📦 Tiny File Manager

by Prasathmani

🔍 What is Tiny File Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-40916

CRITICAL CVSS 9.8 Feb 6, 2025

CVE-2022-40916 is a session fixation vulnerability in Tiny File Manager v2.4.7 and below that allows attackers to hijack user sessions by fixing session IDs before authentication. This affects all use...

CVE-2022-1000

CRITICAL CVSS 9.8 Mar 17, 2022

This path traversal vulnerability in tinyfilemanager allows attackers to access files outside the intended directory by manipulating file paths. It affects all users running tinyfilemanager versions p...

CVE-2021-45010

HIGH CVSS 8.8 Mar 15, 2022

This is an authenticated path traversal vulnerability in Tiny File Manager that allows users with valid accounts to upload malicious PHP files to the webroot directory. Successful exploitation leads t...

CVE-2021-40965

HIGH CVSS 8.8 Sep 15, 2021

This CSRF vulnerability in TinyFileManager allows attackers to trick authenticated administrators into executing malicious requests, leading to arbitrary file uploads and remote code execution. All ve...

CVE-2025-15138

MEDIUM CVSS 4.7 Dec 28, 2025

This vulnerability in TinyFileManager allows attackers to perform path traversal attacks by manipulating the 'fullpath' parameter in tinyfilemanager.php. This could enable unauthorized file access or ...

CVE-2022-40490

MEDIUM CVSS 4.8 Feb 6, 2025

CVE-2022-40490 is a Cross-Site Scripting (XSS) vulnerability in Tiny File Manager v2.4.7 and below that allows attackers to execute arbitrary JavaScript code by injecting malicious payloads into file ...