CVE-2020-21554: Tinyrise Tinyshop
High severity, CVSS 8.1. EPSS: 1.5% chance of exploitation in the next 30 days.
A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could let a malicious user delete any file such as install.lock to reinstall cms.
Affected products
- Tinyrise Tinyshop: version 3.1.1 only
Published 2022-03-25. Last modified 2026-06-17.