ZeroHour

Vulnerabilities

23 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-46651
Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature.

Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted requests to localhost by using http://www.127.0.0.1.example.com/ or a similarly constructed domain name. This may lead to unauthorized port scanning or access to internal-only services.

NVD description · AI analysis pending
4.3<1%
  • prasathmani tiny file manager
CVE-2025-15138
A flaw has been found in prasathmani TinyFileManager up to 2.6.

A flaw has been found in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of the file tinyfilemanager.php. This manipulation of the argument fullpath causes path traversal. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.0<1% PoC
  • prasathmani tiny file manager
CVE-2025-44998
A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScri

A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • prasathmani tiny file manager
CVE-2022-40916
+1 in the same advisory: …40490
Tiny File Manager v2.4.7 and below is vulnerable to session fixation.

Tiny File Manager v2.4.7 and below is vulnerable to session fixation.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • prasathmani tiny file manager
CVE-2024-44020
Missing Authorization vulnerability in prasadkirpekar WP Free SSL – Free SSL Certificate for WordPress and force HTTPS wp-free-ssl.This issue affects WP Free SS

Missing Authorization vulnerability in prasadkirpekar WP Free SSL – Free SSL Certificate for WordPress and force HTTPS wp-free-ssl.This issue affects WP Free SSL – Free SSL Certificate for WordPress and force HTTPS: from n/a through <= 1.2.7.

NVD description · AI analysis pending
8.8<1%
  • prasadkirpekar wp free ssl
CVE-2024-49240
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ajberasategui AB Categories Search Widget ab-categories-se

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ajberasategui AB Categories Search Widget ab-categories-search-widget allows Reflected XSS.This issue affects AB Categories Search Widget : from n/a through <= 0.2.5.

NVD description · AI analysis pending
6.1<1%
  • agustinberasategui ab categories search widget
CVE-2023-48772
Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Prevent Landscape Rotation.This issue affects Prevent Landscape Rotation:

Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Prevent Landscape Rotation.This issue affects Prevent Landscape Rotation: from n/a through 2.0.

NVD description · AI analysis pending
8.8<1%
  • arulprasadj prevent landscape rotation
CVE-2023-4823
The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings.

The WP Meta and Date Remover WordPress plugin before 2.2.0 provides an AJAX endpoint for configuring the plugin settings. This endpoint has no capability checks and does not sanitize the user input, which is then later output unescaped. Allowing any authenticated users, such as subscriber change them and perform Stored Cross-Site Scripting.

NVD description · AI analysis pending
5.4<1% PoC
  • prasadkirpekar wp meta and date remover
CVE-2023-32124
Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Publish Confirm Message plugin <= 1.3.1 versions.

Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Publish Confirm Message plugin <= 1.3.1 versions.

NVD description · AI analysis pending
8.8<1%
  • arulprasadj publish confirm message
CVE-2022-45476
+2 in the same advisory: …23044 …45475
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download.

Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the application is vulnerable to insecure file upload.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • prasathmani tiny file manager
CVE-2022-1000
Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.

Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.

NVD description · AI analysis pending
9.82% PoC
  • prasathmani tiny file manager
CVE-2021-45010
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid use

A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.

NVD description · AI analysis pending
8.870% PoC ×4
  • prasathmani tiny file manager
CVE-2021-42556
Rasa X before 0.42.4 allows Directory Traversal during archive extraction.

Rasa X before 0.42.4 allows Directory Traversal during archive extraction. In the functionality that allows a user to load a trained model archive, an attacker has arbitrary write capability within specific directories via a crafted archive file.

NVD description · AI analysis pending
5.5<1%
  • rasa rasa x
CVE-2021-41127
Rasa is an open source machine learning framework to automate text-and voice-based conversations.

Rasa is an open source machine learning framework to automate text-and voice-based conversations. In affected versions a vulnerability exists in the functionality that loads a trained model `tar.gz` file which allows a malicious actor to craft a `model.tar.gz` file which can overwrite or replace bot files in the bot directory. The vulnerability is fixed in Rasa 2.8.10. For users unable to update ensure that users do not upload untrusted model files, and restrict CLI or API endpoint access where a malicious actor could target a deployed Rasa instance.

NVD description · AI analysis pending
7.1<1%
  • rasa rasa
CVE-2021-40965
+2 in the same advisory: …40964 …40966
A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run

A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run OS commands by inducing the Administrator user to browse a URL controlled by an attacker.

NVD description · AI analysis pending
8.8
group max
<1%
  • prasathmani tiny file manager
CVE-2020-12102
+1 in the same advisory: …12103
In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality.

In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. This allows authenticated users to enumerate directories and files on the filesystem (outside of the application scope).

NVD description · AI analysis pending
7.72%
  • prasathmani tiny file manager
CVE-2019-16790
In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files.

In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.

NVD description · AI analysis pending
8.81%
  • prasathmani tiny file manager