M Files Web
Vendor:
First CVE: Oct 28, 2021 · Active for 4 years
9
Total CVEs
More Total CVEs than 88% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact M Files Web over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 28, 2021
4 years ago
Most Recent CVE
Apr 4, 2025
480 days ago
CVE Severity & Scoring
M Files Web9 CVEs
11%
56%
22%
11%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None5 (55.6%)
Unknown0 (0.0%)
Required4 (44.4%)
Privileges Required
Low6 (66.7%)
High0 (0.0%)
None3 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41807CRITICAL Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefo | Jan 18, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-37253HIGH M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the | Dec 5, 2021 | 7.5 | 26 | NO | NO |
CVE-2021-37254HIGH In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key in | Oct 28, 2021 | 7.5 | 24 | NO | NO |
CVE-2023-4479MEDIUM Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period. | Mar 4, 2024 | 5.4 | 19 | NO | NO |
CVE-2023-3406MEDIUM Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files | Aug 25, 2023 | 6.5 | 19 | NO | NO |
CVE-2022-4264MEDIUM Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration. | Dec 9, 2022 | 4.3 | 19 | NO | NO |
CVE-2023-2325MEDIUM Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on user | Oct 20, 2023 | 5.4 | 18 | NO | NO |
CVE-2025-3087MEDIUM Stored XSS in M-Files Web versions from 25.1.14445.5 to 25.2.14524.4 allows an authenticated user to run scripts | Apr 4, 2025 | 5.4 | 16 | NO | NO |
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally. | Dec 2, 2022 | 2.6 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For M Files Web
Top CWEs
Versions
No cataloged versions.