CVE-2026-18372
CSS injection in M-Files Web
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other vault users.
| CWE | CWE-79 |
| Vendor | m-files corporation |
| Product | m-files web |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for m-files corporation m-files web
Be the first to know when new unknown vulnerabilities affecting m-files corporation m-files web are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
M-Files Corporation / M-Files Web
0 < 26.8.16330.2