CVE-2011-4906: Tiny Tinybrowser

Critical severity, CVSS 9.8. EPSS: 9.6% chance of exploitation in the next 30 days.

Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.

Affected products

  • Tiny Tinybrowser: before 1.5.13 (fixed in 1.5.13)

Published 2020-02-12. Last modified 2026-06-16.