← Back

M Files Server

m-files_server

Vendor: M Files • 34 CVEs

CVEs (34)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1M Files
1M Files Server
Jun 17, 2026
Jun 27, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service
1M Files
1M Files Server
Jun 17, 2026
Apr 20, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
1M Files
1M Files Server
Jun 17, 2026
Apr 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption for a scheduled job.
1M Files
1M Files Server
Jun 17, 2026
Apr 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.
1M Files
1M Files Server
Jun 17, 2026
Apr 5, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.
1M Files
1M Files Server
Jun 17, 2026
Mar 6, 2023
N/A· v4
7.6 HIGH· v3
N/A· v2
Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows the content to steal user sensitive information. This issue affects M-Files New Web: bef...Show more
Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows the content to steal user sensitive information. This issue affects M-Files New Web: before 22.12.12140.3.Show less
1M Files
1M Files Server
Jun 17, 2026
Mar 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0.
1M Files
1M Files Server
Jun 17, 2026
Dec 30, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.
1M Files
1M Files Server
Jun 17, 2026
Dec 2, 2022
N/A· v4
2.6 LOW· v3
N/A· v2
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally.
1M Files
1M Files Server
Jun 17, 2026
Nov 30, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.
1M Files
1M Files Server
Jun 17, 2026
Nov 30, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.
1M Files
1M Files Server
Jun 17, 2026
Jan 18, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.
1M Files
1M Files Server
Jun 17, 2026
Jan 18, 2022
N/A· v4
2.3 LOW· v3
1.9 LOW· v2
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
1M Files
2M Files Server
M Files Web
Jun 17, 2026
Jan 18, 2022
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts ea...Show more
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.Show less