Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2026-0932 Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 a… M Files Server 26.3.15818.5+ Fix from $1,9502026-04-01 MEDIUM 6.5 CVE-2025-11681 Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user… M Files Server 25.2.14524.13 / 25.8.15085.17+ Fix from $1,6002025-11-17 MEDIUM 5.4 CVE-2025-9826 Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to cause script execution for other … Hubshare 25.8+ Fix from $1,6002025-09-15 MEDIUM 5.4 CVE-2025-2091 An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously craf… M Files Mobile 25.6.0+ Fix from $1,6002025-06-16 MEDIUM 6.5 CVE-2025-5964EPSS 14% A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server. M Files Server 24.8.13981.16 / 25.2.14524.9+ Fix from $1,6002025-06-15 HIGH 7.1 CVE-2025-3086 Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly caus… M Files Server 25.3.14549+ Fix from $1,9502025-04-04 MEDIUM 5.4 CVE-2025-3087 Stored XSS in M-Files Web versions from 25.1.14445.5 to 25.2.14524.4 allows an authenticated user to run scripts M Files Web after 25.2.14524.4 Fix from $1,6002025-04-04 HIGH 7.5 CVE-2025-0635 Denial of service condition in M-Files Server in versions before 25.1.14445.5 allows an unauthenticated user to consume computing resources in cert… M Files Server 25.1.14445.5+ Fix from $1,9502025-01-23 CRITICAL 9.8 CVE-2024-10127 Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowe… M Files Server 24.8.13981.13 / 24.11+ Fix from $2,3002024-11-20 MEDIUM 5.4 CVE-2024-9174 Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI Hubshare 5.0.8.6+ Fix from $1,6002024-10-02 MEDIUM 6.5 CVE-2024-6789 A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authen… M Files Server 24.2.13421.15 / 24.8.13981.0+ Fix from $1,6002024-08-27 MEDIUM 5.4 CVE-2024-6124 Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's brows… Hubshare 5.0.6.0+ Fix from $1,6002024-07-29 MEDIUM 5.4 CVE-2024-6881 Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session Hubshare 5.0.6.0+ Fix from $1,6002024-07-29 MEDIUM 5.4 CVE-2024-5142 Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in… Hubshare 5.0.6.0+ Fix from $1,6002024-05-24 HIGH 7.5 CVE-2024-4056 Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to con… M Files Server 24.4.13592+ Fix from $1,9502024-04-26 MEDIUM 5.4 CVE-2023-4479 Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limit… M Files 23.8+ Fix from $1,6002024-03-04 MEDIUM 6.5 CVE-2024-0563 Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of serv… M Files Server 23.2.12340.6 / 23.8.12892.6+ Fix from $1,6002024-02-23 CRITICAL 9.8 CVE-2023-6912 Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potential… M Files Server 23.12.13205.0+ Fix from $2,3002023-12-20 MEDIUM 6.5 CVE-2023-6910 A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust serve… M Files Server 23.12.13195.0+ Fix from $1,6002023-12-20 HIGH 8.8 CVE-2023-6239 Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-… M Files Server 23.11.13168.7+ Fix from $1,9502023-11-28 HIGH 7.5 CVE-2023-6117 A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of the M-Files server … M Files Server after 23.11.13156.0 Fix from $1,9502023-11-22 MEDIUM 5.3 CVE-2023-6189 Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export jobs using the M-Fil… M Files Server 23.11.13156.0+ Fix from $1,6002023-11-22 HIGH 7.8 CVE-2023-5523 Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allow… Web Companion 23.8 / 23.10+ Fix from $1,9502023-10-20 HIGH 7.3 CVE-2023-5524 Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote … Web Companion 23.8 / 23.10+ Fix from $1,9502023-10-20 MEDIUM 5.4 CVE-2023-2325 Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows att… Classic Web 23.10+ Fix from $1,6002023-10-20 MEDIUM 6.5 CVE-2023-3406 Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated use… Classic Web 23.2 / 23.6.12695.3+ Fix from $1,6002023-08-25 MEDIUM 5.3 CVE-2023-3425 Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated us… Classic Web 23.2 / 23.6.12695.3+ Fix from $1,6002023-08-25 HIGH 7.5 CVE-2023-3405 Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of s… M Files Server 23.6.12695.3+ Fix from $1,9502023-06-27 HIGH 7.8 CVE-2023-2480 Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension… M Files 23.5.12598.0+ Fix from $1,9502023-05-25 HIGH 7.8 CVE-2023-2112 Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0. M Files Server 23.4.12455.0+ Fix from $1,9502023-04-20