
prasathmani TinyFileManager tinyfilemanager.php path traversal
Published 2025-12-28 · Analyzed
7.2EPSS 0.007
CVE-2021-40964
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings (../ and ..\) in order to escape the server's intended working directory and write malicious files onto any directory on the computer.
Published 2021-09-15 · Modified
6.51 PoCEPSS 0.082
CVE-2022-45475
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to broken access control.
Published 2022-11-25 · Modified
6.5EPSS 0.009
CVE-2025-44998
A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.
Published 2025-05-23 · Analyzed
6.1EPSS 0.003
CVE-2021-40966
A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will run on any user browser when they access the server.
Published 2021-09-15 · Modified
5.4EPSS 0.005
CVE-2022-40490
Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file.
Published 2025-02-06 · Modified
4.8EPSS 0.004
CVE-2025-46651
Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted requests to localhost by using http://www.127.0.0.1.example.com/ or a similarly constructed domain name. This may lead to unauthorized port scanning or access to internal-only services.
Published 2026-02-03 · Analyzed
4.3EPSS 0.003