Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Prasathmani

First CVE: Dec 30, 2019Active for: 7 yearsTotal CVEs: 16
55.3
VTI Score
TOP TARGET

Prasathmani's vulnerability footprint centers on Tiny File Manager, a lightweight web-based file administration tool that, despite its narrow product scope, occupies a notable position in the vulnerability landscape due to its widespread deployment in resource-constrained environments. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code, while recurring weakness classes—path traversal, cross-site scripting, cross-site request forgery, unrestricted file upload, and improper access control—reflect the inherent risks of web-based file handling and authentication in a minimalist codebase. Defenders should treat updates to this tool as a priority given its direct exposure to untrusted file operations and web request handling; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Prasathmani over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 30, 2019
6 years ago
Most Recent CVE
Feb 3, 2026
171 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-45010HIGH
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to uploa
Mar 15, 20228.877NOYES
CVE-2021-40964MEDIUM
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulne
Sep 15, 20216.536NOYES
CVE-2022-45476CRITICAL
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the applicati
Nov 25, 20229.831NONO
CVE-2022-40916CRITICAL
Tiny File Manager v2.4.7 and below is vulnerable to session fixation.
Feb 6, 20259.830NONO
CVE-2022-23044HIGH
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. This is possible because the appli
Nov 25, 20228.828NONO
CVE-2022-1000CRITICAL
Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.
Mar 17, 20229.827NONO
CVE-2021-40965HIGH
A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run OS commands by induc
Sep 15, 20218.827NONO
CVE-2019-16790HIGH
In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.
Dec 30, 20198.826NONO
CVE-2025-15138HIGH
A flaw has been found in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of the file tinyfilemanager.php. This manipulation of the argum
Dec 28, 20257.223NONO
CVE-2022-45475MEDIUM
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to brok
Nov 25, 20226.523NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
38%
44%
19%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (56.3%)
Unknown0 (0.0%)
Required7 (43.8%)
Privileges Required
Low6 (37.5%)
High2 (12.5%)
None8 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Prasathmani.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Prasathmani — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Prasathmani's Products

View all 5 CNAs →

Top CWEs