CVE-2025-13008
- EPSS 0.06%
- Veröffentlicht 19.12.2025 07:15:58
- Zuletzt bearbeitet 23.02.2026 11:16:18
An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users.
CVE-2025-0619
- EPSS 0.24%
- Veröffentlicht 23.01.2025 11:15:10
- Zuletzt bearbeitet 23.02.2026 11:16:18
Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords
CVE-2024-10127
- EPSS 0.07%
- Veröffentlicht 20.11.2024 09:15:04
- Zuletzt bearbeitet 23.02.2026 11:16:16
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration...
CVE-2024-10126
- EPSS 0.17%
- Veröffentlicht 20.11.2024 09:15:03
- Zuletzt bearbeitet 23.02.2026 11:16:16
Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read server local files of a limited set of filetypes via document preview.
CVE-2023-4479
- EPSS 0.18%
- Veröffentlicht 04.03.2024 08:15:08
- Zuletzt bearbeitet 23.02.2026 09:16:15
Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.
CVE-2024-0563
- EPSS 0.12%
- Veröffentlicht 23.02.2024 09:15:22
- Zuletzt bearbeitet 23.02.2026 11:16:16
Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of service against other anonymous users.
CVE-2023-2480
- EPSS 0.05%
- Veröffentlicht 25.05.2023 14:15:10
- Zuletzt bearbeitet 23.02.2026 09:16:14
Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
CVE-2023-0213
- EPSS 0.03%
- Veröffentlicht 29.03.2023 11:15:07
- Zuletzt bearbeitet 23.02.2026 09:16:13
Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking.
CVE-2022-4264
- EPSS 0.2%
- Veröffentlicht 09.12.2022 15:15:10
- Zuletzt bearbeitet 23.02.2026 08:16:12
Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.