We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-44998



Description

A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter.

Reserved 2025-04-22 | Published 2025-05-23 | Updated 2025-05-23 | Assigner mitre

References

github.com/prasathmani/tinyfilemanager

github.com/l8BL/CVE-2025-44998

cve.org (CVE-2025-44998)

nvd.nist.gov (CVE-2025-44998)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-44998

Support options

Helpdesk Chat, Email, Knowledgebase