Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
852036.4%CRITICAL

Related CVEs

52
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2026-0932Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacker to cause the server to send HTTP GET requests to arbitrary URLs.MEDIUM6.99.3%Apr 1, 2026
CVE-2026-0663Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vault administrator privileges to crash the M-Files Server process by calling a vulnerable API endpoint.MEDIUM6.929.3%Jan 21, 2026
CVE-2025-14267Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak exposure affecting versions before 25.12.15491.7MEDIUM5.627.1%Dec 19, 2025
CVE-2025-14318Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using Web Companion despite Print and Download Prevention module being enabled.MEDIUM5.319.4%Dec 18, 2025
CVE-2025-11681Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash.HIGH7.127.9%Nov 17, 2025
CVE-2025-9826Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to cause script execution for other users.HIGH7.015.0%Sep 15, 2025
CVE-2025-2091An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making requests to untrusted URLs.MEDIUM4.814.1%Jun 16, 2025
CVE-2025-5964A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.HIGH8.495.1%Jun 15, 2025
CVE-2025-3087Stored XSS in M-Files Web versions from 25.1.14445.5 to 25.2.14524.4 allows an authenticated user to run scriptsMEDIUM5.114.5%Apr 4, 2025
CVE-2025-3086Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of serviceMEDIUM6.328.4%Apr 4, 2025
CVE-2025-0648Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highly privileged attacker to cause denial of service via configuration change.MEDIUM5.938.9%Jan 23, 2025
CVE-2025-0635Denial of service condition in M-Files Server in versions before 25.1.14445.5 allows an unauthenticated user to consume computing resources in certain conditions.MEDIUM6.339.9%Jan 23, 2025
CVE-2025-0619Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwordsMEDIUM4.632.6%Jan 23, 2025
CVE-2024-10127Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.CRITICAL9.244.1%Nov 20, 2024
CVE-2024-10126Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read server local files of a limited set of filetypes via document preview.MEDIUM5.329.3%Nov 20, 2024
CVE-2024-9174Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UIMEDIUM6.918.8%Oct 2, 2024
CVE-2024-6789A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read filesHIGH8.442.4%Aug 27, 2024
CVE-2024-6881Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser sessionHIGH8.525.0%Jul 29, 2024
CVE-2024-6124Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser sessionHIGH8.520.7%Jul 29, 2024
CVE-2024-5142Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browserHIGH7.022.4%May 24, 2024