Known Vulnerabilities for M-files Server by M-files
Listed below are 10 of the newest known vulnerabilities associated with "M-files Server" by "M-files".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41269 json | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configu... | Not Provided | 2026-04-23 | 2026-04-23 |
| CVE-2026-41230 json | Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS rec... | Not Provided | 2026-04-23 | 2026-04-23 |
| CVE-2026-41228 json | Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (a... | Not Provided | 2026-04-23 | 2026-04-23 |
| CVE-2026-41193 json | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation featu... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-41062 json | WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in commit 23... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-40899 json | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blo... | Not Provided | 2026-04-16 | 2026-04-18 |
| CVE-2026-40885 json | goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through ... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-40884 json | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the docum... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-40876 json | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based p... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-40576 json | excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in exc... | Not Provided | 2026-04-21 | 2026-04-21 |