M Files Server

Vendor:

First CVE: Jan 18, 2022 · Active for 4 years

37
Total CVEs
More Total CVEs than 97% of tracked products
7.4
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact M Files Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2022
4 years ago
Most Recent CVE
May 18, 2026
69 days ago

CVE Severity & Scoring

M Files Server37 CVEs
All CVEs352,713 CVEs
LowMediumHighCritical
Attack Vector
Local2 (5.4%)
Network35 (94.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (97.3%)
High1 (2.7%)
Unknown0 (0.0%)
User Interaction
None34 (91.9%)
Unknown0 (0.0%)
Required2 (5.4%)
Privileges Required
Low17 (45.9%)
High5 (13.5%)
None15 (40.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files
Dec 19, 20258.629NONO
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a
Nov 20, 20249.829NONO
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefo
Jan 18, 20229.829NONO
Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to c
May 18, 20267.128NONO
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-File
Dec 20, 20239.827NONO
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
Apr 20, 20237.827NONO
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.
Dec 30, 20227.525NONO
Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacke
Apr 1, 20267.324NONO
A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server.
Jun 15, 20256.524NONO
Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files S
Nov 28, 20238.824NONO

Exploit Exposure

Signals from CVEs in this product scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (37 CVEs).

Media Mentions

Signals from CVEs in this product scope (37 CVEs).

Top CNAs Publishing CVEs For M Files Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
23.918.80.6%00
23.1018.80.6%00