Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
15031.0%CRITICAL

Related CVEs

5
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2025-46651Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted requests to localhost by using http://www.127.0.0.1.example.com/ or a similarly constructed domain name. This may lead to unauthorized port scanning or access to internal-only services.MEDIUM4.316.7%Feb 3, 2026
CVE-2025-15138A flaw has been found in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of the file tinyfilemanager.php. This manipulation of the argument fullpath causes path traversal. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.LOW2.042.2%Dec 28, 2025
CVE-2025-44998A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.MEDIUM6.115.2%May 23, 2025
CVE-2022-40916Tiny File Manager v2.4.7 and below is vulnerable to session fixation.CRITICAL9.851.3%Feb 6, 2025
CVE-2022-40490Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file.MEDIUM4.829.4%Feb 6, 2025