Security Advisories
Detailed information on public vulnerabilities in M-Files products. Additional M-Files security related information available in M-Files Trust Center.
2026
| CVE ID | Date issued | Title | CVSS | Products |
|---|---|---|---|---|
| CVE-2026-0932 | 2026-04-01 | SSRF Vulnerability in M-Files Server | 6.9 | M-Files Server before 26.3.15818.5 |
| CVE-2026-0663 | 2026-01-21 | Denial of Service Condition in M-Files Server | 6.9 | M-Files Server before 26.1.15632.3 |
2025
| CVE ID | Date issued | Title | CVSS | Products |
|---|---|---|---|---|
| CVE-2025-13008 | 2025-12-19 | Session Token Disclosure in M-Files Web | 8.6 | M-Files Server before 25.12.15491.7 M-Files Server before LTS 25.8 SR3 (25.8.15085.18) M-Files Server before LTS 25.2 SR3 (25.2.14524.14) M-Files Server before LTS 24.8 SR5 (24.8.13981.17) |
| CVE-2025-14267 | 2025-12-18 | Unintended temporary cached data included in a structure only copy intended to be empty of data | 5,6 | M-Files Server before 25.12.15491.7 |
| CVE-2025-14318 | 2025-12-18 | Improper access validation in M-Files Server | 5.3 | M-Files Server before 25.12.15491.7 |
| CVE-2025-11681 | 2025-11-17 | Denial of Service condition in M-Files Server | 7.1 | M-Files Server before 25.11.15392.1 M-Files Server before 25.2 LTS SR2 (25.2.14524.13) M-Files Server before 25.8 LTS SR2 (25.8.15085.17) |
| CVE-2025-9826 | 2025-09-15 | Stored XSS in M-Files Hubshare | 7.0 | M-Files Hubshare before Aug ’25 (25.8) |
| CVE-2025-2091 | 2025-06-16 | Open Redirection in M-Files Mobile | 4.8 | M-Files Mobile iOS and Android applications before 25.6.0 |
| CVE-2025-5964 | 2025-06-16 | Path traversal in M-Files API | 8.4 | M-Files Server before 25.6.14925.0 M-Files Server before 25.2 LTS SR1 (25.2.14524.9) M-Files Server before 24.8 LTS SR4 (24.8.13981.16) |
| CVE-2025-3086 | 2025-04-04 | User in anonymous role could create and delete views | 6.3 | M-Files Server before 25.3.14549 |
| CVE-2025-3087 | 2025-04-04 | XSS Vulnerability in M-Files Web | 5.1 | M-Files Web versions 25.1.14445.5 and 25.2.14524.4 |
| CVE-2025-2159 | 2025-04-04 | Stored XSS in M-Files Admin user interface | 5.1 | M-Files Admin tool before 25.3.14681.7 |
| CVE-2025-0635 | 2025-01-23 | Denial of Service condition in M-Files Server | 6.3 | M-Files Server before 25.1.14445.5 |
| CVE-2025-0648 | 2025-01-23 | M-Files Server crash via EOT database driver configuration | 5.9 | M-Files Server before 25.1.14445.5 M-Files Server before 24.8 LTS SR3 (24.8.13981.14) |
| CVE-2025-0619 | 2025-01-23 | Unsafe stored password recovery | 4.6 | M-Files Server before 25.1.14445.5 |
2024
| CVE ID | Date issued | Title | CVSS | Products |
|---|---|---|---|---|
| CVE-2024-10126 | 2024-11-20 | Local file inclusion vulnerability in M-Files Server | 5.3 | M-Files Server before 24.11 M-Files Server before 23.8 LTS SR7 M-Files Server before 24.2 LTS SR3 M-Files Server before 24.8 LTS SR1 |
| CVE-2024-10127 | 2024-11-20 | Support for authentication bypass condition in M-Files LDAP authentication | 9.2 | M-Files Server before 24.11 M-Files Server before 24.8 LTS SR2 (24.8.13981.13) |
| CVE-2024-11176 | 2024-11-20 | Incorrect evaluation of effective permissions in M-Files Aino | 5.3 | M-Files Aino before 24.10 |
| CVE-2024-9174 | 2024-10-02 | Stored HTML Injection in Hubshare Social module | 6.9 | M-Files Hubshare before 5.0.8.6 |
