M Files Server
Vendor:
First CVE: Jan 18, 2022 · Active for 4 years
37
Total CVEs
More Total CVEs than 97% of tracked products
7.4
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact M Files Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2022
4 years ago
Most Recent CVE
May 18, 2026
69 days ago
CVE Severity & Scoring
M Files Server37 CVEs
46%
41%
8%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (5.4%)
Network35 (94.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (97.3%)
High1 (2.7%)
Unknown0 (0.0%)
User Interaction
None34 (91.9%)
Unknown0 (0.0%)
Required2 (5.4%)
Privileges Required
Low17 (45.9%)
High5 (13.5%)
None15 (40.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13008HIGH An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files | Dec 19, 2025 | 8.6 | 29 | NO | NO |
CVE-2024-10127CRITICAL Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a | Nov 20, 2024 | 9.8 | 29 | NO | NO |
CVE-2021-41807CRITICAL Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefo | Jan 18, 2022 | 9.8 | 29 | NO | NO |
CVE-2026-0983HIGH Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to c | May 18, 2026 | 7.1 | 28 | NO | NO |
CVE-2023-6912CRITICAL Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-File | Dec 20, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-2112HIGH Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0. | Apr 20, 2023 | 7.8 | 27 | NO | NO |
CVE-2022-4858HIGH Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set. | Dec 30, 2022 | 7.5 | 25 | NO | NO |
CVE-2026-0932HIGH Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacke | Apr 1, 2026 | 7.3 | 24 | NO | NO |
CVE-2025-5964MEDIUM A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server. | Jun 15, 2025 | 6.5 | 24 | NO | NO |
CVE-2023-6239HIGH Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files S | Nov 28, 2023 | 8.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (37 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (37 CVEs).
Media Mentions
Signals from CVEs in this product scope (37 CVEs).
Top CNAs Publishing CVEs For M Files Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 23.9 | 1 | 8.8 | 0.6% | 0 | 0 |
| 23.10 | 1 | 8.8 | 0.6% | 0 | 0 |