Prasathmani's vulnerability footprint centers on Tiny File Manager, a lightweight web-based file administration tool that, despite its narrow product scope, occupies a notable position in the vulnerability landscape due to its widespread deployment in resource-constrained environments. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code, while recurring weakness classes—path traversal, cross-site scripting, cross-site request forgery, unrestricted file upload, and improper access control—reflect the inherent risks of web-based file handling and authentication in a minimalist codebase. Defenders should treat updates to this tool as a priority given its direct exposure to untrusted file operations and web request handling; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Prasathmani over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45010HIGH A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to uploa | Mar 15, 2022 | 8.8 | 77 | NO | YES |
CVE-2021-40964MEDIUM A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulne | Sep 15, 2021 | 6.5 | 36 | NO | YES |
CVE-2022-45476CRITICAL Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the applicati | Nov 25, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-40916CRITICAL Tiny File Manager v2.4.7 and below is vulnerable to session fixation. | Feb 6, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-23044HIGH Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. This is possible because the appli | Nov 25, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-1000CRITICAL Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7. | Mar 17, 2022 | 9.8 | 27 | NO | NO |
CVE-2021-40965HIGH A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run OS commands by induc | Sep 15, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-16790HIGH In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted. | Dec 30, 2019 | 8.8 | 26 | NO | NO |
CVE-2025-15138HIGH A flaw has been found in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of the file tinyfilemanager.php. This manipulation of the argum | Dec 28, 2025 | 7.2 | 23 | NO | NO |
CVE-2022-45475MEDIUM Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to brok | Nov 25, 2022 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Prasathmani.
Media articles that mention a CVE ID that affects a product developed by Prasathmani — matched by CVE ID, not by vendor name.