Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

M-Files Server — Vulnerabilities & Security Advisories 34

All 34 CVE vulnerabilities found in M-Files Server, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known security weaknesses for the M-Files Server software provided by M-Files Corporation. It serves as a centralized resource for identifying and analyzing vulnerabilities within this specific enterprise content management platform, focusing on common weakness classifications such as injection flaws, improper access control, and security misconfigurations. The collection includes documented vulnerabilities discovered and reported over the past several years, providing a historical perspective on the product’s security posture. By aggregating data from various sources, including vendor advisories, security research blogs, and public disclosure databases, this page offers a comprehensive view of the threat landscape associated with M-Files Server installations. It aims to assist security professionals, system administrators, and auditors in assessing the risk exposure of their environments. Visitors to this page can track the progression of advisories issued by the vendor over time, helping to contextualize the severity and remediation timelines of reported issues. Users can also examine specific vulnerability classes to understand the underlying technical flaws that may affect this software, facilitating a deeper comprehension of potential attack vectors. Additionally, the resource allows for a lookup of the product’s vulnerability history, enabling stakeholders to identify recurring issues or persistent weaknesses that may have been addressed or remain unresolved in specific versions. This structured approach supports informed decision-making regarding patching strategies and mitigation efforts without requiring manual cross-referencing of disparate sources. The information presented is intended to support proactive security management and compliance verification for organizations relying on M-Files Server infrastructure.

Vendor: M-Files

CVE IDTitleCVSSSeverityPublished
CVE-2026-0983 Denial of service vulnerability in M-Files Server CWE-1286--2026-05-18
CVE-2026-0932 M-Files Server 安全漏洞 CWE-918 8.2AIHighAI2026-04-01
CVE-2026-0663 Denial of Service condition in M-Files Server CWE-1286 4.9AIMediumAI2026-01-21
CVE-2025-13008 Session Token Disclosure in M-Files Web CWE-359 6.5AIMediumAI2025-12-19
CVE-2025-14267 Unintended temporary cached data included in a structure only copy intended to be empty of data CWE-212 6.5AIMediumAI2025-12-19
CVE-2025-14318 Improper access validation in M-Files Server CWE-863 6.5AIMediumAI2025-12-18
CVE-2025-11681 Denial of Service condition in M-Files Server CWE-400 6.5AIMediumAI2025-11-17
CVE-2025-5964 Path traversal in M-Files API CWE-22 6.5AIMediumAI2025-06-15
CVE-2025-3086 User in anonymous role could create and delete views CWE-653 7.1AIHighAI2025-04-04
CVE-2025-0635 Denial of Service condition in M-Files Server CWE-770 7.5 -2025-01-23
CVE-2025-0619 Unsafe stored password recovery CWE-522 4.9 -2025-01-23
CVE-2025-0648 M-Files Server crash via EOT database driver configuration CWE-248 4.9 -2025-01-23
CVE-2024-10126 Local file inclusion vulnerability in M-Files Server CWE-552 4.3AIMediumAI2024-11-20
CVE-2024-10127 Support for authentication bypass condition in M-Files LDAP authentication CWE-303 8.1AIHighAI2024-11-20
CVE-2024-6789 Path traversal in M-Files API CWE-22 6.5AIMediumAI2024-08-27
CVE-2024-4056 Denial of service condition in M-Files Server CWE-1333 7.5 High2024-04-26
CVE-2024-0563 Denial of service condition in M-Files Server CWE-770 4.3 Medium2024-02-23
CVE-2023-6910 Uncontrolled Resource Consumption in M-Files Server CWE-770 6.5 Medium2023-12-20
CVE-2023-6912 Brute force vulnerability in M-Files user authentication CWE-307 7.5 High2023-12-20
CVE-2023-6239 Incorrect calculation of effective permissions CWE-281 5.4 Medium2023-11-28
CVE-2023-6189 Improper Permission Handling in M-Files Server CWE-280 4.3 Medium2023-11-22
CVE-2023-6117 M-Files REST API allows Denial of Service CWE-770 5.7 Medium2023-11-22
CVE-2023-3425 CVE-2023-3425: Out-of-Bounds memory read CWE-125 6.5 Medium2023-08-25
CVE-2023-3405 Denial of service condition in M-Files Server CWE-248 7.5 High2023-06-27
CVE-2023-0384 Uncontrolled Resource Consuption in M-Files Server CWE-400 6.5 Medium2023-04-20
CVE-2023-0383 Uncontrolled Resource Consuption in M-Files Server CWE-770 7.5 High2023-04-20
CVE-2023-0382 Uncontrolled Resource Consumption in M-Files Server CWE-770 6.5 Medium2023-04-05
CVE-2022-4858 Insertion of Sensitive Information into Log File CWE-532 4.4 Medium2022-12-30
CVE-2022-1911 Information disclosure in M-Files Server CWE-200 5.3 Medium2022-11-30
CVE-2022-1606 Incorrect privilege assignment in M-Files Server CWE-269 2.4 Low2022-11-30

All 34 known CVE vulnerabilities affecting M-Files Server with full Chinese analysis, references, and POCs where available.