← Back

M Files

m-files

58 CVEs • 9 products

Products (9)

Click to collapse
Toggle
Hubshare
hubshare
M Files Web
m-files_web
M Files
m-files
Classic Web
classic_web
Web Companion
web_companion
Server
server
M Files Client
m-files_client
M Files Mobile
m-files_mobile

CVEs (58)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1M Files
1M Files Server
Jun 17, 2026
Mar 6, 2023
N/A· v4
7.6 HIGH· v3
N/A· v2
Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows the content to steal user sensitive information. This issue affects M-Files New Web: bef...Show more
Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows the content to steal user sensitive information. This issue affects M-Files New Web: before 22.12.12140.3.Show less
1M Files
1M Files Server
Jun 17, 2026
Mar 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0.
1M Files
1M Files Client
Jun 17, 2026
Dec 30, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource.
1M Files
1M Files Server
Jun 17, 2026
Dec 30, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.
1M Files
1M Files
Jun 17, 2026
Dec 9, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.
1M Files
1M Files Server
Jun 17, 2026
Dec 2, 2022
N/A· v4
2.6 LOW· v3
N/A· v2
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally.
1M Files
1M Files Server
Jun 17, 2026
Nov 30, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.
1M Files
1M Files Server
Jun 17, 2026
Nov 30, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.
1M Files
1Hubshare
Jun 17, 2026
Oct 31, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server.
1M Files
1Hubshare
Jun 17, 2026
Oct 31, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.
1M Files
1Hubshare
Jun 17, 2026
Oct 31, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.
1M Files
1Hubshare
Jun 17, 2026
Oct 31, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload.
1M Files
1Server
Jun 17, 2026
May 2, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Admin tool allows storing configuration data with script which may then get run by another vault admin...Show more
Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitableShow less
1M Files
1M Files Server
Jun 17, 2026
Jan 18, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.
1M Files
1M Files Server
Jun 17, 2026
Jan 18, 2022
N/A· v4
2.3 LOW· v3
1.9 LOW· v2
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
1M Files
2M Files Server
M Files Web
Jun 17, 2026
Jan 18, 2022
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts ea...Show more
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.Show less
1M Files
1M Files Web
Jun 17, 2026
Dec 5, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of...Show more
M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of the web server, not the responsibility of the individual web applicationShow less
1M Files
1M Files Web
Jun 17, 2026
Oct 28, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.