CVE-2025-2159: M-Files Corporation M-Files Admin

Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Stored XSS in Desktop UI in M-Files Server Admin tool before version 25.3.14681.7 on Windows allows authenticated local user to run scripts via UI

Affected products

Published 2025-04-04. Last modified 2026-06-17.