Vulnerabilities (CVE)

Filtered by vendor M-files
Angry Yack Logo
Total 57 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41810 1 M-files 1 Server 2026-02-23 3.5 LOW 5.2 MEDIUM
Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable
CVE-2026-0663 1 M-files 1 M-files Server 2026-02-23 N/A 4.9 MEDIUM
Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vault administrator privileges to crash the M-Files Server process by calling a vulnerable API endpoint.
CVE-2025-9826 1 M-files 1 Hubshare 2026-02-23 N/A 5.4 MEDIUM
Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to cause script execution for other users.
CVE-2025-5964 1 M-files 1 M-files Server 2026-02-23 N/A 6.5 MEDIUM
A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.
CVE-2025-3087 1 M-files 1 M-files Web 2026-02-23 N/A 5.4 MEDIUM
Stored XSS in M-Files Web versions from 25.1.14445.5 to 25.2.14524.4 allows an authenticated user to run scripts
CVE-2025-3086 1 M-files 1 M-files Server 2026-02-23 N/A 7.1 HIGH
Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of service
CVE-2025-2091 1 M-files 1 M-files Mobile 2026-02-23 N/A 5.4 MEDIUM
An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making requests to untrusted URLs.
CVE-2025-14318 1 M-files 1 M-files Server 2026-02-23 N/A 4.3 MEDIUM
Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using Web Companion despite Print and Download Prevention module being enabled.
CVE-2025-14267 1 M-files 1 M-files Server 2026-02-23 N/A 4.9 MEDIUM
Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak exposure affecting versions before 25.12.15491.7
CVE-2025-11681 1 M-files 1 M-files Server 2026-02-23 N/A 6.5 MEDIUM
Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash.
CVE-2025-0648 1 M-files 1 M-files Server 2026-02-23 N/A 4.9 MEDIUM
Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highly privileged attacker to cause denial of service via configuration change.
CVE-2025-0635 1 M-files 1 M-files Server 2026-02-23 N/A 7.5 HIGH
Denial of service condition in M-Files Server in versions before 25.1.14445.5 allows an unauthenticated user to consume computing resources in certain conditions.
CVE-2025-0619 1 M-files 1 M-files Server 2026-02-23 N/A 4.9 MEDIUM
Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords
CVE-2024-9174 1 M-files 1 Hubshare 2026-02-23 N/A 5.4 MEDIUM
Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI
CVE-2024-6881 1 M-files 1 Hubshare 2026-02-23 N/A 5.4 MEDIUM
Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session
CVE-2024-6789 1 M-files 1 M-files Server 2026-02-23 N/A 6.5 MEDIUM
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
CVE-2024-6124 1 M-files 1 Hubshare 2026-02-23 N/A 5.4 MEDIUM
Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session
CVE-2024-5142 1 M-files 1 Hubshare 2026-02-23 N/A 5.4 MEDIUM
Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browser
CVE-2024-4056 1 M-files 1 M-files Server 2026-02-23 N/A 7.5 HIGH
Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources.
CVE-2024-10127 1 M-files 1 M-files Server 2026-02-23 N/A 9.8 CRITICAL
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.
CVE-2024-10126 1 M-files 1 M-files Server 2026-02-23 N/A 4.3 MEDIUM
Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read server local files of a limited set of filetypes via document preview.
CVE-2024-0563 1 M-files 1 M-files Server 2026-02-23 N/A 4.3 MEDIUM
Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of service against other anonymous users.
CVE-2023-6912 1 M-files 1 M-files Server 2026-02-23 N/A 7.5 HIGH
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.
CVE-2023-6910 1 M-files 1 M-files Server 2026-02-23 N/A 6.5 MEDIUM
A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust server storage space to a point where the server can no longer serve requests.
CVE-2023-6239 1 M-files 1 M-files Server 2026-02-23 N/A 5.4 MEDIUM
Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.
CVE-2023-6189 1 M-files 1 M-files Server 2026-02-23 N/A 4.3 MEDIUM
Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export jobs using the M-Files API methods.
CVE-2023-6117 1 M-files 1 M-files Server 2026-02-23 N/A 5.7 MEDIUM
A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of the M-Files server before 23.11.13156.0 which allows attackers to execute DoS attacks.
CVE-2023-5524 1 M-files 1 Web Companion 2026-02-23 N/A 8.2 HIGH
Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types
CVE-2023-5523 1 M-files 1 Web Companion 2026-02-23 N/A 8.6 HIGH
Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution
CVE-2023-4479 1 M-files 1 M-files 2026-02-23 N/A 7.3 HIGH
Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.
CVE-2023-3425 1 M-files 1 Classic Web 2026-02-23 N/A 6.5 MEDIUM
Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.
CVE-2023-3406 1 M-files 1 Classic Web 2026-02-23 N/A 7.7 HIGH
Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server
CVE-2023-3405 1 M-files 1 M-files Server 2026-02-23 N/A 7.5 HIGH
Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service
CVE-2023-2480 1 M-files 1 M-files 2026-02-23 N/A 7.5 HIGH
Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
CVE-2023-2325 1 M-files 1 Classic Web 2026-02-23 N/A 7.3 HIGH
Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document.
CVE-2023-2112 1 M-files 1 M-files Server 2026-02-23 N/A 3.6 LOW
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
CVE-2023-0384 1 M-files 1 M-files Server 2026-02-23 N/A 6.5 MEDIUM
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption for a scheduled job.
CVE-2023-0383 1 M-files 1 M-files Server 2026-02-23 N/A 7.5 HIGH
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.
CVE-2023-0382 1 M-files 1 M-files Server 2026-02-23 N/A 6.5 MEDIUM
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.
CVE-2023-0213 2 M-files, Microsoft 2 M-files, Windows 2026-02-23 N/A 8.8 HIGH
Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking.