Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-18348 | A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server. |
Solution
Update to the latest patched version.
Workaround
No workaround given by the vendor.
Thu, 09 Oct 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
M-files
M-files m-files Server |
|
CPEs | cpe:2.3:a:m-files:m-files_server:*:*:*:*:-:*:*:* cpe:2.3:a:m-files:m-files_server:*:*:*:*:lts:*:*:* |
|
Vendors & Products |
M-files
M-files m-files Server |
|
Metrics |
cvssV3_1
|
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Mon, 16 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 15 Jun 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server. | |
Title | Path traversal in M-Files API | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: M-Files Corporation
Published:
Updated: 2025-06-16T13:46:48.208Z
Reserved: 2025-06-10T07:36:27.344Z
Link: CVE-2025-5964

Updated: 2025-06-16T13:46:23.208Z

Status : Analyzed
Published: 2025-06-15T20:15:31.037
Modified: 2025-10-09T16:35:13.663
Link: CVE-2025-5964

No data.

No data.