m-files CVE Vulnerabilities & Metrics

Focus on m-files vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About m-files Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with m-files. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total m-files CVEs: 34
Earliest CVE date: 18 Jan 2022, 17:15 UTC
Latest CVE date: 27 Aug 2024, 10:15 UTC

Latest CVE reference: CVE-2024-6789

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 3

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -82.35%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -82.35%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical m-files CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.32

Max CVSS: 5.0

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 32
4.0-6.9 2
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS m-files CVEs

These are the five CVEs with the highest CVSS scores for m-files, sorted by severity first and recency.

All CVEs for m-files

CVE-2024-6789 m-files vulnerability CVSS: 0 27 Aug 2024, 10:15 UTC

A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files

CVE-2024-6881 m-files vulnerability CVSS: 0 29 Jul 2024, 13:15 UTC

Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session

CVE-2024-6124 m-files vulnerability CVSS: 0 29 Jul 2024, 13:15 UTC

Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session

CVE-2023-6912 m-files vulnerability CVSS: 0 20 Dec 2023, 10:15 UTC

Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.

CVE-2023-6910 m-files vulnerability CVSS: 0 20 Dec 2023, 10:15 UTC

A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust server storage space to a point where the server can no longer serve requests.

CVE-2023-6239 m-files vulnerability CVSS: 0 28 Nov 2023, 14:15 UTC

Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.

CVE-2023-6189 m-files vulnerability CVSS: 0 22 Nov 2023, 10:15 UTC

Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export jobs using the M-Files API methods.

CVE-2023-6117 m-files vulnerability CVSS: 0 22 Nov 2023, 10:15 UTC

A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of the M-Files server before 23.11.13156.0 which allows attackers to execute DoS attacks.

CVE-2023-5524 m-files vulnerability CVSS: 0 20 Oct 2023, 07:15 UTC

Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types

CVE-2023-5523 m-files vulnerability CVSS: 0 20 Oct 2023, 07:15 UTC

Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution

CVE-2023-2325 m-files vulnerability CVSS: 0 20 Oct 2023, 07:15 UTC

Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document.

CVE-2023-3425 m-files vulnerability CVSS: 0 25 Aug 2023, 09:15 UTC

Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.

CVE-2023-3406 m-files vulnerability CVSS: 0 25 Aug 2023, 09:15 UTC

Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server

CVE-2023-3405 m-files vulnerability CVSS: 0 27 Jun 2023, 15:15 UTC

Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service

CVE-2023-2480 m-files vulnerability CVSS: 0 25 May 2023, 14:15 UTC

Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications

CVE-2023-2112 m-files vulnerability CVSS: 0 20 Apr 2023, 09:15 UTC

Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.

CVE-2023-0384 m-files vulnerability CVSS: 0 20 Apr 2023, 09:15 UTC

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption for a scheduled job.

CVE-2023-0383 m-files vulnerability CVSS: 0 20 Apr 2023, 09:15 UTC

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.

CVE-2023-0382 m-files vulnerability CVSS: 0 05 Apr 2023, 07:15 UTC

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.

CVE-2023-0213 m-files vulnerability CVSS: 0 29 Mar 2023, 11:15 UTC

Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking.

CVE-2022-4862 m-files vulnerability CVSS: 0 06 Mar 2023, 11:15 UTC

Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows the content to steal user sensitive information. This issue affects M-Files New Web: before 22.12.12140.3.

CVE-2022-3284 m-files vulnerability CVSS: 0 06 Mar 2023, 11:15 UTC

Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0.

CVE-2022-4858 m-files vulnerability CVSS: 0 30 Dec 2022, 12:15 UTC

Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.

CVE-2022-4264 m-files vulnerability CVSS: 0 09 Dec 2022, 15:15 UTC

Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.

CVE-2022-4270 m-files vulnerability CVSS: 0 02 Dec 2022, 13:15 UTC

Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally.

CVE-2022-1911 m-files vulnerability CVSS: 0 30 Nov 2022, 15:15 UTC

Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.

CVE-2022-1606 m-files vulnerability CVSS: 0 30 Nov 2022, 15:15 UTC

Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.

CVE-2022-39019 m-files vulnerability CVSS: 0 31 Oct 2022, 21:15 UTC

Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server.

CVE-2022-39018 m-files vulnerability CVSS: 0 31 Oct 2022, 21:15 UTC

Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.

CVE-2022-39017 m-files vulnerability CVSS: 0 31 Oct 2022, 21:15 UTC

Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.

CVE-2022-39016 m-files vulnerability CVSS: 0 31 Oct 2022, 21:15 UTC

Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload.

CVE-2021-41809 m-files vulnerability CVSS: 4.0 18 Jan 2022, 17:15 UTC

SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.

CVE-2021-41808 m-files vulnerability CVSS: 1.9 18 Jan 2022, 17:15 UTC

In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.

CVE-2021-41807 m-files vulnerability CVSS: 5.0 18 Jan 2022, 17:15 UTC

Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.