← Back

Hubshare

hubshare

Vendor: M Files • 9 CVEs

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1M Files
1Hubshare
Feb 23, 2026
Sep 15, 2025
7.0 HIGH· v4
5.4 MEDIUM· v3
N/A· v2
Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to cause script execution for other users.
1M Files
1Hubshare
Feb 23, 2026
Oct 2, 2024
6.9 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI
1M Files
1Hubshare
Feb 23, 2026
Jul 29, 2024
8.5 HIGH· v4
5.4 MEDIUM· v3
N/A· v2
Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session
1M Files
1Hubshare
Feb 23, 2026
Jul 29, 2024
8.5 HIGH· v4
5.4 MEDIUM· v3
N/A· v2
Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session
1M Files
1Hubshare
Feb 23, 2026
May 24, 2024
7.0 HIGH· v4
5.4 MEDIUM· v3
N/A· v2
Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browser
1M Files
1Hubshare
Nov 21, 2024
Oct 31, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server.
1M Files
1Hubshare
Nov 21, 2024
Oct 31, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.
1M Files
1Hubshare
Nov 21, 2024
Oct 31, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.
1M Files
1Hubshare
Nov 21, 2024
Oct 31, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload.