Home/Product/m files m files server
Product

m files m files server

35 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-0932
< 26.3.15818.5
Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files S
7.3HIGH
CVE-2026-0663
< 26.1.15632.3
Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vault admin
4.9MEDIUM
CVE-2025-14267
< 25.12.15491.7
Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak e
4.9MEDIUM
CVE-2025-14318
< 25.12.15491.7
Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using Web Compani
4.3MEDIUM
CVE-2025-11681
< 25.11.15392.1
Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an
6.5MEDIUM
CVE-2025-5964
>= 25.3.14681.7 and < 25.6.14925.0
A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read file
6.5MEDIUM
CVE-2025-3086
< 25.3.14549
Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users view
7.1HIGH
CVE-2025-0648
>= 24.9.14055.3 and < 25.1.14445.5
Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highly privileg
4.9MEDIUM
CVE-2025-0635
< 25.1.14445.5
Denial of service condition in M-Files Server in versions before 25.1.14445.5 allows an unauthenticated user to consume computin
7.5HIGH
CVE-2025-0619
< 25.1.14445.5
Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external conn
4.9MEDIUM
CVE-2024-10127
< 24.11
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configu
9.8CRITICAL
CVE-2024-10126
< 23.8.12892.6
Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows a
4.3MEDIUM
CVE-2024-6789
< 24.8.13981.0
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.1289
6.5MEDIUM
CVE-2024-4056
>= 23.11.13168.6 and < 24.4.13592
Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthe
7.5HIGH
CVE-2024-0563
< 23.2.12340.6
Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to
4.3MEDIUM
CVE-2023-6912
< 23.12.13205.0
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication
7.5HIGH
CVE-2023-6910
< 23.12.13195.0
A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacke
6.5MEDIUM
CVE-2023-6239
>= 23.11 and < 23.11.13168.7
Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configu
5.4MEDIUM
CVE-2023-6189
< 23.11.13156.0
Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export
4.3MEDIUM
CVE-2023-6117
<= 23.11.13156.0
A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of t
5.7MEDIUM
CVE-2023-3405
< 23.6.12695.3
Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user t
7.5HIGH
CVE-2023-2112
< 23.4.12455.0
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
3.6LOW
CVE-2023-0384
< 23.4.12528.1
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory
6.5MEDIUM
CVE-2023-0383
< 23.4.12528.1
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory
7.5HIGH
CVE-2023-0382
< 23.4.12528.1
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memor
6.5MEDIUM
CVE-2022-4862
< 22.12.12140.3
Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows t
5.0MEDIUM
CVE-2022-3284
< 22.11.12011.0
Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before
6.5MEDIUM
CVE-2022-4858
< 22.10.11846.0
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens fr
4.4MEDIUM
CVE-2022-4270
< 22.5.11436.1
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions ac
2.0LOW
CVE-2022-1911
< 22.6.11534.4
Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to
5.3MEDIUM
CVE-2022-1606
< 22.3.11237.3
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanage
2.4LOW
CVE-2021-41810
< 22.2.11051.0
Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Admin tool a
5.2MEDIUM
CVE-2021-41809
< 22.1.11017.1
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from
3.5LOW
CVE-2021-41808
< 21.11.10775.0
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sens
2.0LOW
CVE-2021-41807
< 21.12.10873.0
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accoun
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin