📦 M Files Server

by M Files

🔍 What is M Files Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-10127

CRITICAL CVSS 9.8 Nov 20, 2024

This vulnerability allows attackers to bypass authentication in M-Files servers when configured with vulnerable OpenLDAP setups. It enables unauthorized access without valid credentials by exploiting ...

CVE-2025-0635

HIGH CVSS 7.5 Jan 23, 2025

CVE-2025-0635 is a denial-of-service vulnerability in M-Files Server that allows unauthenticated attackers to consume computing resources, potentially making the server unresponsive. This affects orga...

CVE-2024-4056

HIGH CVSS 7.5 Apr 26, 2024

CVE-2024-4056 is a denial-of-service vulnerability in M-Files Server that allows unauthenticated attackers to consume computing resources, potentially making the server unavailable. This affects M-Fil...

CVE-2023-6912

HIGH CVSS 7.5 Dec 20, 2023

M-Files Server versions before 23.12.13205.0 lack brute force protection, allowing attackers unlimited authentication attempts to guess user passwords. This affects all organizations using vulnerable ...

CVE-2023-0383

HIGH CVSS 7.5 Apr 20, 2023

This vulnerability in M-Files Server allows attackers to cause denial of service through uncontrolled memory consumption. By sending specially crafted user-controlled operations, attackers can exhaust...

CVE-2021-41807

HIGH CVSS 7.5 Jan 18, 2022

This vulnerability allows attackers to perform unlimited login attempts against certain M-Files user accounts, enabling brute-force attacks to guess passwords. It affects M-Files Server and M-Files We...

CVE-2026-0663

MEDIUM CVSS 4.9 Jan 21, 2026

This vulnerability allows authenticated attackers with vault administrator privileges to crash M-Files Server by calling a vulnerable API endpoint, causing denial of service. It affects M-Files Server...

CVE-2025-14267

MEDIUM CVSS 4.9 Dec 19, 2025

This vulnerability in M-Files Server allows sensitive information to be exposed due to incomplete data removal before transfer. It affects organizations using M-Files Server versions before 25.12.1549...

CVE-2025-14318

MEDIUM CVSS 4.3 Dec 18, 2025

M-Files Server versions before 25.12.15491.7 have an improper access control vulnerability that allows authenticated users to download files through M-Files Web using Web Companion even when the Print...

CVE-2025-11681

MEDIUM CVSS 6.5 Nov 17, 2025

An authenticated user can cause a denial-of-service by crashing the MFserver process in vulnerable M-Files Server versions. This affects organizations using M-Files Server before the patched versions,...

CVE-2025-0648

MEDIUM CVSS 4.9 Jan 23, 2025

A configuration change vulnerability in M-Files Server's database driver allows highly privileged attackers to cause unexpected server crashes, leading to denial of service. This affects M-Files Serve...

CVE-2024-10126

MEDIUM CVSS 4.3 Nov 20, 2024

This CVE describes a Local File Inclusion vulnerability in M-Files Server that allows authenticated users to read server local files of limited filetypes via the document preview feature. It affects M...

CVE-2022-4862

MEDIUM CVSS 5.0 Mar 6, 2023

This vulnerability allows authenticated users to inject HTML content that gets rendered in other users' browsers in M-Files Web, potentially enabling cross-site scripting attacks. It affects all M-Fil...

CVE-2022-4858

MEDIUM CVSS 4.4 Dec 30, 2022

M-Files Server versions before 22.10.11846.0 can log sensitive authentication tokens to log files when specific configurations are enabled. This vulnerability allows attackers with access to log files...

CVE-2022-1911

MEDIUM CVSS 5.3 Nov 30, 2022

CVE-2022-1911 is an information disclosure vulnerability in M-Files Server where an error in the parser function allows unauthenticated attackers to access some operating system information. This affe...

CVE-2023-2112

LOW CVSS 3.6 Apr 20, 2023

This vulnerability in M-Files Desktop component service allows an authenticated user in one session to move laterally to another user's session, potentially accessing unauthorized data or performing a...

CVE-2021-41809

LOW CVSS 3.5 Jan 18, 2022

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in M-Files Server products. It allows attackers to make unauthorized queries from the server when previewing certain document type...