CVE-2025-46651
- EPSS 0.03%
- Veröffentlicht 03.02.2026 00:00:00
- Zuletzt bearbeitet 10.02.2026 20:53:45
Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted requests to localhost by using http://www.127.0.0....
CVE-2025-15138
- EPSS 0.23%
- Veröffentlicht 28.12.2025 13:32:08
- Zuletzt bearbeitet 31.12.2025 19:36:39
A flaw has been found in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of the file tinyfilemanager.php. This manipulation of the argument fullpath causes path traversal. Remote exploitation of the attack ...
CVE-2025-44998
- EPSS 0.06%
- Veröffentlicht 23.05.2025 00:00:00
- Zuletzt bearbeitet 31.12.2025 19:43:08
A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.
CVE-2022-40490
- EPSS 0.12%
- Veröffentlicht 06.02.2025 17:15:13
- Zuletzt bearbeitet 31.12.2025 19:40:50
Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing fil...
CVE-2022-40916
- EPSS 0.43%
- Veröffentlicht 06.02.2025 17:15:13
- Zuletzt bearbeitet 31.12.2025 19:40:50
Tiny File Manager v2.4.7 and below is vulnerable to session fixation.
CVE-2022-45475
- EPSS 0.92%
- Veröffentlicht 25.11.2022 18:15:11
- Zuletzt bearbeitet 31.12.2025 19:40:50
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to broken access control.
CVE-2022-45476
- EPSS 0.9%
- Veröffentlicht 25.11.2022 18:15:11
- Zuletzt bearbeitet 31.12.2025 19:40:50
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the application is vulnerable to insecure file upload.
CVE-2022-23044
- EPSS 1.32%
- Veröffentlicht 25.11.2022 17:15:10
- Zuletzt bearbeitet 31.12.2025 19:40:50
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. This is possible because the application is vulnerable to CSRF.
CVE-2022-1000
- EPSS 0.35%
- Veröffentlicht 17.03.2022 11:15:07
- Zuletzt bearbeitet 31.12.2025 19:40:50
Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.
CVE-2021-45010
- EPSS 72.44%
- Veröffentlicht 15.03.2022 12:15:08
- Zuletzt bearbeitet 31.12.2025 19:40:50
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.