Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to cause script execution for other users.
Fixes

Solution

Update to patched version 25.8 or newer.


Workaround

No workaround given by the vendor.

History

Mon, 15 Sep 2025 10:30:00 +0000

Type Values Removed Values Added
Description Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to cause script execution for other users.
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: M-Files Corporation

Published:

Updated: 2025-09-15T13:43:58.690Z

Reserved: 2025-09-02T09:52:49.686Z

Link: CVE-2025-9826

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-15T11:15:34.497

Modified: 2025-09-15T11:15:34.497

Link: CVE-2025-9826

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.