M-Files Web
M-Files · 9 CVEs
CSS injection in M-Files Web
Aug 19, 2026
HTML injection in M-Files Web
Aug 19, 2026
Stored XSS Vulnerability in M-Files Web
Apr 4, 2025
Stored XSS Vulnerability in M-Files Web
Mar 4, 2024
Stored XSS Vulnerability in M-Files Classic Web
Oct 20, 2023
Path traversal issue in M-Files Classic Web
Aug 25, 2023
Incorrect privilege assignment in M-Files Web Server
Dec 9, 2022
Incorrect privilege assignment in M-Files Web Server
Dec 2, 2022
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0, allows brute-forci…
Jan 18, 2022
M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range…
Dec 5, 2021
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain…
Oct 28, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-18372 | CSS injection in M-Files Web | MEDIUM | 0.43% | Aug 19, 2026 |
| CVE-2026-18371 | HTML injection in M-Files Web | MEDIUM | 0.40% | Aug 19, 2026 |
| CVE-2025-3087 | Stored XSS Vulnerability in M-Files Web | MEDIUM | 0.27% | Apr 4, 2025 |
| CVE-2023-4479 | Stored XSS Vulnerability in M-Files Web | HIGH | 0.44% | Mar 4, 2024 |
| CVE-2023-2325 | Stored XSS Vulnerability in M-Files Classic Web | HIGH | 0.43% | Oct 20, 2023 |
| CVE-2023-3406 | Path traversal issue in M-Files Classic Web | HIGH | 0.74% | Aug 25, 2023 |
| CVE-2022-4264 | Incorrect privilege assignment in M-Files Web Server | MEDIUM | 0.53% | Dec 9, 2022 |
| CVE-2022-4270 | Incorrect privilege assignment in M-Files Web Server | LOW | 0.55% | Dec 2, 2022 |
| CVE-2021-41807 | Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0, allows brute-forcing of certain type of user accounts. | CRITICAL | 1.11% | Jan 18, 2022 |
| CVE-2021-37253 | M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is… | HIGH | 2.93% | Dec 5, 2021 |
| CVE-2021-37254 | In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party com… | HIGH | 1.34% | Oct 28, 2021 |
Showing 1 to 9 of 9 CVEs