Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-6497
prasathmani TinyFileManager File Upload filemanager.php server-side request forgery
CVE-2026-6496
prasathmani TinyFileManager POST Parameter filemanager.php path traversal
CVE-2025-46651
Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted requests to localhost by using http://www.127.0.0.1.example.com/ or a similarly constructed domain name. This may lead to unauthorized port scanning or access to internal-only services.
CVE-2025-15138
prasathmani TinyFileManager tinyfilemanager.php path traversal
CVE-2025-44998
A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.
