VendorsM-filesm-files_serverany version
Vulnerabilities

M-files M-files Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

34CVEs
CVE-2021-41807
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0, allows brute-forcing of certain type of user accounts.
Published 2022-01-18 · Modified
9.8EPSS 0.011
CVE-2023-6912
Brute force vulnerability in M-Files user authentication
Published 2023-12-20 · Modified
9.8EPSS 0.010
CVE-2024-10127
Support for authentication bypass condition in M-Files LDAP authentication
Published 2024-11-20 · Modified
9.8EPSS 0.006
CVE-2023-6239
Incorrect calculation of effective permissions
Published 2023-11-28 · Modified
8.8EPSS 0.006
CVE-2025-5964
Path traversal in M-Files API
Published 2025-06-15 · Modified
8.4EPSS 0.127
CVE-2024-6789
Path traversal in M-Files API
Published 2024-08-27 · Modified
8.4EPSS 0.006
CVE-2023-2112
Desktop component allows lateral movement between sessions
Published 2023-04-20 · Modified
7.8EPSS 0.002
CVE-2022-4862
XSS vulnerability in M-Files Web
Published 2023-03-06 · Modified
7.6EPSS 0.004
CVE-2023-0383
Uncontrolled Resource Consuption in M-Files Server
Published 2023-04-20 · Modified
7.5EPSS 0.008
CVE-2023-3405
Denial of service condition in M-Files Server
Published 2023-06-27 · Modified
7.5EPSS 0.008
CVE-2023-0384
Uncontrolled Resource Consuption in M-Files Server
Published 2023-04-20 · Modified
7.5EPSS 0.008
CVE-2024-4056
Denial of service condition in M-Files Server
Published 2024-04-26 · Modified
7.5EPSS 0.008
CVE-2023-6117
M-Files REST API allows Denial of Service
Published 2023-11-22 · Modified
7.5EPSS 0.007
CVE-2022-3284
Insecure way of passing a download key
Published 2023-03-06 · Modified
7.5EPSS 0.007
CVE-2025-0635
Denial of Service condition in M-Files Server
Published 2025-01-23 · Modified
7.5EPSS 0.005
CVE-2022-4858
Insertion of Sensitive Information into Log File
Published 2022-12-30 · Modified
7.5EPSS 0.005
CVE-2026-0932
Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacker to cause the server to send HTTP GET requests to arbitrary URLs.
Published 2026-04-01 · Analyzed
7.3EPSS 0.002
CVE-2025-3086
User in anonymous role could create and delete views
Published 2025-04-04 · Modified
7.1EPSS 0.004
CVE-2025-11681
Denial of Service condition in M-Files Server
Published 2025-11-17 · Modified
7.1EPSS 0.004
CVE-2026-0663
Denial of Service condition in M-Files Server
Published 2026-01-21 · Modified
6.9EPSS 0.004
CVE-2023-6910
Uncontrolled Resource Consumption in M-Files Server
Published 2023-12-20 · Modified
6.5EPSS 0.009
CVE-2023-0382
Uncontrolled Resource Consumption in M-Files Server
Published 2023-04-05 · Modified
6.5EPSS 0.008
CVE-2024-0563
Denial of service condition in M-Files Server
Published 2024-02-23 · Modified
6.5EPSS 0.007
CVE-2025-0648
M-Files Server crash via EOT database driver configuration
Published 2025-01-23 · Modified
5.9EPSS 0.005
CVE-2025-14267
Unintended temporary cached data included in a structure only copy intended to be empty of data
Published 2025-12-19 · Modified
5.6EPSS 0.004
CVE-2022-1911
Information disclosure in M-Files Server
Published 2022-11-30 · Modified
5.3EPSS 0.006
CVE-2023-6189
Improper Permission Handling in M-Files Server
Published 2023-11-22 · Modified
5.3EPSS 0.005
CVE-2024-10126
Local file inclusion vulnerability in M-Files Server
Published 2024-11-20 · Modified
5.3EPSS 0.004
CVE-2025-14318
Improper access validation in M-Files Server
Published 2025-12-18 · Modified
5.3EPSS 0.003
CVE-2025-0619
Unsafe stored password recovery
Published 2025-01-23 · Modified
4.9EPSS 0.004
CVE-2021-41809
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, allows requests from server.
Published 2022-01-18 · Modified
4.3EPSS 0.006
CVE-2022-1606
Incorrect privilege assignment in M-Files Server
Published 2022-11-30 · Modified
4.3EPSS 0.005
CVE-2022-4270
Incorrect privilege assignment in M-Files Web Server
Published 2022-12-02 · Modified
2.6EPSS 0.005
CVE-2021-41808
In M-Files Server product with versions before 21.11.10775.0, enabling logging of federated authentication would write sensitive information to event logs.
Published 2022-01-18 · Modified
2.3EPSS 0.002