CVE Tools

M-files

15 CVEs tracked since 2022. Since Jan 2022, none of them reached CISA KEV.

M-files CVEs per month

Jan 2022 to Apr 2023. Point at a month, or focus the strip and use the arrow keys.
M-files CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-0130
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-1040
2022-11null or fewer
2022-1240
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-0440

Products

The products that kept showing up in M-files's monthly top three, with their CVEs summed over those months.

  1. M-files Server93 months
  2. Hubshare41 month
  3. M-files Web32 months
  4. M-files Client11 month
  5. M-files Desktop11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting M-files.

  1. CVE-2026-0932Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacker to cause the se...7.3
  2. CVE-2026-0663Denial of Service condition in M-Files Server4.9
  3. CVE-2025-14267Unintended temporary cached data included in a structure only copy intended to be empty of data4.9
  4. CVE-2025-14318Improper access validation in M-Files Server4.3
  5. CVE-2025-11681Denial of Service condition in M-Files Server6.5
  6. CVE-2025-9826Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to cause script execution for other users.5.4
  7. CVE-2025-2091Open redirection in M-Files Mobile5.4
  8. CVE-2025-5964Path traversal in M-Files API6.5
  9. CVE-2025-3087Stored XSS Vulnerability in M-Files Web5.4
  10. CVE-2025-3086User in anonymous role could create and delete views7.1
  11. CVE-2025-0635Denial of Service condition in M-Files Server7.5
  12. CVE-2025-0619Unsafe stored password recovery4.9
  13. CVE-2025-0648M-Files Server crash via EOT database driver configuration4.9
  14. CVE-2024-10126Local file inclusion vulnerability in M-Files Server4.3
  15. CVE-2024-10127Support for authentication bypass condition in M-Files LDAP authentication9.8

The record

Peak rank
#129 in Dec 2022
Busiest month shown
Oct 2022, 4 CVEs
Months with a KEV entry
0 since Jan 2022
Monthly snapshots
4 since 2022
M-files's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store