CVE-2026-108801 | prasathmani TinyFileManager up to 2.6 tinyfilemanager.php move_uploaded_file fullpath unrestricted upload

SecurityVulns

A vulnerability was found in prasathmani TinyFileManager up to 2.6. It has been rated as critical. The impacted element is the function move_uploaded_file of the file tinyfilemanager.php. Performing a manipulation of the argument fullpath results in unrestricted upload.

This vulnerability is reported as CVE-2026-108801. The attack is possible to be carried out remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More