CVE-2025-2159
Stored XSS in M-Files Admin user interface
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Stored XSS in Desktop UI in M-Files Server Admin tool before version 25.3.14681.7 on Windows allows authenticated local user to run scripts via UI
| CWE | CWE-79 |
| Vendor | m-files corporation |
| Product | m-files admin |
| Published | Apr 4, 2025 |
| Last Updated | Feb 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for m-files corporation m-files admin
Be the first to know when new unknown vulnerabilities affecting m-files corporation m-files admin are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
M-Files Corporation / M-Files Admin
0 < 25.3.14681.7
References
Credits
Pasi Orovuo / Solita Oy Teemu Laakso / Solita Oy