Skip to main content

Vendor/product archive

m-files / m-files_web CVEs

Beta · best-effort

4 CVEs tagged to m-files / m-files_web0 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2025-3087

Published Apr 4, 2025

Stored XSS in M-Files Web versions from 25.1.14445.5 to 25.2.14524.4 allows an authenticated user to run scripts

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-37253

Published Dec 5, 2021

M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37254

Published Oct 28, 2021

In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1