Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

M-Files — Vulnerabilities & Security Advisories 30

Browse all 30 CVE security advisories affecting M-Files. AI-powered Chinese analysis, POCs, and references for each vulnerability.

M-Files operates as an intelligent information management platform, utilizing metadata-driven architecture to organize and secure enterprise data across diverse repositories. Historically, its software has been associated with thirty recorded Common Vulnerabilities and Exposures, predominantly involving remote code execution, cross-site scripting, and privilege escalation flaws. These vulnerabilities often stem from insufficient input validation and improper access controls within the application’s web interface and API endpoints. While specific major public breaches linked directly to M-Files remain limited in public reporting, the recurring nature of these CVEs highlights persistent challenges in securing complex enterprise content management systems. The platform’s reliance on third-party components and custom integrations frequently introduces attack surfaces that require rigorous patching and configuration management. Security assessments indicate that timely updates and strict role-based access policies are critical for mitigating the identified risks associated with its extensive feature set.

Found 14 results / 30 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2023-6239 Incorrect calculation of effective permissions — M-Files Server CWE-281 5.4 Medium 2023-11-28
CVE-2023-6189 Improper Permission Handling in M-Files Server — M-Files Server CWE-280 4.3 Medium 2023-11-22
CVE-2023-6117 M-Files REST API allows Denial of Service — M-Files Server CWE-770 5.7 Medium 2023-11-22
CVE-2023-3425 CVE-2023-3425: Out-of-Bounds memory read — M-Files Server CWE-125 6.5 Medium 2023-08-25
CVE-2023-3405 Denial of service condition in M-Files Server — M-Files Server CWE-248 7.5 High 2023-06-27
CVE-2023-0384 Uncontrolled Resource Consuption in M-Files Server — M-Files Server CWE-400 6.5 Medium 2023-04-20
CVE-2023-0383 Uncontrolled Resource Consuption in M-Files Server — M-Files Server CWE-770 7.5 High 2023-04-20
CVE-2023-0382 Uncontrolled Resource Consumption in M-Files Server — M-Files Server CWE-770 6.5 Medium 2023-04-05
CVE-2022-4858 Insertion of Sensitive Information into Log File — M-Files Server CWE-532 4.4 Medium 2022-12-30
CVE-2022-1911 Information disclosure in M-Files Server — M-Files Server CWE-200 5.3 Medium 2022-11-30
CVE-2022-1606 Incorrect privilege assignment in M-Files Server — M-Files Server CWE-269 2.4 Low 2022-11-30
CVE-2021-41808 In M-Files Server product with versions before 21.11.10775.0, enabling logging of federated authentication would write sensitive information to event logs. — M-Files Server CWE-532 2.0 Low 2022-01-18
CVE-2021-41807 Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0, allows brute-forcing of certain type of user accounts. — M-Files Server CWE-307 7.5 High 2022-01-18
CVE-2021-41809 SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, allows requests from server. — M-Files Server CWE-918 3.5 Low 2022-01-18

This page lists every published CVE security advisory associated with M-Files. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.