| CVE-2024-9333 | 2024-10-02 | Permission bypass in M-Files Connector for Copilot | 5.3 | M-Files Connector for Copilot before 24.9.3 |
| CVE-2024-6789 | 2024-08-27 | Path traversal in M-Files API | 8.4 | M-Files Server before 24.8.13981.0 M-Files Server before 24.2 LTS SR2 (24.2.13421.15) M-Files Server before 23.8 LTS SR6 (23.8.12892.0) |
| CVE-2024-6881 | 2024-07-29 | Stored XSS Vulnerability | 8.5 | M-Files Hubshare before 5.0.6.0 |
| CVE-2024-6124 | 2024-07-29 | Reflected XSS in Hubshare via Open Redirect | 8.5 | M-Files Hubshare before 5.0.6.0 |
| CVE-2024-4056 | 2024-04-26 | Denial of Service condition in M-Files Server | 7.5 | M-Files Server before 24.4.13592.4 and after 23.11 M-Files Server not affected at 24.2 LTS |
| CVE-2024-5142 | 2024-04-26 | XSS Vulnerability in Hubshare | 7.0 | M-Files Hubshare before 5.0.6.0 |
| CVE-2023-4479 | 2024-03-04 | Stored XSS Vulnerability in M-Files Web | 7.3 | M-Files Web before 23.8 |
| CVE-2024-0563 | 2024-02-23 | Denial of service condition in M-Files Server | 4.3 | M-Files Server before 24.2 M-Files Server before 23.2 LTS SR7 M-Files Server before 23.8 LTS SR5 |
2023
| CVE ID | Date issued | Title | CVSS | Products |
|---|---|---|---|---|
| CVE-2023-6912 | 2023-12-19 | Brute force vulnerability in M-Files user authentication | 7.5 | M-Files Server before 23.12.13205.0 M-Files Server before 23.2 LTS SR6 (this service release is not affected) M-Files Server before 23.8 LTS SR4 (this service release is not affected) |
| CVE-2023-6910 | 2023-12-18 | Uncontrolled Resource Consumption in M-Files Server | 6.5 | M-Files Server before 23.12.13195.0 M-Files Server before 23.2 LTS SR6 (this service release is not affected) M-Files Server before 23.8 LTS SR4 (this service release is not affected) |
| CVE-2023-6117 | 2023-11-22 | M-Files REST API allows Denial of Service | 5.7 | M-Files Server before 23.11.13156.0 |
| CVE-2023-6189 | 2023-11-22 | Elevation of Privilege in M-Files Server | 4.3 | M-Files Server before 23.11.13156.0 |
| CVE-2023-6239 | 2023-11-21 | Incorrect calculation of effective permissions | 5.4 | M-Files Server 23.9 M-Files Server 23.10 M-Files Server 23.11 versions prior to 23.11.13168.7 |
| CVE-2023-2325 | 2023-10-20 | Stored XSS Vulnerability in M-Files Classic Web | 7.3 | M-Files Server before 23.10 M-Files Server before 23.2 LTS SR4 (this service release is not affected) M-Files Server before 23.8 LTS SR1 (this service release is not affected) |
| CVE-2023-5524 | 2023-10-20 | M-Files Web Companion allowed Remote Code Execution for some filetypes | 8.2 | M-Files Web Companion before 23.10 M-Files Web Companion before 23.8 LTS SR1 |
| CVE-2023-5523 | 2023-10-20 | M-Files Web Companion allows Remote Code Execution | 8.6 | M-Files Web Companion before 23.10 M-Files Web Companion before 23.8 LTS SR1 |
| CVE-2023-3406 | 2023-08-25 | Path traversal issue in M-Files Classic Web | 7.7 | M-Files Classic Web before 23.6.12695.3 M-Files Classic Web before 23.2 LTS SR3 |
| CVE-2023-3405 | 2023-06-28 | Denial of service in M-Files Server | 7.5 | M-Files Server before 23.6.12695.3 (excluding 23.2 SR2 and newer) |
| CVE-2023-3425 | 2023-06-27 | Out-of-Bounds memory read in M-Files Server | 6.5 | M-Files Server before 23.8.12892.6 M-Files Server before 23.2 LTS SR3 |
| CVE-2023-2480 | 2023-05-25 | Elevation of Privilege in M-Files Desktop Client | 7.5 | M-Files Client before 23.5.12598.0 |
| CVE-2023-0383 | 2023-04-20 | Uncontrolled Resource Consumption in M-Files Server | 7.5 | M-Files Server before 23.4.12528.1 |
