VendorsM-filesm-files_webany version
Vulnerabilities

M-files M-Files Web any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-41807
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0, allows brute-forcing of certain type of user accounts.
Published 2022-01-18 · Modified
9.8EPSS 0.011
CVE-2021-37253
M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of the web server, not the responsibility of the individual web application
Published 2021-12-05 · Modified
7.8EPSS 0.028
CVE-2021-37254
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.
Published 2021-10-28 · Modified
7.5EPSS 0.013
CVE-2025-3087
Stored XSS Vulnerability in M-Files Web
Published 2025-04-04 · Modified
5.4EPSS 0.003