Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

M-Files — Vulnerabilities & Security Advisories 30

Browse all 30 CVE security advisories affecting M-Files. AI-powered Chinese analysis, POCs, and references for each vulnerability.

M-Files operates as an intelligent information management platform, utilizing metadata-driven architecture to organize and secure enterprise data across diverse repositories. Historically, its software has been associated with thirty recorded Common Vulnerabilities and Exposures, predominantly involving remote code execution, cross-site scripting, and privilege escalation flaws. These vulnerabilities often stem from insufficient input validation and improper access controls within the application’s web interface and API endpoints. While specific major public breaches linked directly to M-Files remain limited in public reporting, the recurring nature of these CVEs highlights persistent challenges in securing complex enterprise content management systems. The platform’s reliance on third-party components and custom integrations frequently introduces attack surfaces that require rigorous patching and configuration management. Security assessments indicate that timely updates and strict role-based access policies are critical for mitigating the identified risks associated with its extensive feature set.

Found 14 results / 30Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2023-6239 Incorrect calculation of effective permissions — M-Files ServerCWE-281 5.4 Medium2023-11-28
CVE-2023-6189 Improper Permission Handling in M-Files Server — M-Files ServerCWE-280 4.3 Medium2023-11-22
CVE-2023-6117 M-Files REST API allows Denial of Service — M-Files ServerCWE-770 5.7 Medium2023-11-22
CVE-2023-3425 CVE-2023-3425: Out-of-Bounds memory read — M-Files ServerCWE-125 6.5 Medium2023-08-25
CVE-2023-3405 Denial of service condition in M-Files Server — M-Files ServerCWE-248 7.5 High2023-06-27
CVE-2023-0384 Uncontrolled Resource Consuption in M-Files Server — M-Files ServerCWE-400 6.5 Medium2023-04-20
CVE-2023-0383 Uncontrolled Resource Consuption in M-Files Server — M-Files ServerCWE-770 7.5 High2023-04-20
CVE-2023-0382 Uncontrolled Resource Consumption in M-Files Server — M-Files ServerCWE-770 6.5 Medium2023-04-05
CVE-2022-4858 Insertion of Sensitive Information into Log File — M-Files ServerCWE-532 4.4 Medium2022-12-30
CVE-2022-1911 Information disclosure in M-Files Server — M-Files ServerCWE-200 5.3 Medium2022-11-30
CVE-2022-1606 Incorrect privilege assignment in M-Files Server — M-Files ServerCWE-269 2.4 Low2022-11-30
CVE-2021-41808 In M-Files Server product with versions before 21.11.10775.0, enabling logging of federated authentication would write sensitive information to event logs. — M-Files ServerCWE-532 2.0 Low2022-01-18
CVE-2021-41807 Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0, allows brute-forcing of certain type of user accounts. — M-Files ServerCWE-307 7.5 High2022-01-18
CVE-2021-41809 SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, allows requests from server. — M-Files ServerCWE-918 3.5 Low2022-01-18

This page lists every published CVE security advisory associated with M-Files. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.