CVE-2022-39017: M-Files Hubshare

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.

Affected products

  • M-Files Hubshare: before 3.3.10.9 (fixed in 3.3.10.9)

Published 2022-10-31. Last modified 2026-06-17.