This page lists publicly disclosed CVE vulnerabilities affecting m-files classic_web (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-2325 | Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document. | [email protected] | 7.3 | 0.08% | 2023-10-20 | 2026-02-23 |
| CVE-2023-3425 | Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory. | [email protected] | 6.5 | 0.19% | 2023-08-25 | 2026-02-23 |
| CVE-2023-3406 | Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server | [email protected] | 7.7 | 0.10% | 2023-08-25 | 2026-02-23 |