M-files web
This hub aggregates every CVE we track for M-files web, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
9
CVEs tracked
0
Critical
6
High
0
In CISA KEV
Severity distribution
HIGH6MEDIUM2LOW1
Monthly trend
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 9 most recently published vulnerabilities affecting M-files web.
- CVE-2025-3087Stored XSS Vulnerability in M-Files Web5.4
- CVE-2023-4479Stored XSS Vulnerability in M-Files Web7.3
- CVE-2023-2325Stored XSS Vulnerability in M-Files Classic Web7.3
- CVE-2023-3406Path traversal issue in M-Files Classic Web7.7
- CVE-2022-4264Incorrect privilege assignment in M-Files Web Server6.5
- CVE-2022-4270Incorrect privilege assignment in M-Files Web Server2.0
- CVE-2021-41807Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0, allows brute-forcing of certain type of user accounts.7.5
- CVE-2021-37253M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior i...7.5
- CVE-2021-37254In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.7.5
Product normalization is registry-driven with AI assist and human review. How it works