VendorsPrasathmanitiny_file_managerany version
Vulnerabilities

Prasathmani Tiny File Manager any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2022-1000
Path Traversal in prasathmani/tinyfilemanager
Published 2022-03-17 · Modified
9.8EPSS 0.019
CVE-2022-40916
Tiny File Manager v2.4.7 and below is vulnerable to session fixation.
Published 2025-02-06 · Analyzed
9.8EPSS 0.008
CVE-2021-40965
A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run OS commands by inducing the Administrator user to browse a URL controlled by an attacker.
Published 2021-09-15 · Modified
9.3EPSS 0.006
CVE-2021-45010
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.
Published 2022-03-15 · Modified
8.81 PoCEPSS 0.701
CVE-2019-16790
Remote Code Execution in Tiny File Manager
Published 2019-12-30 · Modified
8.8EPSS 0.012
CVE-2025-15138
prasathmani TinyFileManager tinyfilemanager.php path traversal
Published 2025-12-28 · Analyzed
7.2EPSS 0.007
CVE-2021-40964
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings (../ and ..\) in order to escape the server's intended working directory and write malicious files onto any directory on the computer.
Published 2021-09-15 · Modified
6.51 PoCEPSS 0.082
CVE-2021-40966
A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will run on any user browser when they access the server.
Published 2021-09-15 · Modified
5.4EPSS 0.005
CVE-2022-40490
Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file.
Published 2025-02-06 · Modified
4.8EPSS 0.004
CVE-2025-46651
Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted requests to localhost by using http://www.127.0.0.1.example.com/ or a similarly constructed domain name. This may lead to unauthorized port scanning or access to internal-only services.
Published 2026-02-03 · Analyzed
4.3EPSS 0.003