PatchSiren

M-Files Corporation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM M-Files Corporation CVE published 2026-08-19

CVE-2026-18372

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T12:17:17.043Z and has not been modified since then. CVE-2026-18372 is a CSS injection vulnerability in M-Files Web before 26.8.16330.2. An authenticated vault administrator can inject arbitrary CSS, affecting the web user interface displayed to other vault users. The vulnerability has a CVSS scor [truncated]

MEDIUM M-Files Corporation CVE published 2026-08-19

CVE-2026-18371

An HTML injection vulnerability exists in M-Files Web before version 26.8.16330.2. This allows an authenticated attacker to affect the web user interface contents displayed to other users. The vulnerability can lead to unauthorized modifications of the user interface, potentially disrupting normal operations or leaking sensitive information. Administrators should be aware of the potential risks and take n [truncated]

MEDIUM M-Files Corporation CVE published 2026-08-05

CVE-2026-0931

CVE-2026-0931 is a denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3. An authenticated admin user can cause the M-Files Server process to crash and fail to restart. The CVSS score is 6.9 (MEDIUM). Affected M-Files Server administrators and users with admin privileges should verify their server versions and apply updates if necessary. Official records are limited; further verif [truncated]

HIGH M-Files Corporation CVE published 2026-05-18

CVE-2026-0983

CVE-2026-0983 is an authenticated denial-of-service issue in M-Files Server. According to the vendor advisory referenced by NVD, a user with authentication can cause the MFserver process to crash, affecting versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3.