CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Tiny File Manager v2.4.7 and below is vulnerable to session fixation.