Product
prasathmani tiny file manager
16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-46651
CVE-2025-15138
CVE-2025-44998
CVE-2022-40916
CVE-2022-40490
CVE-2022-45476
CVE-2022-45475
CVE-2022-23044
CVE-2022-1000
CVE-2021-45010
CVE-2021-40966
CVE-2021-40965
CVE-2021-40964
CVE-2020-12103
CVE-2020-12102
CVE-2019-16790
<= 2.6
Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insuff
<= 2.6
A flaw has been found in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of the file t
all versions
A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers
<= 2.4.7
Tiny File Manager v2.4.7 and below is vulnerable to session fixation.
<= 2.4.7
Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows
all versions
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them fo
all versions
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is poss
all versions
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within t
< 2.4.7
Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.
<= 2.4.7
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows re
<= 2.4.6
A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a fi
<= 2.4.6
A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows atta
<= 2.4.6
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a f
all versions
In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticated users to
all versions
In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. This al
< 2.3.9
In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated