Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tiny File Manager HIGH 7.2
CVE-2025-15138

A flaw has been found in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of the file tinyfilemanager.php.…

Fix: after 2.6
Fix from $1,950 2025-12-28
Tiny File Manager MEDIUM 6.1
CVE-2025-44998

A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitra…

No fix yet
Fix from $1,600 2025-05-23
Tiny File Manager CRITICAL 9.8
CVE-2022-40916

Tiny File Manager v2.4.7 and below is vulnerable to session fixation.

Fix: after 2.4.7
Fix from $2,300 2025-02-06
Tiny File Manager CRITICAL 9.8
CVE-2022-45476

Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is…

No fix yet
Fix from $2,300 2022-11-25
Tiny File Manager MEDIUM 6.5
CVE-2022-45475

Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the ap…

No fix yet
Fix from $1,600 2022-11-25
Tiny File Manager HIGH 8.8
CVE-2022-23044

Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. Thi…

No fix yet
Fix from $1,950 2022-11-25
Tiny File Manager CRITICAL 9.8
CVE-2022-1000

Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.

Fix: 2.4.7+
Fix from $2,300 2022-03-17
Tiny File Manager HIGH 8.8
CVE-2021-45010EPSS 70%

A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (wit…

Fix: after 2.4.7
Fix from $1,950 2022-03-15
Tiny File Manager HIGH 8.8
CVE-2021-40965

A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload fil…

Fix: after 2.4.6
Fix from $1,950 2021-09-15
Tiny File Manager MEDIUM 6.5
CVE-2021-40964EPSS 8%

A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin cre…

Fix: after 2.4.6
Fix from $1,600 2021-09-15
Tiny File Manager MEDIUM 5.4
CVE-2021-40966

A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HT…

Fix: after 2.4.6
Fix from $1,600 2021-09-15
Tiny File Manager HIGH 7.7
CVE-2020-12103

In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticated users to create backup copi…

Patch available
Fix from $1,950 2020-04-28
Tiny File Manager HIGH 7.7
CVE-2020-12102

In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. This allows authenticated …

Patch available
Fix from $1,950 2020-04-28
Tiny File Manager HIGH 8.8
CVE-2019-16790

In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.

Fix: 2.3.9+
Fix from $1,950 2019-12-30