Tiny File Manager
Vendor:
First CVE: Dec 30, 2019 · Active for 6 years
16
Total CVEs
More Total CVEs than 93% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tiny File Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 30, 2019
6 years ago
Most Recent CVE
Feb 3, 2026
174 days ago
CVE Severity & Scoring
Tiny File Manager16 CVEs
38%
44%
19%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (56.3%)
Unknown0 (0.0%)
Required7 (43.8%)
Privileges Required
Low6 (37.5%)
High2 (12.5%)
None8 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45010HIGH A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to uploa | Mar 15, 2022 | 8.8 | 77 | NO | YES |
CVE-2021-40964MEDIUM A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulne | Sep 15, 2021 | 6.5 | 36 | NO | YES |
CVE-2022-45476CRITICAL Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the applicati | Nov 25, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-40916CRITICAL Tiny File Manager v2.4.7 and below is vulnerable to session fixation. | Feb 6, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-23044HIGH Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. This is possible because the appli | Nov 25, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-1000CRITICAL Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7. | Mar 17, 2022 | 9.8 | 27 | NO | NO |
CVE-2021-40965HIGH A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run OS commands by induc | Sep 15, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-16790HIGH In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted. | Dec 30, 2019 | 8.8 | 26 | NO | NO |
CVE-2025-15138HIGH A flaw has been found in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of the file tinyfilemanager.php. This manipulation of the argum | Dec 28, 2025 | 7.2 | 23 | NO | NO |
CVE-2022-45475MEDIUM Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to brok | Nov 25, 2022 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
12.5% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Tiny File Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.4.8 | 3 | 8.4 | 0.8% | 0 | 0 |
| 2.4.7 | 1 | 6.1 | 0.2% | 0 | 0 |
| 2.4.1 | 2 | 7.7 | 1.6% | 0 | 0 |