
CVE-2025-46651 Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied U… https://www.cve.org/CVERecord?id=CVE-2025-46651
Post summary
The text announces a server‑side request forgery (SSRF) flaw in Tiny File Manager 2.6, noting insufficient validation of user‑supplied URLs in the upload feature.