| CVE-2023-0384 | 2023-04-20 | Uncontrolled Resource Consumption in M-Files Server | 6.5 | M-Files Server before 23.4.12528.1 |
| CVE-2023-2112 | 2023-04-20 | Desktop Component allows lateral movement between sessions | 3.6 | M-Files Desktop before 23.4.12455.0 |
| CVE-2023-0382 | 2023-04-05 | Uncontrolled Resource Consumption in M-Files Server | 6.5 | M-Files Server before 23.4.12528.1 |
| CVE-2023-0213 | 2023-03-29 | Elevation of Privilege | 8.8 | M-Files version before 22.6. |
| CVE-2022-4862 | 2023-03-06 | XSS vulnerability in M-Files Web | 5.0 | M-Files Web before 22.12.12140.3. |
| CVE-2022-3284 | 2023-03-06 | Insecure way of passing a download key | 6.5 | M-Files New Web before 22.11.12011.0. |
2022
| CVE ID | Date issued | Title | CVSS | Products |
|---|---|---|---|---|
| CVE-2022-4861 | 2022-12-30 | Incorrect Implementation of Authentication Algorithm | 4.8 | M-Files Client before 22.5.11356.0. |
| CVE-2022-4858 | 2022-12-30 | Insertion of Sensitive Information into Log File | 4.4 | M-Files Server before 22.10.11846.0. |
| CVE-2022-4264 | 2022-12-09 | Incorrect privilege assignment | 6.5 | M-Files Web Classic version before 22.8.11691.0. |
| CVE-2022-4270 | 2022-12-02 | Incorrect privilege assignment | 2.0 | M-Files Web Classic version before 22.5.11436.1. M-Files Web vNext version before 22.5.11436.1. |
| CVE-2022-1606 | 2022-11-30 | Incorrect Privilege Assignment | 2.4 | All M-Files Server versions before 22.3.111.64.0 and before 22.3.11237.1. |
| CVE-2022-1911 | 2022-11-30 | Information disclosure in M-Files Server | 5.3 | M-Files Server before 22.6.11534.1 and before 22.6.11505.0. |
| CVE-2022-3602 | 2022-11-01 | OpenSSL 3.x Vulnerability and M-Files | 7.5 | M-Files Server/Desktop/Classic Web/VNEXT/Mobile |
| CVE-2022-39017 | 2022-08-20 | Avoid any XSS script execution from comments areas (social, document comment, form comment, etc) | 8.2 | Hubshare |
| CVE-2022-39019 | 2022-08-20 | Pdftron: add security layer to avoid the lack of authorisation check on rendered images from pdftron | 8.2 | Hubshare |
| CVE-2022-39018 | 2022-08-20 | Pdftron: add security layer to avoid the lack of authorisation check on rendered images from pdftron | 8.2 | Hubshare |
| CVE-2022-39016 | 2022-08-20 | Pdftron: avoid possible account takeover with XSS | 8.2 | Hubshare |
| CVE-2021-41810 | 2022-05-02 | Script injection in M-Files Admin | 5.2 | M-Files Admin before 22.2.11051.0 |
| CVE-2022-22965 | 2022-04-01 | Spring Framework RCE and M-Files | 9.8 | M-Files Server/Desktop/Classic Web/VNEXT/Mobile |
| CVE-2022-26809 | 2022-03-09 | Remote Procedure Call Runtime Remote Code Execution Vulnerability and M-Files | 9.8 | M-Files Server/Desktop/Classic Web/VNEXT/Mobile |
| CVE-2021-41809 | 2022-01-17 | SSRF Vulnerability | 3.5 | M-Files Server version before 22.1.11017.1 |
| CVE-2021-41808 | 2022-01-17 | Information disclosure | 2.0 | M-Files Server version before 21.11.10775.0 |
| CVE-2021-41807 | 2022-01-17 | Lack of rate limiting | 7.5 | M-Files Server version before 21.12.10873.0 M-Files Web version before 21.12.10873.0 |
2021
| CVE ID | Date issued | Title | CVSS | Products |
|---|---|---|---|---|
| CVE-2021-37253 | 2021-12-03 | Denial of Service | 7.5 | M-Files Classic Web |
| CVE-2021-37254 | 2021-10-27 | Information Disclosure Vulnerability | 7.5 | M-Files Web version before 20.10.9524.1 M-Files Web version before 20.10.9445.0 |
