CVE-2025-14267: M-Files Server
Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.
Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak exposure affecting versions before 25.12.15491.7
Affected products
- M-Files M-Files Server: before 25.12.15491.7 (fixed in 25.12.15491.7)
Published 2025-12-19. Last modified 2026-06-17.