CVEs we hold for M-files
Records whose assigning authority named M-files as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-0983Denial of service vulnerability in M-Files ServerM-Files Server CVE-2026-0931Denial-of-service vulnerability in M-Files ServerM-Files Server CVE-2026-0663Denial of Service condition in M-Files ServerM-Files Server CVE-2025-3086User in anonymous role could create and delete viewsM-Files Server CVE-2025-2159Stored XSS in M-Files Admin user interfaceM-Files Admin CVE-2025-14318Improper access validation in M-Files ServerM-Files Server CVE-2025-14267Unintended temporary cached data included in a structure only copy intended to be empty of dataM-Files Server CVE-2025-11681Denial of Service condition in M-Files ServerM-Files Server CVE-2025-0648M-Files Server crash via EOT database driver configurationM-Files Server CVE-2025-0635Denial of Service condition in M-Files ServerM-Files Server CVE-2024-9333Permission bypass in M-Files Connector for CopilotM-Files Connector for Copilot CVE-2024-9174Stored HTML Injection in Hubshare social moduleM-Files Hubshare CVE-2024-6881Stored XSS VulnerabilityM-Files Corporation Hubshare CVE-2024-6124Reflected XSS in Hubshare via Open RedirectM-Files Corporation Hubshare CVE-2024-5142XSS in Hubshare's social moduleM-Files Corporation Hubshare CVE-2024-4056Denial of service condition in M-Files ServerM-Files Server CVE-2024-11176Incorrect evaluation of effective permissions in M-Files AinoM-Files Aino CVE-2024-10127Support for authentication bypass condition in M-Files LDAP authenticationM-Files Server CVE-2024-10126Local file inclusion vulnerability in M-Files ServerM-Files Server CVE-2024-0563Denial of service condition in M-Files ServerM-Files Server CVE-2023-6912Brute force vulnerability in M-Files user authenticationM-Files Server CVE-2023-6910Uncontrolled Resource Consumption in M-Files ServerM-Files Server CVE-2023-6239Incorrect calculation of effective permissionsM-Files Server CVE-2023-6189Improper Permission Handling in M-Files ServerM-Files Server CVE-2023-6117M-Files REST API allows Denial of ServiceM-Files Server CVE-2023-5524M-Files Web Companion allows Remote Code Execution for some filetypesM-Files Web Companion CVE-2023-5523M-Files Web Companion allows Remote Code ExecutionM-Files Web Companion CVE-2023-3425CVE-2023-3425: Out-of-Bounds memory readM-Files Server CVE-2023-3406Path traversal issue in M-Files Classic WebM-Files Web CVE-2023-3405Denial of service condition in M-Files ServerM-Files Server CVE-2023-2480Elevation of Privilege in M-Files Desktop ClientM-Files Client CVE-2023-2325Stored XSS Vulnerability in M-Files Classic WebM-Files Web CVE-2023-2112Desktop component allows lateral movement between sessionsM-Files Desktop CVE-2023-0384Uncontrolled Resource Consuption in M-Files ServerM-Files Server CVE-2023-0383Uncontrolled Resource Consuption in M-Files ServerM-Files Server CVE-2023-0382Uncontrolled Resource Consumption in M-Files ServerM-Files Server CVE-2022-4861Incorrect Implementation of Authentication AlgorithmM-Files Client CVE-2022-4858Insertion of Sensitive Information into Log FileM-Files Server CVE-2022-4270Incorrect privilege assignment in M-Files Web ServerM-Files Web CVE-2022-4264Incorrect privilege assignment in M-Files Web ServerM-Files Web CVE-2022-39019Broken access controls on PDFtron WebviewerUI in M-Files HubshareM-Files Hubshare CVE-2022-39018Broken access controls on PDFtron data in M-Files HubshareM-Files Hubshare CVE-2022-39017XSS in all comments fields in M-Files HubshareM-Files Hubshare CVE-2022-39016Javascript injection in PDFtron in M-Files HubshareM-Files Hubshare CVE-2022-3284Insecure way of passing a download keyM-Files New Web CVE-2022-1911Information disclosure in M-Files ServerM-Files Server CVE-2022-1606Incorrect privilege assignment in M-Files ServerM-Files Server CVE-2021-41809SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, allows requests from server.M-Files Server CVE-2021-41808In M-Files Server product with versions before 21.11.10775.0, enabling logging of federated authentication would write…M-Files Server CVE-2021-41807Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0, allows…M-Files Web 64 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.