← Back

M Files

m-files

Vendor: M Files • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1M Files
1M Files
Feb 23, 2026
Mar 4, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.
1M Files
1M Files
Feb 23, 2026
May 25, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
1M Files
1M Files
Feb 23, 2026
Mar 29, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking.
1M Files
1M Files
Feb 23, 2026
Dec 9, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.